APPLICATION OF THE
SECURITY TRIAGE PROCESS
2
APPLICATION OF THE SECURITY TRIAGE PROCESS
HAS EXTERNAL ADVICE BEEN SOUGHT:
Is the security triage being applied to a new initiative, project, asset, product or service?
Comprise Critical National Infrastructure
is a commercial site involving the creation,
processing, trading or storage of valuable
materials, currency, pharmaceuticals,
chemicals, petrochemicals, or gases or
the provision or production of enablers for
production of these materials
fulfils a defence, law enforcement, national
security or diplomatic function
is used, or is planned to be used, to host
event of security significance
constitutes a landmark, nationally
significant site or crowded place
at/before its start
or to an existing initiative, project, asset, product or service
or is it being assessed retrospectively?
IF YES, WHAT WAS THE SOURCE(S) OF ADVICE?
KEY POINTS IN ADVICE RECEIVED:
IF A NEW INITIATIVE, PRODUCT, ASSET, PRODUCT OR SERVICE IS THE SECURITY TRIAGE
BEING APPLIED
IF AN EXISTING INITIATIVE, PRODUCT, ASSET, PRODUCT OR SERVICE, WHAT IS THE TRIGGER
FOR APPLYING THE SECURITY TRIAGE PROCESS (SEE CLAUSE 4.6 OF THE ISO)?
IF THE ASSESSMENT IS TAKING PLACE IN RELATION TO BUILT ASSET, DOES THAT BUILT ASSET:
Ye s No
(tick all that are relevant)
3
APPLICATION OF THE SECURITY TRIAGE PROCESS
Ye s
Ye s
No
No
IF THE ASSESSMENT IS TAKING PLACE IN RELATION TO AN ASSET, PRODUCT OR SERVICE, IS
THERE SUFFICIENT RISK THAT IT IS, OR CAN BE, USED TO SIGNIFICANTLY COMPROMISE THE
INTEGRITY, SAFETY, SECURITY AND/OR RESILIENCE OF AN ASSET, PRODUCT OR SERVICE,
OR ITS ABILITY TO FUNCTION?
ARE THERE NEIGHBOURING BUILT ASSETS ABOUT WHICH INFORMATION WILL BE COLLECTED?
DETAILS OF THOSE CONSULTED:
ARE THERE ANY SPECIFIC REQUIREMENTS IN RELATION TO INFORMATION ABOUT THE
NEIGHBOURING BUILT ASSET MADE BY OWNER(S)/OCCUPIER(S)/OPERATOR(S)?
Neighbouring
built asset
Neighbouring built asset
Neighbouring built asset
Information which will
be collected
Name of contact
If yes, request made relating to sensitive information
Owner/occupier/
operator consulted?
Date consultation completed
If not consulted,
why not?
4
APPLICATION OF THE SECURITY TRIAGE PROCESS
ST1 ST3
ST2 ST4
WHAT WAS THE OUTCOME FROM THE SECURITY TRIAGE PROCESS?
Ye s No
IF ST4, ARE THERE REALISTIC BUSINESS BENEFITS TO BE DERIVED FROM APPLYING A
SECURITY-MINDED APPROACH?
THIS DOCUMENT SHOULD BE SIGNED BY AN APPROPRIATE SENIOR MANAGER WITHIN THE
ASSET OWNER’S ORGANISATION.
Signature
If it has been determined that:
the built asset is not sensitive in whole or in part;
there are no security requirements in relation to non-publicly available information relating to neighbouring
assets; and
there are no realistic business benefits to be derived from adopting a security-minded approach
then there is no requirement for Clauses 5 to 9 of BS EN ISO 19560-5:2020 to be applied. However, a
copy of this assessment should be retained.
If a security-minded approach is to be adopted then Clauses 5 to 9 should be implemented in line
with the requirements of that document. In addition, a copy of this assessment should be included as
part of the Security Strategy developed.
Date
click to sign
signature
click to edit