ANSI/ASIS PAP.1-2012 Physical Asset Protection
How to run physical security as a management system: a top-management policy and accountable owner, documented context and scope, a security survey and risk assessment that drive countermeasure choice, layered protection in depth, designed and commissioned physical protection systems with a maintenance and replacement life cycle, emergency command and control, exercises, audit and review, and element guidance on CPTED, site hardening, lighting, barriers, intrusion detection, access control, video surveillance, alarm monitoring and security staffing. 74 leaves read against the complete standard.
ANSI/ASIS PAP.1-2012 Physical Asset Protection is a compliance framework from United States (American National Standard, used internationally) with 4 domains and 74 controls that map to 4 other frameworks. The largest domains are Annex B: The elements of physical asset protection – ANSI/ASIS PAP.1-2012 Physical Asset Protection (39 controls), Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection (27 controls), Clause 6: Establishing the framework – ANSI/ASIS PAP.1-2012 Physical Asset Protection (6 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection
| Code | Title |
|---|---|
| ansi-asis-pap-1-2012-physical-asset-protection::A.10.1 | A.10.1 A documented PAPMS maintenance and change management programme |
| ansi-asis-pap-1-2012-physical-asset-protection::A.10.2 | A.10.2 Continual improvement of the PAPMS |
| ansi-asis-pap-1-2012-physical-asset-protection::A.2.1 | A.2.1 Resources for the PAPMS across the PPS life cycle |
| ansi-asis-pap-1-2012-physical-asset-protection::A.2.2 | A.2.2 A formal, documented communication and consultation process |
| ansi-asis-pap-1-2012-physical-asset-protection::A.3 | A.3 PAPMS documentation contents |
| ansi-asis-pap-1-2012-physical-asset-protection::A.3.1 | A.3.1 Records demonstrating conformity and results |
| ansi-asis-pap-1-2012-physical-asset-protection::A.3.2 | A.3.2 Document control procedure with integrity and access protection |
| ansi-asis-pap-1-2012-physical-asset-protection::A.4.1 | A.4.1 Procedures for legal, regulatory and other requirements |
| ansi-asis-pap-1-2012-physical-asset-protection::A.4.2 | A.4.2 A formal, documented risk assessment process kept up to date |
| ansi-asis-pap-1-2012-physical-asset-protection::A.4.2.1 | A.4.2.1 A documented security survey procedure for risk identification and exposure |
| ansi-asis-pap-1-2012-physical-asset-protection::A.4.2.2 | A.4.2.2 A documented risk treatment and countermeasure selection process |
| ansi-asis-pap-1-2012-physical-asset-protection::A.5.1 | A.5.1 PAP objectives and targets |
| ansi-asis-pap-1-2012-physical-asset-protection::A.5.2 | A.5.2 PAP programmes (action plans) to achieve objectives |
| ansi-asis-pap-1-2012-physical-asset-protection::A.6.1 | A.6.1 Roles, authority, cross-functional teams and command and control |
| ansi-asis-pap-1-2012-physical-asset-protection::A.6.2 | A.6.2 Competence, training and awareness |
| ansi-asis-pap-1-2012-physical-asset-protection::A.7.1 | A.7.1 Countermeasure procedures and a protection in depth strategy |
| ansi-asis-pap-1-2012-physical-asset-protection::A.7.2 | A.7.2 Documented performance criteria and operational control procedures |
| ansi-asis-pap-1-2012-physical-asset-protection::A.7.3 | A.7.3 Design of controls and countermeasures (PPS design) |
| ansi-asis-pap-1-2012-physical-asset-protection::A.7.4 | A.7.4 A PDCA-based physical protection systems life-cycle programme |
| ansi-asis-pap-1-2012-physical-asset-protection::A.7.5 | A.7.5 PPS maintenance, evaluation and replacement |
| ansi-asis-pap-1-2012-physical-asset-protection::A.7.6 | A.7.6 Emergencies, unusual situations and disruptive events |
| ansi-asis-pap-1-2012-physical-asset-protection::A.8.1 | A.8.1 Monitoring and measurement of PAP performance and PPS effectiveness |
| ansi-asis-pap-1-2012-physical-asset-protection::A.8.2 | A.8.2 Periodic evaluation of compliance |
| ansi-asis-pap-1-2012-physical-asset-protection::A.8.3 | A.8.3 Exercises and testing with formal post-exercise reports |
| ansi-asis-pap-1-2012-physical-asset-protection::A.8.4 | A.8.4 Nonconformities, corrective and preventive action |
