// PHYSICAL SECURITY ASSESSMENT · HANS STUDY · ONTARIO, CANADA

Physical security assessment and gap analysis

An insurer's requirements letter, a customer audit, a CPCSC contract clause, a break-in, or a site you inherited with no documentation. The question is the same each time: what does the physical security here actually do, and how far is it from what is needed?

What it covers

  • Cameras. Coverage of entries and main routes, whether recording is verified, and whether a camera identifies a face or only detects that someone is there.
  • Access control. Doors, door hardware, held-open and forced-door alarms, and who holds access and for how long.
  • Credentials. The card technology and its configuration, and how quickly a leaver's access is removed.
  • Intrusion. Detection and alarm paths around the areas that matter.
  • The network these systems sit on. Segmentation, switch configuration, and remote access, as in why your physical security system is the soft spot in your network.
  • The servers. The VMS and access control servers, which are Windows Server hosts underneath. See VMS server hardening.

What it is compared against

A gap analysis needs a yardstick. Which one depends on why you are asking: CPCSC physical protection, 03.10.x, your own standard, an insurer's requirements, or the organization's needs once the threat is written down. Nothing is measured against what a vendor would like to sell.

For credentials and doors, the floor I set in my CPCSC readiness book shows how specific the comparison gets:

  • Held-open and forced-door alarms on the doors that matter, which is a checkbox on most controllers
  • 13.56 MHz Seos or iCLASS SE with custom keys, not the standard keyset
  • Legacy and 125 kHz technologies disabled at the reader, to stop downgrade attacks
  • OSDP Secure Channel between reader and controller, and readers on current firmware
  • At least one identification-quality camera at the entry, since thermal doesn't identify and bispectral can
  • Card plus PIN on the doors that matter, matched to what the organization actually makes and protects

The book is free to read: The Study Guide to CPCSC Readiness.

What you receive

  • A ranked gap list, each gap tied to the requirement or standard it fails
  • A remediation plan in a sensible order, written so an integrator can price it
  • A written baseline of what is installed and how it is configured
  • A working session to go through the findings

How it runs

Four phases. Most of it is remote, through a screen share or the DHD, a remote access device. On-site time is quoted separately and agreed before any travel.

PH-01

Scope and standard

A call to agree which sites and systems are in, and which standard the site is compared against: CPCSC physical protection, your own standard, or an insurer requirement.

PH-02

Collect

Drawings, device lists, and configuration exports, with the VMS and access control servers and the network examined remotely, through the DHD where needed. A site walk is added where doors and camera views have to be seen in person.

PH-03

Compare

What is installed and how it is configured, set against what the standard or the organization needs. Every gap is tied to the requirement it fails.

PH-04

Report and plan

A ranked gap list and a remediation plan, walked through with you so the questions the report raises get answered.

Independent of whoever installed it

I don't resell hardware or software, I don't take commissions or finder's fees, and I don't install anything, so a gap is never a sales opportunity and the findings read the same whoever installed the system. I do hold manufacturer access agreements for technical documentation and a contact who answers hard questions, and no money moves toward this practice through them. The independence policy sets out the specifics.

Who it's for

  • Defence suppliers working toward CPCSC, where physical protection is one of the families an assessor reads
  • Organizations that inherited a physical security system with no reliable documentation
  • Owners and security managers answering an insurer or a customer audit
  • Organizations before a technology refresh or a capital project, or after an incident or a near miss

Related work

PSA-01

Health checks →

A structured look at one running platform: Genetec, Milestone, Avigilon, AXIS, C-CURE 9000, OnGuard, or EntraPass.

Questions

Does CPCSC Level 1 cover physical security?

In part. 2 of the 13 Level 1 requirements are physical: 03.10.01, physical access authorizations, and 03.10.07, physical access control. This assessment can compare a site against CPCSC physical protection, 03.10.x, as the standard.

What does a physical security assessment cover?

Cameras, access control, credentials, intrusion, the network those systems sit on, and the VMS and access control servers underneath them. Each gap is tied to the requirement or standard it fails.

What is the site compared against?

It depends on why you are asking: CPCSC physical protection, your own standard, an insurer's requirements, or the organization's needs once the threat is written down. Nothing is measured against what a vendor would like to sell.

Can this be done remotely, or does it need a site walk?

Most of it is remote, through a screen share or the DHD, a remote access device. A site walk is added where doors and camera views have to be seen in person, and on-site time is quoted separately and agreed before any travel.

Do you install or resell physical security hardware?

No. I don't resell hardware or software, I don't take commissions or finder's fees, and I don't install anything, so the findings read the same whoever installed the system.

How is the assessment priced?

The sites and systems in scope are agreed on a scoping call, and a written quote comes before any work starts. On-site time is quoted separately and agreed before any travel.

Book a scoping call

Bring the letter, the audit finding, or the clause that triggered this, and a list of the sites, and a short call confirms the scope.