Operational Planning and Control

Introduction

Clause 8 of ISO 18788:2015 focuses on operations, requiring organizations to ensure that their Security Operations Management System (SOMS) translates strategic objectives into tactical and operational execution. At the core of this requirement is operational planning and control (8.1), which ensures that security activities are systematically designed, managed, monitored, and improved to deliver effective, lawful, and ethical services.

Annex A.8.1 provides further guidance, clarifying that planning and control must be proactive, risk-based, and measurable, integrating with risk management, competence, resources, and stakeholder expectations.

The Purpose of Operational Planning and Control

  1. Consistency: Ensures all security operations are carried out in a controlled and repeatable manner.
  2. Risk-Based Assurance: Embeds risk assessment and treatment into planning, so resources are applied where risks are greatest.
  3. Legal and Ethical Compliance: Aligns with international human rights, applicable laws, and contractual requirements.
  4. Efficiency: Prevents waste of resources, duplication of effort, or operational blind spots.
  5. Auditability: Provides records of planning, decision-making, and operational execution for review and certification.

Elements of Operational Planning and Control

1. Risk-Based Planning

  • All operations must begin with risk assessments (strategic, tactical, operational).
  • Risks to clients, employees, contractors, and communities must be identified, evaluated, and treated.
  • Risk registers form the foundation for operational objectives and controls.
  • Planning must integrate with the organization's risk appetite and tolerance frameworks.

2. Alignment with Objectives

  • Operations must link directly to:
    • Strategic Objectives (e.g., compliance with ISO 18788, client trust, human rights).
    • Tactical Objectives (e.g., regional security plans, training deployment, stakeholder engagement).
    • Operational Objectives (e.g., patrol schedules, incident reporting, access control).
  • A golden thread must trace each operational task back to higher-level objectives.

3. Operational Controls

  • Controls must be planned and implemented to ensure operations are effective and lawful:
    • Preventive controls - Vetting, SOPs, training, barriers.
    • Detective controls - Incident reporting, surveillance, audits.
    • Corrective controls - Response teams, grievance procedures, corrective actions.
  • Controls must be measurable through the Internal Control Effectiveness (ICE) methodology, linking performance to residual risk reduction.

4. Resource Allocation

  • Planning must confirm that sufficient resources (Clause 7.1) are available:
    • Budget, personnel, vehicles, communications, technology, training funds.
  • Resources must be documented, allocated, and auditable, ensuring sustainability and fairness.

5. Documentation and Communication

  • Operations must be guided by policies, procedures, SOPs, and plans.
  • Documentation must be controlled under Clause 7.5.3: versioned, accessible, and retained.
  • Communication of operational plans must ensure all staff know their responsibilities and escalation procedures (Clause 7.4).

6. Monitoring and Control

  • Operations must be monitored against objectives, KPIs, and risk criteria.
  • Regular reviews, audits, and incident analysis must be used to adjust plans.
  • Corrective actions must be recorded, evaluated, and used for continual improvement.

Guidance from A.8.1

Annex A emphasizes that organizations should:

  • Establish processes for planning, implementing, monitoring, and controlling operations.
  • Incorporate contingency planning for emergencies or disruptions.
  • Identify measurable performance criteria (KPIs, ICE, LoR/LoA).
  • Ensure that roles and responsibilities for operations are defined and documented.
  • Apply a Plan-Do-Check-Act (PDCA) cycle, ensuring continuous improvement.

Documentation and Audit Evidence

For audit and certification, organizations must demonstrate evidence of:

  • Operational Plans: Mission plans, deployment schedules, SOPs, training timetables.
  • Risk Assessments: Linked to specific operations, updated as threats change.
  • Resource Allocation Records: Budgets, asset registers, training records.
  • Communication Logs: Briefings, radio logs, incident reports.
  • Monitoring & Review Records: KPIs, performance dashboards, audit reports.
  • Corrective Actions: Root cause analyses, improvement plans, grievance resolution reports.

Evidence must comply with the Audit Evidence Reliability Model (AERM), favoring confirmative and automated evidence (digital logs, system reports, independent verifications) over verbal or anecdotal sources.

Conclusion

Clause 8.1 of ISO 18788 ensures that security operations are not ad hoc or reactive but structured, risk-based, and auditable. Through operational planning and control, organizations can align strategy with field execution, allocate resources effectively, and demonstrate compliance with laws, contracts, and international standards.

By embedding the principles of A.8.1—planning, controlling, monitoring, and continually improving—security providers deliver operations that are effective, ethical, and certifiable, building trust with clients, regulators, and communities.