Back to Frameworks

ANSI/ASIS PAP.1-2012 Physical Asset Protection

United States (American National Standard, used internationally)
vANSI/ASIS PAP.1-2012 (approved 24 February 2012)
4 domains
74 controls

How to run physical security as a management system: a top-management policy and accountable owner, documented context and scope, a security survey and risk assessment that drive countermeasure choice, layered protection in depth, designed and commissioned physical protection systems with a maintenance and replacement life cycle, emergency command and control, exercises, audit and review, and element guidance on CPTED, site hardening, lighting, barriers, intrusion detection, access control, video surveillance, alarm monitoring and security staffing. 74 leaves read against the complete standard.

Verified

ANSI/ASIS PAP.1-2012 Physical Asset Protection is a compliance framework from United States (American National Standard, used internationally) with 4 domains and 74 controls that map to 4 other frameworks. The largest domains are Annex B: The elements of physical asset protection – ANSI/ASIS PAP.1-2012 Physical Asset Protection (39 controls), Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection (27 controls), Clause 6: Establishing the framework – ANSI/ASIS PAP.1-2012 Physical Asset Protection (6 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection

27 controls
Controls in the Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection domain of ANSI/ASIS PAP.1-2012 Physical Asset Protection — 27 controls
CodeTitle
ansi-asis-pap-1-2012-physical-asset-protection::A.10.1A.10.1 A documented PAPMS maintenance and change management programme
ansi-asis-pap-1-2012-physical-asset-protection::A.10.2A.10.2 Continual improvement of the PAPMS
ansi-asis-pap-1-2012-physical-asset-protection::A.2.1A.2.1 Resources for the PAPMS across the PPS life cycle
ansi-asis-pap-1-2012-physical-asset-protection::A.2.2A.2.2 A formal, documented communication and consultation process
ansi-asis-pap-1-2012-physical-asset-protection::A.3A.3 PAPMS documentation contents
ansi-asis-pap-1-2012-physical-asset-protection::A.3.1A.3.1 Records demonstrating conformity and results
ansi-asis-pap-1-2012-physical-asset-protection::A.3.2A.3.2 Document control procedure with integrity and access protection
ansi-asis-pap-1-2012-physical-asset-protection::A.4.1A.4.1 Procedures for legal, regulatory and other requirements
ansi-asis-pap-1-2012-physical-asset-protection::A.4.2A.4.2 A formal, documented risk assessment process kept up to date
ansi-asis-pap-1-2012-physical-asset-protection::A.4.2.1A.4.2.1 A documented security survey procedure for risk identification and exposure
ansi-asis-pap-1-2012-physical-asset-protection::A.4.2.2A.4.2.2 A documented risk treatment and countermeasure selection process
ansi-asis-pap-1-2012-physical-asset-protection::A.5.1A.5.1 PAP objectives and targets
ansi-asis-pap-1-2012-physical-asset-protection::A.5.2A.5.2 PAP programmes (action plans) to achieve objectives
ansi-asis-pap-1-2012-physical-asset-protection::A.6.1A.6.1 Roles, authority, cross-functional teams and command and control
ansi-asis-pap-1-2012-physical-asset-protection::A.6.2A.6.2 Competence, training and awareness
ansi-asis-pap-1-2012-physical-asset-protection::A.7.1A.7.1 Countermeasure procedures and a protection in depth strategy
ansi-asis-pap-1-2012-physical-asset-protection::A.7.2A.7.2 Documented performance criteria and operational control procedures
ansi-asis-pap-1-2012-physical-asset-protection::A.7.3A.7.3 Design of controls and countermeasures (PPS design)
ansi-asis-pap-1-2012-physical-asset-protection::A.7.4A.7.4 A PDCA-based physical protection systems life-cycle programme
ansi-asis-pap-1-2012-physical-asset-protection::A.7.5A.7.5 PPS maintenance, evaluation and replacement
ansi-asis-pap-1-2012-physical-asset-protection::A.7.6A.7.6 Emergencies, unusual situations and disruptive events
ansi-asis-pap-1-2012-physical-asset-protection::A.8.1A.8.1 Monitoring and measurement of PAP performance and PPS effectiveness
ansi-asis-pap-1-2012-physical-asset-protection::A.8.2A.8.2 Periodic evaluation of compliance
ansi-asis-pap-1-2012-physical-asset-protection::A.8.3A.8.3 Exercises and testing with formal post-exercise reports
ansi-asis-pap-1-2012-physical-asset-protection::A.8.4A.8.4 Nonconformities, corrective and preventive action
ansi-asis-pap-1-2012-physical-asset-protection::A.8.5A.8.5 Internal audit of the PAPMS
ansi-asis-pap-1-2012-physical-asset-protection::A.9A.9 Management review with defined inputs and outputs

