ANSI/ASIS PAP.1-2012 Physical Asset Protection
Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection

ANSI/ASIS PAP.1-2012 Physical Asset Protection A.7.3: A.7.3 Design of controls and countermeasures (PPS design)

The PPS design should follow from the policy and risk assessment, reflect the organization's functions against its threats and vulnerabilities, and bring the parts of the PPS together as one design. The organization should design PPS by: setting objectives from the threat, vulnerability and criticality analyses so threats, vulnerabilities, targets and consequences are clear; finding cross-functional and cross-discipline interdependencies as a team; choosing the elements that lower the chance of a threat succeeding, soften consequences if it does and plan the response; assessing possible points of failure to decide on redundancy and layering; assessing the competence needed so qualified, approved and recognised protection professionals design and deploy the system; turning system criteria into design specifications (drawings, schedules, schematics) covering equipment and materials and the hardware and software needed; estimating design and life-cycle costs and budgeting from cost-benefit options; ensuring acceptance, approval, responsibility and accountability; monitoring the effectiveness of the design and design process continually; and keeping sound both the organization and whatever functions and assets the system covers. The PPS should combine people, procedures and equipment to deter, delay, detect and respond so adversaries are denied their target, with layers considered across environmental design, barriers and site hardening, entry and access control, security lighting, intrusion detection, video surveillance, electronic and network controls, personnel and administrative procedures. Every phase of the design process should be documented.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 7.3 Securing offices, rooms and facilities

ISO 28000:2022 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.