ISO 18788 Security Operations Management System Training Course
| Course code | SD-SM-008 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Security Management |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Private security operations face heightened scrutiny where services involve guarding, protective security, patrols, access control, secure transport, or work in complex environments. Leaders must demonstrate that operational decisions protect clients, personnel, communities and human rights while meeting contractual, legal and regulatory obligations. ISO 18788 provides a management-system framework for doing this consistently, but organisations often struggle to translate its clauses into workable procedures, risk controls, incident records, supplier controls and performance evidence.
This five-day course teaches participants how to interpret and apply ISO 18788:2015 to a private security operation. Participants examine organisational context, leadership responsibilities, human-rights due diligence, security risk assessment, operational planning, competence management, incident handling, corrective action and management review. They practise building an ISO 18788 implementation plan, mapping controls to operational processes, defining measurable objectives and preparing evidence for internal or certification audits.
Training combines instructor-led clause interpretation with scenario-based workshops based on security-service contracts, high-risk assignments, subcontracted guarding and operational incidents. Participants work in groups to develop a Security Operations Management System (SOMS) implementation pack: a context and stakeholder register, risk assessment, control matrix, incident workflow, audit checklist and staged implementation roadmap. This provides a practical starting point for use in their own organisation.
The course is suited to security managers, operational leaders, compliance professionals and internal auditors who already understand how security services are delivered and now need to design, operate, improve or assess a formal security management system.
Course objectives
By the end of this course, participants will be able to:
- Interpret ISO 18788:2015 clauses and translate them into operational security-management requirements
- Conduct an organisational-context and interested-party analysis for a Security Operations Management System
- Build a security risk assessment using threat, vulnerability, consequence and control criteria
- Design human-rights due-diligence controls for security personnel, use of force and community interactions
- Create documented SOMS procedures for operational planning, incident reporting and corrective action
- Develop measurable security objectives, performance indicators and management-review inputs
- Prepare an ISO 18788 internal audit checklist and gather objective evidence against requirements
- Produce a phased ISO 18788 implementation roadmap for an operational security function
Benefits of attending
For you
- Gain a defensible method for converting ISO 18788 clauses into workable security-operating controls
- Build confidence to lead or contribute to a SOMS implementation, gap assessment or improvement programme
- Strengthen credibility when advising leaders on human-rights, use-of-force and security-governance controls
- Develop audit-ready documentation skills for security risks, incidents, corrective actions and performance evidence
- Leave with a practical implementation pack that can be adapted to a current security contract or operating unit
For your organisation
- Creates a repeatable framework for controlling security operations across sites, contracts and subcontractors
- Reduces exposure to inconsistent use-of-force, human-rights, incident-management and escalation practices
- Improves evidence available for client assurance, tender responses, internal governance and certification preparation
- Links security risk assessments to defined controls, responsibilities, competence requirements and performance measures
- Gives the organisation a prioritised roadmap for closing ISO 18788 gaps without disrupting live operations
Target competencies
Who should attend
- Security Managers — who must establish consistent controls across guarding, patrol, access-control or protective-security services
- Security Operations Managers — who translate client requirements and risk assessments into deployable operational procedures
- Security Compliance Managers — who need to align security policies, records and assurance activities with ISO 18788
- HSE Managers — who oversee integrated risk, incident and corrective-action arrangements affecting security operations
- Internal Auditors — who need to plan and conduct evidence-based audits of a Security Operations Management System
- Contract and Supplier Managers — who must set, monitor and assure ISO 18788 expectations for subcontracted security providers
Requirements and prerequisites
Participants should have practical experience in private security operations, security risk management, contract security, compliance, HSE, or internal auditing. They should be familiar with basic management-system concepts such as policies, procedures, risk registers, incident reporting, corrective actions and performance measures. Experience of ISO 9001, ISO 45001, ISO 31000 or another ISO management standard is helpful but not essential. Participants do not need prior ISO 18788 implementation or certification-audit experience, legal qualifications, specialist security technology skills or access to a live management system. A laptop is useful for completing workshop templates.