Annex B: The elements of physical asset protection – ANSI/ASIS PAP.1-2012 Physical Asset Protection

39 controls
Controls in the Annex B: The elements of physical asset protection – ANSI/ASIS PAP.1-2012 Physical Asset Protection domain of ANSI/ASIS PAP.1-2012 Physical Asset Protection — 39 controls
CodeTitle
ansi-asis-pap-1-2012-physical-asset-protection::B.1B.1 PAP system goals: protection in depth, tolerance of component failure, balanced protection and performance specifications
ansi-asis-pap-1-2012-physical-asset-protection::B.1.1B.1.1 PAP systems applied through the A.4.2 risk assessment
ansi-asis-pap-1-2012-physical-asset-protection::B.1.2B.1.2 Security surveys by accredited professionals, with findings followed up
ansi-asis-pap-1-2012-physical-asset-protection::B.1.3B.1.3 Cost-benefit analysis of controls over the full life cycle
ansi-asis-pap-1-2012-physical-asset-protection::B.1.4B.1.4 Security convergence of physical and information security risk management
ansi-asis-pap-1-2012-physical-asset-protection::B.1.5B.1.5 Crime prevention through environmental design (CPTED)
ansi-asis-pap-1-2012-physical-asset-protection::B.1.5.1B.1.5.1 Implementing CPTED
ansi-asis-pap-1-2012-physical-asset-protection::B.1.6B.1.6 Site hardening on delay in depth
ansi-asis-pap-1-2012-physical-asset-protection::B.1.6.1B.1.6.1 Site access control and perimeter delineation
ansi-asis-pap-1-2012-physical-asset-protection::B.1.6.2B.1.6.2 Implementing site hardening systems
ansi-asis-pap-1-2012-physical-asset-protection::B.2.1B.2.1 Security lighting objectives
ansi-asis-pap-1-2012-physical-asset-protection::B.2.2B.2.2 Implementing security lighting
ansi-asis-pap-1-2012-physical-asset-protection::B.3.1B.3.1 Physical barrier systems and their functions
ansi-asis-pap-1-2012-physical-asset-protection::B.3.2B.3.2 Implementing barrier systems
ansi-asis-pap-1-2012-physical-asset-protection::B.4.1B.4.1 Intrusion detection objectives
ansi-asis-pap-1-2012-physical-asset-protection::B.4.2B.4.2 Implementing intrusion detection in concentric layers
ansi-asis-pap-1-2012-physical-asset-protection::B.5.1B.5.1 Entry and access control objectives and the three identification factors
ansi-asis-pap-1-2012-physical-asset-protection::B.5.2B.5.2 Implementing entry and access control systems
ansi-asis-pap-1-2012-physical-asset-protection::B.6.1B.6.1 Defining video system parameters: purpose, retention and image quality
ansi-asis-pap-1-2012-physical-asset-protection::B.6.10B.6.10 Cost estimate
ansi-asis-pap-1-2012-physical-asset-protection::B.6.11B.6.11 Procurement and installation
ansi-asis-pap-1-2012-physical-asset-protection::B.6.12B.6.12 Training of users and administrators
ansi-asis-pap-1-2012-physical-asset-protection::B.6.13B.6.13 Policies and procedures for system use
ansi-asis-pap-1-2012-physical-asset-protection::B.6.14B.6.14 Testing: acceptance and periodic checks
ansi-asis-pap-1-2012-physical-asset-protection::B.6.2B.6.2 Video system architecture
ansi-asis-pap-1-2012-physical-asset-protection::B.6.3B.6.3 Signal and data transmission
ansi-asis-pap-1-2012-physical-asset-protection::B.6.4B.6.4 Recording methods
ansi-asis-pap-1-2012-physical-asset-protection::B.6.5B.6.5 System ownership and division of responsibility
ansi-asis-pap-1-2012-physical-asset-protection::B.6.6B.6.6 Camera selection by observation category
ansi-asis-pap-1-2012-physical-asset-protection::B.6.7B.6.7 Direct product comparisons in real placement conditions
ansi-asis-pap-1-2012-physical-asset-protection::B.6.8B.6.8 Viewing clients and monitoring requirements
ansi-asis-pap-1-2012-physical-asset-protection::B.6.9B.6.9 Video system design and specification by qualified professionals
ansi-asis-pap-1-2012-physical-asset-protection::B.7.1B.7.1 Objectives of alarms, communications and display
ansi-asis-pap-1-2012-physical-asset-protection::B.7.2.1B.7.2.1 Security considerations for the command centre
ansi-asis-pap-1-2012-physical-asset-protection::B.7.2.2B.7.2.2 Technology: network capacity, resilience and space conditioning
ansi-asis-pap-1-2012-physical-asset-protection::B.7.2.3B.7.2.3 Architectural design of the monitoring facility
ansi-asis-pap-1-2012-physical-asset-protection::B.7.2.4B.7.2.4 Technical systems: integration and monitoring by exception
ansi-asis-pap-1-2012-physical-asset-protection::B.8B.8 Personnel: involving people and choosing a security staffing model
ansi-asis-pap-1-2012-physical-asset-protection::B.9B.9 Security policies and procedures

