On the Application of the Safety-II Concept in a Security Context
Journal article, Peer reviewed
MetadataVis full innførsel
OriginalversjonEuropean Journal for Security Research. 2019 10.1007/s41125-019-00041-0
This paper presents an alternative and broader security risk perspective, incorporat-ing uncertainty, as a two-dimensional combination of (1) threat (Th) on value (Vl), (2) vulnerability (Vu) given coping capabilities (Cc), and associated uncertainties U (will the threat scenario occur? and to what degree are we vulnerable?). Moreo-ver, this work attempts to provide an integrated approach to the safety and secu-rity fields. We look closely into the issues related to Safety-I, Safety-II and security. Whereas conventional safety management approaches (Safety-I) are based on hind-sight knowledge and risk assessments calculating historical data-based probabilities, the concept of Safety-II looks for ways to enhance the ability of organisations to be resilient in the sense that they recognise, adapt to and absorb disturbances. Three determinants that shape the Safety-II concept in the security perspective are the capacity of organisations to operate in changing circumstances; formulating strat-egies that promote a willingness to devote resources to security purposes, driven mainly by the organisation’s leader; and an organisational culture that encourage people to speak up (respond), think creatively (anticipate), and act as mindful par-ticipants (monitor and learn). Based on clarifying some of the fundamental build-ing blocks of security risk assessment, this work develops an extended security risk assessment, including an analysis of both vulnerability and resilience. The analysis explores how the system works following any type of threat scenario and determines whether key functions and operations can be sustained.