Glossary
Definitions of key terms in terrorism preparedness, industrial security and resilience used at ISTP.
Key ISTP terms
One definition per term, used consistently across the programme.
Industrial security
The discipline of protecting the assets, people, information and operational continuity of an industrial or commercial organisation against deliberate threats.
Terrorism preparedness
An organisation's ability to understand terrorism risk and to put plans, roles, detection, reporting and recovery in place before an incident occurs.
Security resilience
The capacity of a security system to detect, withstand and adapt to threats, including through layered protection and surveillance awareness.
Organisational resilience
The ability of an organisation to prevent, prepare for, respond to, adapt to and recover from disruption while continuing its critical functions. ISTP's umbrella framework.
Security governance
The structure of authority, accountability, policy and reporting that makes security part of organisational decision-making.
Threat–Vulnerability–Consequence (TVC)
A framework for assessing a single risk scenario: how likely the threat is, how vulnerable the asset is and how severe the consequences would be.
TVRA
Threat, Vulnerability and Risk Assessment: a whole-facility assessment process producing a prioritised risk list and treatment recommendations.
CARVER+Shock
An asset-prioritisation tool developed for food defence as a derivative of the military CARVER method: Criticality, Accessibility, Recuperability, Vulnerability, Effect, Recognizability, plus psychological effect (Shock).
Hostile reconnaissance
Observation of a target by those planning an attack. Recognising its indicators is one of the most effective early-detection points for facility managers.
Counter-surveillance detection
Techniques for recognising whether a person or facility is being observed, applied ethically and without assuming the authority of law enforcement.
Defence in depth
Layered protection, so that failure of one layer does not immediately expose the asset.
CPTED
Crime Prevention Through Environmental Design: preventing crime through the design of the physical environment, such as lighting, sightlines and access layout.
ESRM
Enterprise Security Risk Management: an ASIS approach that treats security as a risk-management function shared with asset owners.
Incident Command System (ICS)
A standard command structure for managing incidents with clear roles, chain of command and communication.
BCMS / BCP
Business Continuity Management System (ISO 22301) and Business Continuity Plan: the system and plan for keeping critical functions running through disruption.
Certificate of Completion
A certificate stating that a participant has met the programme requirements. Distinct from a competency certification, which states that a person is competent under a certification body's scheme.