Services Fit For Purpose?
Just a few questions that we at Verrimus are obviously very interested in learning the answers to, if you have the time and are currently responsible for contracting Technical Surveillance Counter Measures services, please let us have your comments.
How do you know that the Technical Surveillance Counter Measures (TSCM)service provider that you currently use (whether an in-house team or an outsourced capability) is fit for purpose? What measures, evaluations and comparisons do you make to ensure that you are receiving the service level suitable for your organisation?
Do you seek independent peer reviews? Do you mount ‘test’ scenarios? When did your service provider last receive operational evaluation (OPEVAL) training? When was your services provider’s equipment last serviced or calibrated and underwent any necessary maintenance checks? Do you receive full debriefs, explanations, post-survey certificates with recommendations and actionable data?
How do you know that the service you are using meets your organisation’s risk appetite? Do you currently have a service contract with favourable terms for advice, briefings, internal communication strategies and ad-hoc support included? When did you last review your service provision?
What are the current viable threats to your industry sector? How does your TSCM service fit in with your overall Privacy Protection Programme? Are you faced with internal blockages or external resistance regarding TSCM requests?
We’re genuinely interested in any comments around these questions from anyone who has had experience of contracting or maintaining a TSCM service provision.