The SOMS Manual - A Living Framework for Security Excellence

Introduction

Clause 4.4 of ISO 18788:2015 requires organizations to establish, implement, maintain, and continually improve their Security Operations Management System (SOMS). The SOMS Manual serves as the central documented reference point, providing structure, clarity, and assurance that the organization's operations are aligned with international standards, legal obligations, and stakeholder expectations.

Much like an ISMS Manual under ISO/IEC 27001 or a QMS Manual under ISO 9001, the SOMS Manual is more than just a compliance document. It acts as the blueprint for governance, risk management, and assurance in the security domain.

Purpose of the SOMS Manual

The Manual fulfils several critical functions:

Reflection of the Standard

  • The Manual must map directly to ISO 18788 clauses, ensuring that each requirement (context, leadership, planning, support, operations, evaluation, and improvement) is addressed through documented policies, procedures, and controls.

Guidance for Implementation

  • It provides detailed instructions on how the organization's policies and processes are applied across all levels—head office, regional offices, deployed personnel, and subcontractors.

Framework for Maintenance

  • The Manual defines responsibilities, review mechanisms, and reporting structures to ensure that the SOMS remains effective and relevant in changing internal and external contexts.

Assurance to Stakeholders

  • The Manual is evidence for clients, auditors, and regulators that the company operates transparently, consistently, and in compliance with international norms and human rights obligations.

Driver of Continual Improvement

  • By integrating feedback loops—such as audits, risk assessments, lessons learned from incidents, and management reviews—the Manual ensures that the SOMS evolves with time and context.

Key Components of the SOMS Manual

A well-structured SOMS Manual under ISO 18788 typically includes:

  1. Introduction & Scope
    • Statement of conformity with ISO 18788.
    • Defined scope of operations (aligned with Clause 4.3).
  2. Context of the Organization
    • Internal and external context analysis.
    • Stakeholder needs and expectations (Clause 4.2).
  3. Leadership & Governance
    • Policies, human rights commitments, and governance structures.
    • Roles, responsibilities, and authorities.
  4. Risk Management Framework
    • Criteria for identifying, assessing, and treating risks.
    • Linkage to ISO 31000 and operational risk methodologies.
  5. Operational Controls
    • Deployment of security personnel.
    • Incident reporting and escalation processes.
    • Use of force, rules of engagement, and human rights considerations.
  6. Support Functions
    • Competence and training.
    • Communication and awareness.
    • Documentation and record control.
  7. Performance Evaluation
    • Monitoring, measurement, and reporting.
    • Internal audits and management reviews.
  8. Improvement Mechanisms
    • Corrective and preventive actions.
    • Lessons learned and best practice adoption.

Assurance through the SOMS Manual

The Manual is not only for internal use but also serves as assurance documentation for external stakeholders:

  • For Clients - It demonstrates that services are delivered within a controlled, ethical, and human-rights-compliant framework.
  • For Auditors/Certification Bodies - It provides a structured reference showing how ISO 18788 requirements are addressed.
  • For Employees and Contractors - It communicates expectations, standards, and operational protocols, ensuring consistent performance across the organization.

Continual Improvement

Clause 4.4 explicitly requires continual improvement, which must be embedded in the Manual by:

  • Documenting performance metrics and KPIs.
  • Establishing review cycles for updating policies and procedures.
  • Integrating lessons from incidents, audits, and stakeholder feedback.
  • Linking improvement activities to organizational objectives and risk appetite.

This ensures that the SOMS is a living management system, not a static document.

Conclusion

The SOMS Manual under Clause 4.4 of ISO 18788 is the anchor of the entire management system. By reflecting the requirements of the standard, providing operational guidance, and embedding mechanisms for assurance and continual improvement, the Manual transforms ISO 18788 from a theoretical framework into a practical, auditable, and value-driven system.

For a security company seeking international certification, the Manual is the evidence of intent and capability—a visible demonstration that the organization not only complies with ISO 18788 but also commits to professional, ethical, and sustainable security operations.