| ansi-asis-pap-1-2012-physical-asset-protection::A.8.5 | A.8.5 Internal audit of the PAPMS |
| ansi-asis-pap-1-2012-physical-asset-protection::A.9 | A.9 Management review with defined inputs and outputs |
Annex B: The elements of physical asset protection – ANSI/ASIS PAP.1-2012 Physical Asset Protection
| Code | Title |
|---|---|
| ansi-asis-pap-1-2012-physical-asset-protection::B.1 | B.1 PAP system goals: protection in depth, tolerance of component failure, balanced protection and performance specifications |
| ansi-asis-pap-1-2012-physical-asset-protection::B.1.1 | B.1.1 PAP systems applied through the A.4.2 risk assessment |
| ansi-asis-pap-1-2012-physical-asset-protection::B.1.2 | B.1.2 Security surveys by accredited professionals, with findings followed up |
| ansi-asis-pap-1-2012-physical-asset-protection::B.1.3 | B.1.3 Cost-benefit analysis of controls over the full life cycle |
| ansi-asis-pap-1-2012-physical-asset-protection::B.1.4 | B.1.4 Security convergence of physical and information security risk management |
| ansi-asis-pap-1-2012-physical-asset-protection::B.1.5 | B.1.5 Crime prevention through environmental design (CPTED) |
| ansi-asis-pap-1-2012-physical-asset-protection::B.1.5.1 | B.1.5.1 Implementing CPTED |
| ansi-asis-pap-1-2012-physical-asset-protection::B.1.6 | B.1.6 Site hardening on delay in depth |
| ansi-asis-pap-1-2012-physical-asset-protection::B.1.6.1 | B.1.6.1 Site access control and perimeter delineation |
| ansi-asis-pap-1-2012-physical-asset-protection::B.1.6.2 | B.1.6.2 Implementing site hardening systems |
| ansi-asis-pap-1-2012-physical-asset-protection::B.2.1 | B.2.1 Security lighting objectives |
| ansi-asis-pap-1-2012-physical-asset-protection::B.2.2 | B.2.2 Implementing security lighting |
| ansi-asis-pap-1-2012-physical-asset-protection::B.3.1 | B.3.1 Physical barrier systems and their functions |
| ansi-asis-pap-1-2012-physical-asset-protection::B.3.2 | B.3.2 Implementing barrier systems |
| ansi-asis-pap-1-2012-physical-asset-protection::B.4.1 | B.4.1 Intrusion detection objectives |
| ansi-asis-pap-1-2012-physical-asset-protection::B.4.2 | B.4.2 Implementing intrusion detection in concentric layers |
| ansi-asis-pap-1-2012-physical-asset-protection::B.5.1 | B.5.1 Entry and access control objectives and the three identification factors |
| ansi-asis-pap-1-2012-physical-asset-protection::B.5.2 | B.5.2 Implementing entry and access control systems |
| ansi-asis-pap-1-2012-physical-asset-protection::B.6.1 | B.6.1 Defining video system parameters: purpose, retention and image quality |
| ansi-asis-pap-1-2012-physical-asset-protection::B.6.10 | B.6.10 Cost estimate |
| ansi-asis-pap-1-2012-physical-asset-protection::B.6.11 | B.6.11 Procurement and installation |
| ansi-asis-pap-1-2012-physical-asset-protection::B.6.12 | B.6.12 Training of users and administrators |
| ansi-asis-pap-1-2012-physical-asset-protection::B.6.13 | B.6.13 Policies and procedures for system use |
| ansi-asis-pap-1-2012-physical-asset-protection::B.6.14 | B.6.14 Testing: acceptance and periodic checks |
| ansi-asis-pap-1-2012-physical-asset-protection::B.6.2 | B.6.2 Video system architecture |
| ansi-asis-pap-1-2012-physical-asset-protection::B.6.3 | B.6.3 Signal and data transmission |
| ansi-asis-pap-1-2012-physical-asset-protection::B.6.4 | B.6.4 Recording methods |
| ansi-asis-pap-1-2012-physical-asset-protection::B.6.5 | B.6.5 System ownership and division of responsibility |
| ansi-asis-pap-1-2012-physical-asset-protection::B.6.6 | B.6.6 Camera selection by observation category |
| ansi-asis-pap-1-2012-physical-asset-protection::B.6.7 | B.6.7 Direct product comparisons in real placement conditions |
| ansi-asis-pap-1-2012-physical-asset-protection::B.6.8 | B.6.8 Viewing clients and monitoring requirements |
| ansi-asis-pap-1-2012-physical-asset-protection::B.6.9 | B.6.9 Video system design and specification by qualified professionals |
| ansi-asis-pap-1-2012-physical-asset-protection::B.7.1 | B.7.1 Objectives of alarms, communications and display |
| ansi-asis-pap-1-2012-physical-asset-protection::B.7.2.1 | B.7.2.1 Security considerations for the command centre |
