Security spending without assessment is guessing with money, and over-guessing is as real a failure as under-guessing. The manuscript's starting premise scales the whole program: the facility with a crime history needs more than the low-crime neighborhood; the 24-hour operation more than the daytime lot; the hospital garage serving late-shift staff more than the 9-to-5 deck. Assessment is how the scaling gets evidence.
The three legal doctrines. The security program operates inside a legal frame the practitioner must know conversationally. The standard of care benchmarks what a competent, prudent professional would do in the circumstances, and it runs two directions: the design professional who falls short may be negligent, and the owner who declines the professional's recommended security measures may violate the standard themselves. It flexes with context: location, crime history, hours, clientele. The reasonable person test asks whether conduct matched what an idealized, averagely prudent operator would have done: sufficient lighting, cameras, patrols under the same circumstances. Foreseeability completes the negligence architecture with its five elements (duty of care, breach, foreseeable harm, causation, damages), and its practical teeth are in what it does not require: the operator need not predict the specific car break-in at 2:00 a.m. Tuesday, only that inadequate security foreseeably invites some crime, with the facility's own claims history the strongest evidence of what was foreseeable. The manuscript's standing counsel applies to all three: aim to exceed the litmus tests, and reassess annually, because changing conditions and the industry-wide adoption of new technologies move the baseline underneath a static program.
Know the crimes and the data. The threat inventory is familiar (auto theft, break-ins for visible valuables, vandalism and property damage, and crimes against persons), and the data sources for grounding it are enumerated: local police records, the FBI's UCR program, the Bureau of Justice Statistics, the National Crime Victimization Survey, NIBRS, business associations and neighborhood watch groups, private security consultants, academic studies, and the commercial tier: CAP Index's address-specific crime forecasting. The escort-at-night convention for 24-hour operations' employees marks where inventory becomes obligation.
The assessment method. The manuscript's step sequence is a usable field protocol. Gather: blueprints, area crime statistics, incident reports. Identify risks: the location and surroundings read honestly, the lighting gaps and obscured views that make hiding spots, every access point (gates, stairs, elevators, emergency exits), and the activity levels that argue for enhanced or reduced response. Evaluate existing measures: cameras, alarms, access control, personnel, with maintenance and actual functionality verified, and the navigational layer (signs, emergency phones, markings) checked. Audit physically: walk the structure for broken gates, damaged fencing, unsecured entries; check lighting everywhere, especially at night; test the sightlines from the control room. Assess management: past incident response, reporting protocols, hiring and training of security personnel. Engage stakeholders: users, employees, local law enforcement, neighboring businesses and residents, whose perceptions are data. Mitigate: the comprehensive plan built from findings: lighting into the dark spots, obstacles out of the sightlines, cameras positioned for coverage, access control where entry needs restricting, trained personnel, and posted signage that advertises the security posture. Review periodically: monitor the statistics and incidents for emerging trends, and re-audit on schedule. Alongside the protocol, three recurring owner-side questions: does the surrounding area's incident history (reviewed periodically with law enforcement) establish the requirement; does the owner/operator agreement's scope warrant outside security; and can design and layout changes substitute for operational spend.
assess before spending and reassess annually: run the field protocol end to end, ground it in the enumerated data sources, and document both the findings and the response, because the three doctrines (standard of care, reasonable person, foreseeability) will judge the program retrospectively, and the operator's best defense is a dated assessment, a proportionate plan, and the record showing the recommended measures were adopted rather than declined.
From the shelf
- Module 61: security by designwhat the number funds
- Calls-for-service request template · link pending platform buildgetting the data the assessment needs
Source crosswalk -- where each section came from in the manuscript
| Module section | Source: Chapter 26, "Crime Prevention & Cyber Security" |
|---|---|
| Scaling premise | "Security Concepts" |
| Three doctrines | "Standard of Care"; "'Reasonable Person' Test"; "Foreseeability" |
| Crimes and data | "Criminal Activity"; data-source list; CAP Index |
| Assessment method | "Crime Assessment" (step protocol and trailing owner questions) |
| Not carried forward | Measures themselves (in #61); cyber (in #63) |