FAQs

What is physical security risk management?

  • Physical security risk management is the ongoing process of identifying physical threats and vulnerabilities, evaluating their potential likelihood and impact, prioritizing risks, and implementing protective measures to reduce harm to people, property, and operations.

What is the difference between a physical security risk assessment and risk management?

  • A physical security risk assessment identifies and evaluates threats, vulnerabilities, and potential consequences at a particular point in time. Risk management is the broader ongoing process of using those findings to prioritize risks, implement protective measures, monitor effectiveness, and reassess changing conditions.

What types of risks are included in physical security risk management?

  • Physical security risk management can address risks such as unauthorized access, theft, workplace violence, intrusion, vandalism, asset loss, perimeter breaches, operational disruption, and other events that could affect people, facilities, or business operations.

How often should physical security risks be reassessed?

  • There is no single reassessment schedule appropriate for every organization. Physical security should be reviewed periodically and when meaningful changes occur, such as facility expansion, operational changes, new threats, major security incidents, new technologies, or changes to the people and assets being protected. A continuous risk-management approach is more effective than treating assessment as a one-time activity.