This curriculum spans the full lifecycle of a physical security assessment engagement, from scoping and reconnaissance to penetration testing and governance, comparable in depth to a multi-phase audit conducted across distributed enterprise facilities with layered access controls and regulatory compliance requirements.
Module 1: Defining Physical Security Scope in Vulnerability Assessments
- Selecting physical access points to include in the scan based on asset criticality and regulatory exposure.
- Determining whether to assess perimeter controls (fences, gates) or focus only on building entry points.
- Deciding whether third-party managed facilities (e.g., colocation data centers) require inclusion and under what access terms.
- Establishing boundaries between physical and cyber assessments when electronic access systems (badges, biometrics) are involved.
- Obtaining authorization for intrusive testing such as lock picking or tailgating simulations without triggering false alarms.
- Documenting exclusions for areas with safety risks (e.g., hazardous materials storage) or legal restrictions (e.g., law enforcement zones).
Module 2: Site Reconnaissance and Threat Modeling
- Conducting covert vs. overt site surveys based on organizational culture and sensitivity of operations.
- Mapping ingress/egress routes used by personnel, contractors, and delivery vehicles to identify weak control points.
- Assessing local crime data and geopolitical risks to prioritize threat vectors (e.g., smash-and-grab vs. targeted intrusion).
- Identifying blind spots in surveillance coverage using site blueprints and on-site visual verification.
- Evaluating the effectiveness of natural surveillance (lighting, landscaping, visibility) in deterring unauthorized access.
- Integrating insider threat indicators—such as unescorted visitor access—into physical vulnerability models.
Module 3: Access Control System Evaluation
- Testing electronic door controllers for default credentials, unpatched firmware, or network exposure to internal subnets.
- Assessing the reliability of multi-factor access (badge + PIN) at high-security zones under duress or bypass conditions.
- Reviewing access logs from physical security systems for anomalies such as after-hours entries or badge cloning patterns.
- Validating time-based access rules (e.g., after-hours lockdowns) through timed entry attempts during off-peak hours.
- Inspecting fail-secure vs. fail-safe configurations on doors in relation to fire code compliance and security needs.
- Testing mantrap functionality for susceptibility to tailgating or reverse egress exploitation.
Module 4: Surveillance and Detection Infrastructure Audit
- Verifying camera coverage overlap and blind spot mitigation in high-risk areas such as server rooms and loading docks.
- Assessing video retention policies against incident investigation requirements and storage capacity limits.
- Testing motion detectors and glass-break sensors for false positives and environmental interference (HVAC, lighting).
- Evaluating the encryption and network segmentation of IP-based camera systems to prevent interception or spoofing.
- Checking alarm panel responsiveness and escalation procedures during simulated intrusion events.
- Reviewing maintenance logs for cameras and sensors to identify recurring faults or unaddressed outages.
Module 5: Physical Penetration Testing Execution
- Planning lock bypass attempts using impressioning, shimming, or picking tools within legal and policy boundaries.
- Simulating social engineering attacks such as impersonation or pretexting to gain unescorted access to restricted areas.
- Testing RFID badge cloning resistance using portable readers and analyzing signal modulation characteristics.
- Conducting tailgating assessments during shift changes to measure employee adherence to access protocols.
- Deploying hidden test devices (e.g., Raspberry Pi) to evaluate detection response times and physical monitoring.
- Documenting physical evidence left behind during testing to assess forensic recovery capabilities.
Module 6: Visitor and Contractor Management Review
- Auditing visitor registration processes for consistent ID verification and escort enforcement.
- Assessing temporary badge systems for expiration enforcement and tracking of movement within facilities.
- Reviewing contractor access rights to ensure role-based limitations (e.g., HVAC techs not accessing IT rooms).
- Testing visitor log integration with security operations for real-time monitoring and incident correlation.
- Evaluating pre-visit vetting procedures, including background checks for high-risk zones.
- Inspecting procedures for collecting and deactivating visitor badges upon departure.
Module 7: Incident Response and Physical Forensics
- Validating physical alarm response times by coordinating with on-site security or external monitoring services.
- Assessing chain-of-custody procedures for seized physical evidence such as cloned badges or tampered locks.
- Reviewing integration between physical security events and SIEM systems for correlated incident detection.
- Testing communication protocols between security personnel, IT, and executive leadership during breach simulations.
- Documenting forensic readiness: availability of high-resolution video, access logs, and audit trails.
- Conducting post-incident tabletop exercises to evaluate physical containment and evidence preservation.
Module 8: Compliance, Reporting, and Remediation Governance
- Mapping identified vulnerabilities to regulatory frameworks such as ISO 27001, NIST SP 800-53, or PCI DSS physical controls.
- Prioritizing remediation based on exploit likelihood, asset value, and operational disruption cost.
- Coordinating disclosure of findings with legal and PR teams when vulnerabilities involve third-party vendors.
- Establishing timelines for retesting physical controls after remediation actions are completed.
- Integrating physical security scan results into enterprise risk registers with quantified risk scores.
- Defining ownership and accountability for physical control improvements across facilities, security, and IT teams.