Scope and standard
A call to agree which sites and systems are in, and which standard the site is compared against: CPCSC physical protection, your own standard, or an insurer requirement.
Search hans.study
Indexed across articles, news, KB updates, knowledge base, books, learning, and tools. Press Esc to close.
// PHYSICAL SECURITY ASSESSMENT · HANS STUDY · ONTARIO, CANADA
An insurer's requirements letter, a customer audit, a CPCSC contract clause, a break-in, or a site you inherited with no documentation. The question is the same each time: what does the physical security here actually do, and how far is it from what is needed?
A gap analysis needs a yardstick. Which one depends on why you are asking: CPCSC physical protection, 03.10.x, your own standard, an insurer's requirements, or the organization's needs once the threat is written down. Nothing is measured against what a vendor would like to sell.
For credentials and doors, the floor I set in my CPCSC readiness book shows how specific the comparison gets:
The book is free to read: The Study Guide to CPCSC Readiness.
Four phases. Most of it is remote, through a screen share or the DHD, a remote access device. On-site time is quoted separately and agreed before any travel.
A call to agree which sites and systems are in, and which standard the site is compared against: CPCSC physical protection, your own standard, or an insurer requirement.
Drawings, device lists, and configuration exports, with the VMS and access control servers and the network examined remotely, through the DHD where needed. A site walk is added where doors and camera views have to be seen in person.
What is installed and how it is configured, set against what the standard or the organization needs. Every gap is tied to the requirement it fails.
A ranked gap list and a remediation plan, walked through with you so the questions the report raises get answered.
I don't resell hardware or software, I don't take commissions or finder's fees, and I don't install anything, so a gap is never a sales opportunity and the findings read the same whoever installed the system. I do hold manufacturer access agreements for technical documentation and a contact who answers hard questions, and no money moves toward this practice through them. The independence policy sets out the specifics.
A structured look at one running platform: Genetec, Milestone, Avigilon, AXIS, C-CURE 9000, OnGuard, or EntraPass.
Independent design review and pre-design assessment for access control, CCTV, and integrated systems.
Every Genetec page on the site: services, tools, field writing, and case studies.
In part. 2 of the 13 Level 1 requirements are physical: 03.10.01, physical access authorizations, and 03.10.07, physical access control. This assessment can compare a site against CPCSC physical protection, 03.10.x, as the standard.
Cameras, access control, credentials, intrusion, the network those systems sit on, and the VMS and access control servers underneath them. Each gap is tied to the requirement or standard it fails.
It depends on why you are asking: CPCSC physical protection, your own standard, an insurer's requirements, or the organization's needs once the threat is written down. Nothing is measured against what a vendor would like to sell.
Most of it is remote, through a screen share or the DHD, a remote access device. A site walk is added where doors and camera views have to be seen in person, and on-site time is quoted separately and agreed before any travel.
No. I don't resell hardware or software, I don't take commissions or finder's fees, and I don't install anything, so the findings read the same whoever installed the system.
The sites and systems in scope are agreed on a scoping call, and a written quote comes before any work starts. On-site time is quoted separately and agreed before any travel.
Bring the letter, the audit finding, or the clause that triggered this, and a list of the sites, and a short call confirms the scope.
Two tools run by default to help me understand how the site is used. You can turn either off at any time. Cloudflare's server-side analytics is always on and never sees your identity.