The Security Policy - The Cornerstone of a SOMS
Introduction
Clause 5.2 of ISO 18788:2015 requires organizations to establish a policy that sets the strategic direction, objectives, and commitments of the Security Operations Management System (SOMS). The policy is not just a document; it is the foundation of governance, accountability, and ethical conduct in security operations.
The Security Policy must reflect the organization's mission, values, and obligations under ISO 18788, while also aligning with human rights frameworks, legal requirements, and stakeholder expectations. It sets the tone for the entire system—defining what the organization stands for, how it operates, and how it continually improves.
Purpose of the SOMS Policy
The Security Policy serves multiple functions:
- Strategic Direction
- Provides clarity on the organization's vision and how security operations align with corporate objectives.
- Establishes the role of the SOMS as a driver of governance, risk, and compliance.
- Commitment to Compliance
- Affirms adherence to laws, regulations, contracts, and international norms.
- Embeds obligations under the Montreux Document, ICoC (International Code of Conduct for Private Security Providers), and human rights standards.
- Risk and Human Rights Assurance
- Demonstrates the organization's commitment to managing risk responsibly while protecting people, assets, and communities.
- Reinforces proportionality, accountability, and respect for fundamental freedoms.
- Framework for Objectives
- Provides the basis for setting measurable SOMS objectives and linking them to continual improvement cycles.
- Communication of Values
- Ensures that employees, contractors, clients, and external stakeholders understand the principles that guide the company's security operations.
Key Elements of a Security Policy under ISO 18788
A robust Security Policy should include:
- Statement of Commitment - Clear support for ISO 18788, legal compliance, and respect for human rights.
- Mission & Values - How the organization protects people, property, and reputation while acting ethically.
- Scope of Application - Defining where and to whom the policy applies (e.g., guards, supervisors, subcontractors, support functions).
- Risk Management Approach - Acknowledgment of the use of ISO 31000 principles and structured methods for identifying, assessing, and mitigating risks.
- Human Rights Integration - Explicit recognition of international humanitarian law and the organization's responsibility to uphold rights during operations.
- Commitment to Continual Improvement - Assurance that the SOMS will be maintained, reviewed, and improved through performance evaluation, audits, and management reviews.
- Responsibilities and Accountability - Roles of leadership, SOMS champions, and operational staff in implementing and upholding the policy.
- Communication Requirements - How the policy will be disseminated internally and externally to ensure awareness and buy-in.
The Policy as an Assurance Tool
The Security Policy must be documented, communicated, and available to all stakeholders. This provides assurance that:
- Clients can trust security operations are governed by internationally recognized principles.
- Employees and Contractors know the behavioural and operational expectations placed upon them.
- Auditors and Regulators can verify alignment with ISO 18788 requirements.
- Communities and Stakeholders see tangible commitments to ethical, lawful, and respectful security practices.
Leadership Role in the Policy
Top management, supported by divisional and operational leaders, must:
- Approve and endorse the policy.
- Ensure it is consistent with the strategic direction of the organization.
- Actively communicate and promote the policy.
- Demonstrate alignment between stated commitments and actual practices (“walking the talkâ€).
This ensures that the tone at the top is visible in the policy, while the tone in the middle and at the operational level guarantees its effective implementation across the organization.
Conclusion
The Security Policy under Clause 5.2 of ISO 18788 is the cornerstone of the SOMS, providing a documented statement of intent, direction, and accountability. By aligning strategic objectives with legal obligations, human rights, and risk management principles, the policy ensures that security operations are ethical, professional, and resilient.
A strong, well-communicated policy demonstrates to clients, regulators, employees, and communities that the organization is committed not only to compliance but also to trust, transparency, and continual improvement.