Training methodology
An experienced instructor leads clause-by-clause discussions using realistic private-security scenarios rather than abstract standard interpretation. Participants analyse a simulated security-services organisation, identify ISO 18788 gaps, complete risk and stakeholder registers, draft operating controls and test incident-response decisions. Small-group workshops examine subcontractor oversight, human-rights concerns and audit evidence. Each day ends with a practical artefact that becomes part of an individual implementation pack. On day five, participants present a prioritised application plan for their own operating environment and receive instructor feedback.
Course outline
Day 1: ISO 18788 foundations and organisational context
- Purpose, scope and structure of ISO 18788:2015
- Security Operations Management System process model
- Clause interpretation and documented-information requirements
- Organisational context analysis for private security services
- Interested-party needs, contractual obligations and legal requirements
- SOMS scope definition across sites, services and subcontractors
- Leadership, security policy and accountability structures
Workshop: Participants create a context, interested-party and scope statement for a simulated multi-site security provider.
Day 2: Risk, human rights and operational planning
- Security risk assessment using threat, vulnerability and consequence criteria
- Risk acceptance thresholds and treatment-selection methods
- Human-rights risk identification in private security operations
- Use-of-force policy controls and proportionality principles
- Operational planning for guarding, patrol and access-control assignments
- Client requirements, rules of engagement and post orders
- Business continuity and emergency-response planning
Workshop: Teams complete a security and human-rights risk assessment with a control-treatment plan for a high-risk client assignment.
Day 3: Operational controls, people and suppliers
- Competence criteria, vetting, licensing and training records
- Command-and-control arrangements and operational communications
- Equipment issue, maintenance and accountability controls
- Subcontractor due diligence and supplier performance requirements
- Deployment planning, shift handover and supervision records
- Information security and protection of incident evidence
- Stakeholder communication and community-engagement controls
Workshop: Participants develop an operational-control matrix linking key service risks to owners, procedures, records and verification methods.
Day 4: Incident management, performance and improvement
- Incident classification, notification and escalation workflows
- Evidence preservation, investigation and reporting principles
- Nonconformity identification and root-cause analysis
- Corrective-action planning and effectiveness verification
- Security objectives, key performance indicators and data quality
- Monitoring, measurement, analysis and evaluation requirements
- Management-review inputs, decisions and action tracking
Workshop: Participants investigate a simulated use-of-force incident and produce an incident workflow, root-cause analysis and corrective-action record.
Day 5: Internal audit and implementation roadmap
- ISO 19011 audit principles applied to security operations
- Risk-based internal audit programme design
- Audit checklists, interview questions and sampling methods
- Objective evidence for ISO 18788 clause conformity
- Audit findings, nonconformities and report writing
- Gap assessment and implementation-priority scoring
- Certification-readiness planning and continual-improvement cycles
Workshop: Participants conduct a mini audit of the case organisation and present a phased ISO 18788 implementation roadmap with priorities, owners and evidence requirements.
Tools & standards covered
ISO 18788:2015, ISO 31000:2018, ISO 19011:2018, Microsoft Excel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Dar es Salaam · USD 3,500 -
21 – 25 Sep 2026Book
Live Online · USD 1,500 -
05 – 09 Oct 2026Book
Dubai · USD 4,500 -
12 – 16 Oct 2026Book
Dar es Salaam · USD 3,500 -
12 – 16 Oct 2026Book
Cape Town · USD 4,200 -
19 – 23 Oct 2026Book
Live Online · USD 1,500 -
26 – 30 Oct 2026Book
Kigali · USD 3,500 -
02 – 06 Nov 2026Book
Live Online · USD 1,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Security Management
LenelS2 OnGuard Access Control Administration Training Course
Physical access control administration affects more than door convenience. In healthcare, industrial, utilities and corporate sites, incorre…
Security Management Fundamentals for Organizational Resilience Training Course
Security failures rarely remain isolated. A perimeter breach, protest, theft, insider threat, cyber-enabled disruption, severe weather event…
Security Management for Oil and Gas Facilities Training Course
Oil and gas facilities face security exposures that can interrupt production, endanger personnel, damage critical assets and create regulato…
Advanced Security Management for Enterprise Risk Leaders Training Course
Enterprise security leaders are expected to protect people, facilities, information, supply chains and business continuity while giving exec…