A site hardening effort should first name which facilities, operations and assets need protecting, set the boundaries and limits of protected spaces and configure layered protection around them. Which applications (barriers, entry control, intruder detection, surveillance, lighting, manned guarding) are needed follows from criticality ratings and the business impact if first and later layers are defeated, and each should be converged with other PAP and security systems to control site access, deter, delay, detect, deny and respond, limiting the effect of a breach; a hardened site also deters by looking a less attractive target. The organization should: assess how attractive a target the site is (its design, who occupies it, its local and regional profile, any essential service role) and its threat profile (past, present and future) of the facility, assets, operations and community; assess overall site risk including vulnerability and accessibility; evaluate neighbouring perimeters and adjacent areas; form a PAP plan and test the effectiveness of several perimeter, outer and inner options, safety included; weigh the cost-effectiveness of the options; and set response directives and operating procedures for routine inspection, function checks and fixing breaches.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.