Clause 5: Leadership and governance – ANSI/ASIS PAP.1-2012 Physical Asset Protection

2 controls
Controls in the Clause 5: Leadership and governance – ANSI/ASIS PAP.1-2012 Physical Asset Protection domain of ANSI/ASIS PAP.1-2012 Physical Asset Protection — 2 controls
CodeTitle
ansi-asis-pap-1-2012-physical-asset-protection::5.15.1 Top management shows leadership of the physical asset protection programme
ansi-asis-pap-1-2012-physical-asset-protection::5.25.2 A physical asset protection policy meeting eleven conditions

Clause 6: Establishing the framework – ANSI/ASIS PAP.1-2012 Physical Asset Protection

6 controls
Controls in the Clause 6: Establishing the framework – ANSI/ASIS PAP.1-2012 Physical Asset Protection domain of ANSI/ASIS PAP.1-2012 Physical Asset Protection — 6 controls
CodeTitle
ansi-asis-pap-1-2012-physical-asset-protection::6.16.1 A PAPMS established, run, maintained and continually improved
ansi-asis-pap-1-2012-physical-asset-protection::6.26.2 External and internal factors identified, evaluated and taken into account
ansi-asis-pap-1-2012-physical-asset-protection::6.2.16.2.1 External context defined and documented
ansi-asis-pap-1-2012-physical-asset-protection::6.2.26.2.2 Internal context defined and documented
ansi-asis-pap-1-2012-physical-asset-protection::6.2.36.2.3 Risk and resilience management context defined and documented
ansi-asis-pap-1-2012-physical-asset-protection::6.2.46.2.4 PAPMS scope and boundaries defined and retained

Your Compliance Coverage

If you comply with ANSI/ASIS PAP.1-2012 Physical Asset Protection, you already cover:

Maps to 4 other frameworks

74 total controls
ISO 27002:2022
37 source controls mapped|24 target controls covered
50%
ISO 28000:2022
35 source controls mapped|32 target controls covered
47%
ASIS SPC.1-2009 - Organizational Resilience Standard
28 source controls mapped|24 target controls covered
38%
ISO 22301:2019
2 source controls mapped|2 target controls covered
3%

Coverage is not the same as your position

This page shows what ANSI/ASIS PAP.1-2012 Physical Asset Protection overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is ANSI/ASIS PAP.1-2012 Physical Asset Protection and who does it apply to?

ANSI/ASIS PAP.1-2012 Physical Asset Protection is a compliance framework from United States (American National Standard, used internationally) with 4 domains and 74 controls. How to run physical security as a management system: a top-management policy and accountable owner, documented context and scope, a security survey and risk assessment that drive countermeasure choice, layered protection in depth, designed and commissioned physical protection systems with a maintenance and replacement life cycle, emergency command and control, exercises, audit and review, and element guidance on CPTED, site hardening, lighting, barriers, intrusion detection, access control, video surveillance, alarm monitoring and security staffing. 74 leaves read against the complete standard. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ANSI/ASIS PAP.1-2012 Physical Asset Protection actually require?

ANSI/ASIS PAP.1-2012 Physical Asset Protection has 74 controls organised across 4 domains. The largest domains are Annex B: The elements of physical asset protection – ANSI/ASIS PAP.1-2012 Physical Asset Protection (39 controls), Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection (27 controls), Clause 6: Establishing the framework – ANSI/ASIS PAP.1-2012 Physical Asset Protection (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ANSI/ASIS PAP.1-2012 Physical Asset Protection do I already cover?

ANSI/ASIS PAP.1-2012 Physical Asset Protection maps to 4 other compliance frameworks. The top mapping partners are ISO 27002:2022 (50% coverage), ISO 28000:2022 (47% coverage), ASIS SPC.1-2009 - Organizational Resilience Standard (38% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement ANSI/ASIS PAP.1-2012 Physical Asset Protection?

Start your ANSI/ASIS PAP.1-2012 Physical Asset Protection compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ANSI/ASIS PAP.1-2012 Physical Asset Protection requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 74 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.

Get Started Free →

Free forever — no credit card required