| ansi-asis-pap-1-2012-physical-asset-protection::B.7.2.2 | B.7.2.2 Technology: network capacity, resilience and space conditioning |
| ansi-asis-pap-1-2012-physical-asset-protection::B.7.2.3 | B.7.2.3 Architectural design of the monitoring facility |
| ansi-asis-pap-1-2012-physical-asset-protection::B.7.2.4 | B.7.2.4 Technical systems: integration and monitoring by exception |
| ansi-asis-pap-1-2012-physical-asset-protection::B.8 | B.8 Personnel: involving people and choosing a security staffing model |
| ansi-asis-pap-1-2012-physical-asset-protection::B.9 | B.9 Security policies and procedures |
Clause 5: Leadership and governance – ANSI/ASIS PAP.1-2012 Physical Asset Protection
| Code | Title |
|---|---|
| ansi-asis-pap-1-2012-physical-asset-protection::5.1 | 5.1 Top management shows leadership of the physical asset protection programme |
| ansi-asis-pap-1-2012-physical-asset-protection::5.2 | 5.2 A physical asset protection policy meeting eleven conditions |
Clause 6: Establishing the framework – ANSI/ASIS PAP.1-2012 Physical Asset Protection
| Code | Title |
|---|---|
| ansi-asis-pap-1-2012-physical-asset-protection::6.1 | 6.1 A PAPMS established, run, maintained and continually improved |
| ansi-asis-pap-1-2012-physical-asset-protection::6.2 | 6.2 External and internal factors identified, evaluated and taken into account |
| ansi-asis-pap-1-2012-physical-asset-protection::6.2.1 | 6.2.1 External context defined and documented |
| ansi-asis-pap-1-2012-physical-asset-protection::6.2.2 | 6.2.2 Internal context defined and documented |
| ansi-asis-pap-1-2012-physical-asset-protection::6.2.3 | 6.2.3 Risk and resilience management context defined and documented |
| ansi-asis-pap-1-2012-physical-asset-protection::6.2.4 | 6.2.4 PAPMS scope and boundaries defined and retained |
Your Compliance Coverage
If you comply with ANSI/ASIS PAP.1-2012 Physical Asset Protection, you already cover:
Maps to 4 other frameworks
Coverage is not the same as your position
This page shows what ANSI/ASIS PAP.1-2012 Physical Asset Protection overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is ANSI/ASIS PAP.1-2012 Physical Asset Protection and who does it apply to?
ANSI/ASIS PAP.1-2012 Physical Asset Protection is a compliance framework from United States (American National Standard, used internationally) with 4 domains and 74 controls. How to run physical security as a management system: a top-management policy and accountable owner, documented context and scope, a security survey and risk assessment that drive countermeasure choice, layered protection in depth, designed and commissioned physical protection systems with a maintenance and replacement life cycle, emergency command and control, exercises, audit and review, and element guidance on CPTED, site hardening, lighting, barriers, intrusion detection, access control, video surveillance, alarm monitoring and security staffing. 74 leaves read against the complete standard. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ANSI/ASIS PAP.1-2012 Physical Asset Protection actually require?
ANSI/ASIS PAP.1-2012 Physical Asset Protection has 74 controls organised across 4 domains. The largest domains are Annex B: The elements of physical asset protection – ANSI/ASIS PAP.1-2012 Physical Asset Protection (39 controls), Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection (27 controls), Clause 6: Establishing the framework – ANSI/ASIS PAP.1-2012 Physical Asset Protection (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ANSI/ASIS PAP.1-2012 Physical Asset Protection do I already cover?
ANSI/ASIS PAP.1-2012 Physical Asset Protection maps to 4 other compliance frameworks. The top mapping partners are ISO 27002:2022 (50% coverage), ISO 28000:2022 (47% coverage), ASIS SPC.1-2009 - Organizational Resilience Standard (38% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ANSI/ASIS PAP.1-2012 Physical Asset Protection?
Start your ANSI/ASIS PAP.1-2012 Physical Asset Protection compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ANSI/ASIS PAP.1-2012 Physical Asset Protection requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 74 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.
Get Started Free →Free forever — no credit card required