ISTPIndustrial Security & Terrorism Preparedness
Home › Glossary

Glossary

Definitions of the key industrial security and terrorism preparedness terms used in the ISTP Programme.

Glossary

Key ISTP terms


One definition per term, used consistently across all programme materials.

Industrial security

The discipline of protecting the assets, personnel, information and operational continuity of an industrial or commercial organisation against deliberate threats.

Organisational resilience

An organisation's ability to prevent, prepare for, respond to and recover from disruption while continuing to run its critical functions. Used by ISTP as the overarching framework.

Threat–Vulnerability–Consequence (TVC)

A framework for assessing a single risk scenario: how likely the threat is to materialise, how vulnerable the asset is, and how severe the consequence would be.

TVRA

Threat, Vulnerability and Risk Assessment — the full assessment process for a facility, producing a prioritised risk list and treatment recommendations.

CARVER+Shock

An asset prioritisation tool developed for food defence as a derivative of the military CARVER method: Criticality, Accessibility, Recuperability, Vulnerability, Effect, Recognisability, plus psychological effect (Shock).

Hostile reconnaissance

Observation of a target by those planning an attack. Recognising its indicators is one of the most effective early detection points available to a facility manager.

Counter-surveillance detection

Techniques for recognising whether a person or a facility is under observation, carried out ethically and without assuming the authority of the state.

Defence in depth

Layered security, so that the failure of one layer does not immediately open access to the asset.

CPTED

Crime Prevention Through Environmental Design — preventing crime through the design of the physical environment: lighting, sightlines, and the arrangement of access.

ESRM

Enterprise Security Risk Management — the ASIS approach that positions security as a risk management function shared with asset owners.

Incident Command System (ICS)

A standard command structure for managing incidents, with clearly defined roles, chain of command and communication.

BCMS / BCP

Business Continuity Management System (ISO 22301) and Business Continuity Plan — the system and the plan that keep critical functions running during disruption.

Certificate of Completion

A certificate stating that a participant has completed the requirements of a programme. Distinct from a competency certification, which states that a person is competent under the scheme of a certification body.

WhatsApp