INTERPORTPOLICE INTRODUCES P²SeMS: A NEW STANDARD FOR INTEGRATED SECURITY MANAGEMENT
Secretary General Jay Grant said the Standard addresses a challenge that has become increasingly important as transportation security has grown more complex.
Download PDFINTERPORTPOLICE INTRODUCES P²SeMS: A NEW STANDARD FOR INTEGRATED SECURITY MANAGEMENT
A comprehensive approach to strengthening security, resilience and organizational assurance across airports, seaports, transportation systems and border environments
INTERPORTPOLICE has introduced the P²SeMS — Port Protective Security Management System Standard, providing police, security and transportation authorities with a comprehensive framework for examining how security is governed, managed, integrated and continually improved across their organizations.
Secretary General Jay Grant said the Standard addresses a challenge that has become increasingly important as transportation security has grown more complex.
“Most authorities already have substantial security capabilities,” Grant said. “They have police and security personnel, emergency plans, cybersecurity programs, access control, technology, training, exercises and regulatory requirements. The question P²SeMS asks is whether all of those capabilities are connected as a management system — and how leadership knows that the entire system is working as intended.”
FROM INDIVIDUAL PROGRAMS TO AN INTEGRATED SECURITY SYSTEM
Modern transportation authorities operate in an environment where physical security, cybersecurity, personnel, information, operations, emergency management and organizational resilience increasingly intersect.
A cyber incident can disrupt physical operations. A credentialing weakness can create an insider vulnerability. A communications failure can affect emergency response. A contractor or supplier can introduce risk into otherwise well-protected operations.
P²SeMS was developed around the principle that these responsibilities cannot always be effectively managed as separate security programs.
Instead, the Standard provides an Integrated Operational Assurance Framework through which an authority can examine its security responsibilities as an interconnected system.
“An incident does not respect an organizational chart,” Grant said. “Police, security, operations, IT, cyber, emergency management, communications and executive leadership may all have different responsibilities, but during a major event those responsibilities quickly intersect. P²SeMS is intended to help authorities understand and manage those connections before an incident occurs.”
PLAN. EXECUTE. VERIFY. ACT.
At the center of P²SeMS is a continuing management cycle: Plan, Execute, Verify and Act.
Planning establishes governance, accountability, risk, requirements, objectives and resources.
Execution turns those requirements into operational capabilities involving people, procedures, technology, training, communications and security measures.
Verification determines whether those capabilities actually work through assessments, exercises, inspections, performance measurement, incident reviews and other assurance activities.
Action ensures that identified deficiencies and lessons learned result in meaningful improvement.
The process then repeats as threats, technology, operations and organizational requirements change.
“The objective is not another security plan sitting on a shelf,” Grant said. “The objective is to establish a system through which leadership can continually ask: Are we prepared? Can we demonstrate that we are prepared? Where are the gaps? And what are we doing about them?”
BUILDING ON WHAT AUTHORITIES ALREADY HAVE
P²SeMS is not intended to replace an authority’s existing security plans, police procedures, emergency operations plans, cybersecurity frameworks or regulatory programs.
Instead, it provides a management structure for connecting and assuring those existing capabilities.
That distinction is important.
Authorities have invested substantial resources over many years developing specialized security programs. P²SeMS provides a way to examine whether those programs collectively support the organization’s security objectives, whether responsibilities are clearly understood and whether leadership has sufficient information to evaluate performance.
The Standard also encourages authorities to examine the relationship between compliance and capability.
Meeting a regulatory requirement remains essential, but having a required plan, procedure or piece of equipment does not necessarily demonstrate that the organization can successfully use that capability during an actual incident.
P²SeMS therefore places significant emphasis on exercising, verification, measurement, lessons learned and corrective action.
A STANDARD DESIGNED TO PROMPT QUESTIONS
INTERPORTPOLICE is encouraging authorities to review P²SeMS against their existing security arrangements rather than simply treating the Standard as another compliance requirement.
An authority reviewing P²SeMS might discover that it already performs many of the activities described in the Standard.
The value comes from examining how those activities fit together.
Does leadership have clearly defined security accountability?
Are cyber and physical security risks considered together when appropriate?
Are plans exercised under realistic conditions?
Do police, security, operations and other departments understand their respective responsibilities?
Does important security information reach everyone who needs it?
Are identified vulnerabilities tracked through corrective action?
Are lessons from incidents and exercises actually incorporated into operations?
And, ultimately, can the organization demonstrate that its security system is functioning as intended?
“These are not questions that should only be asked after something goes wrong,” Grant said. “P²SeMS provides a framework for asking them systematically and continuously.”
THE OUTCOME: GREATER ASSURANCE
The intended outcome of P²SeMS is greater organizational assurance.
For police and security leadership, that means a clearer understanding of capabilities, vulnerabilities, responsibilities and priorities.
For executive leadership and the Governing Body, it provides a better basis for understanding security performance, making risk decisions and determining where resources may be required.
For employees and operational departments, it reinforces that security is an organizational responsibility rather than solely the responsibility of the police or security department.
And for the authority as a whole, it provides a structure for continuous improvement as threats, technology and operations evolve.
Grant summarized the distinction this way:
“We want organizations to be able to move beyond saying, ‘We believe we are prepared.’ The stronger position is: ‘We can demonstrate how we are prepared, we know where improvement is needed, and we have a process for addressing it.’ That is what operational assurance is about.”
INTERPORTPOLICE INVITES AUTHORITIES TO REVIEW P²SeMS
INTERPORTPOLICE is inviting airport, seaport, transportation and border authorities, together with their police, public safety, security and executive leadership, to review the P²SeMS Standard and compare its framework with their existing security management arrangements.
The purpose of that review is not simply to determine whether an organization “meets” a Standard.
It is to begin a broader examination of how effectively the organization governs, integrates, verifies and continually improves the capabilities entrusted with protecting its people, operations and infrastructure.
P²SeMS asks a relatively simple question with potentially significant implications:
Does your organization have a collection of security programs — or an integrated security management system?
For authorities responsible for protecting increasingly complex transportation environments, INTERPORTPOLICE believes that is a question worth examining.

