This unit covers the BASK's named safety and security threats and its short drug-free workplace list, then tests whether you respond to a threat as a risk to be assessed and planned for.
The named threats
Workplace violence, active shooter, theft, fraud, corporate espionage, sabotage, kidnapping and ransom, insider threat, and data breach.
Insider threat is on the list. Wage compression is compensation, adverse impact is a selection concept, and succession gaps are talent management. None appears among the BASK's safety and security threats.
Drug-free workplace
The BASK names two approaches: drug testing and treatment of substance abuse.
- Background screening and credit checks belong to employment screening.
- Wellness incentives and premium differentials are benefits design.
- Discipline and progressive termination is an employee relations process the BASK does not list here.
How the scenarios are keyed
Both keyed answers do two things at once: handle the present incident and close the planning gap, because the BASK pairs these threats with emergency and disaster preparation and response planning.
- Coworker making threats and describing building entrances, no threat assessment process: address the immediate threat and build workplace violence and active shooter preparation into the risk plan. Moving the supervisor's office relocates a target without assessing the threat. Referring to the EAP and closing the report treats a threat of violence as a support matter only. Asking the reporting employee to gather more detail delays action and puts an untrained employee in the investigative role.
- Vendor reports possible exposure of employee records, with no HR role or notification process defined: treat the data breach as an identified risk and act within the emergency response and risk process. Getting written confirmation and stopping documents the event without responding. Replacing the vendor is procurement, not response. Telling all employees their data has certainly been compromised states as certain what is not yet established.
Carry this in: act now on what you can verify, and put the threat into the risk process so the next one is not improvised.