A barrier plan should start from the assets to protect, the site's boundaries and limits and a layered configuration around the asset, with the type of barrier set by criticality and by the business impact if the first and later layers fail. Barriers should support other parts of the programme such as site access control and converge with the overall plan (video surveillance, behavioural analytics, intrusion detection, patrols and staff awareness) to deter, limit the impact of a breach and improve detection of and response to barrier alerts; well-chosen barriers also make a site look a less attractive target. The organization should: assess target attractiveness (design, occupants, local or national profile, essential service role) and threat history and outlook (past, current and likely future threats) of the facility, assets, operations and community; assess overall site risk including vulnerability and accessibility; evaluate neighbouring perimeters and adjacencies; form a barrier plan and test several perimeter, outer and inner options, safety included; compare cost-effectiveness; and set response directives and procedures for routine inspection, function checks and breach remediation.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.