Sylvie, J R (2005) Developing best practices for industrial project life cycle security and a methodology for measuring implementation. PhD thesis, University of Texas at Austin, USA.
Abstract
The intent of this research was to establish security-related best practices with respect to the delivery of capital facility projects for the industrial sector. Its purpose was to develop security best practices for implementation during the project phases of frontend planning through startup to enhance facility security throughout its life cycle. Proven construction industry best practices for project delivery were evaluated and used to identify specific security requirements. After identifying the essential security practices, these practices were categorized by security elements for organization and analysis. The practices were further grouped by project phase to assist with scoring of their use. A Security Rating Index (SRI) was developed to provide a quantitative means for determining the level of use of the practices and for assessing impacts on cost, schedule, and safety. Use of the SRI requires the selection of consequence levels, which quantify potential results of a security breach over the facility life cycle, and threat levels, which quantify the intention and capability of an adversary to undertake detrimental actions. These concepts allow comparisons to be made between projects with similar security requirements. An Internet-based questionnaire was programmed to collect project data for analysis. Following data collection, project information was analyzed to determine the relationship between project characteristics and security practice implementation. Based upon the research and data analysis, a methodology for implementing security best practices for industrial projects was developed to facilitate the adoption of the security best practices by industry. While it does not provide specific guidance for the implementation of security procedures at the project level, it offers a framework for integrating security into the project delivery process in the context of likely threats facing the facility and consequences of security breaches.
| Item Type: | Thesis (Doctoral) |
|---|---|
| Uncontrolled Keywords: | security; life cycle; project delivery; safety; best practice |
| Index terms: | construction industry, internet, implementation, level of use, project delivery, best practice, startup, life cycle, methodology, questionnaire, project data, data analysis |
| Subjects: | business, data collection methods, value management, computing systems, project delivery, data analysis and analytics, contractual arrangements, performance management, research methods, industry analysis |
| Topics: | Quality Management, Procurement, Project Management, Digital Applications, Business Strategy, Research Practice |
| Descriptive scope: | 5 PCTEA |
N.B. Descriptive scope is a count of how many of the five facets of empirical research are indicated by the words used in title, abstract and keywords. It is not intended as a judgement on the research; merely a count of the kind of word we would expect to indicate Phenomenon, Concepts, Theoretical framing, Empirical techniques, Analytical techniques. If all five are present, then a code of “5 PCTEA” will indicate this. If you feel the coding for this record is questionable, we welcome discussion around the terms we matched or the way we categorized them. The facet you would expect may not be coded, or a facet may be coded inappropriately. This can also bear on a larger question, of which facets should be treated as defining in construction management research. Please get in touch, and we will look at it. More details here