ANSI/ASIS PAP.1-2012 Physical Asset Protection
Annex B: The elements of physical asset protection – ANSI/ASIS PAP.1-2012 Physical Asset Protection

ANSI/ASIS PAP.1-2012 Physical Asset Protection B.1.2: B.1.2 Security surveys by accredited professionals, with findings followed up

A security survey, part of risk assessment and the main fact-finding tool of the PAPMS assessment programme, looks at a facility, how it operates and the policies and procedures it runs, to establish current protection status, find gaps or excess, set the needed protection level and recommend improvements; the surveyor should be able to review, verify, analyse and appraise the organization, facilities, buildings, assets and operations. Survey aims include: fixing scope and assets to protect; checking system function against requirements; identifying critical factors and interdependencies; confirming continued requirements and the resources and capability to sustain the PAPMS; reinforcing good practice, including where compliance lapses; delivering a well structured, clear, concise, accurate and complete report; and providing a baseline against which performance is later evaluated. The organization should: define survey objectives, scope and outputs; use only accredited PAP professionals with a proven survey record; have contracts, non-disclosure and due diligence agreements in place first; secure cooperation and availability of those in scope; provide the information, data, documents and references needed; grant access to facilities, buildings, assets and operating areas; support the survey and surveyor; review the report and follow up findings, observations and recommendations regularly; and check findings against the relevant risk assessments and update them. A survey can grow into an organization-wide security analysis and risk assessment, show the range of solutions and their consequences, and support security risk, continuity, response and recovery programmes.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 4.3.1 4.3.1 A formal, documented risk assessment and impact analysis with recovery time objectives

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex B: The elements of physical asset protection – ANSI/ASIS PAP.1-2012 Physical Asset Protection

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.