Attention Catherine Owen

profileJoe14
FinalProjectPlanningInstrument-UMGCDirectorofSecurityInputs4.pdf

1

CCJS 345 – Introduction to Security Management

Instructions for Completing the Risk Assessment/Security and Safety Planning Instrument

Introduction

The course requirements for CCJS 345, Introduction to Security Ma na gement, include the completion of a “Risk Assessment/Secu-

rity and Safety Plan” a s the fina l project, which places students into a specific role of a security practitioner in a “real world”

security a pplica tion tha t provides them with the opportunity to demonstra te the security a nd lea dership competencies they a cquired

a nd/or enha nced during the course by discerning the weekly rea ding a ssignments, incorpora ting into the required writing a ssign-

ments substa ntive informa tion rega rding security opera tions a nd ma nagement principles ba sed on diligent a nd thorough resea rch,

a nd fully pa rticipa ting in a ll the cla ss security a nd sa fety discussion forums. Moreover, in this fina l project, our students/security

pra ctitioners ha ve the occa sion to esta blish their a ca demic credentia ls a nd skill for a ssessing a nd ma na ging risk, which is considered

by ma ny security professiona ls a s their single most importa nt function in protecting a ssets.

To fully succeed in the fina l project, our security pra ctitioners must demonstra te their a bility to a pply risk a ssessment a nd ma nage-

ment principles a nd other security pla nning a nd opera ting concepts, policies, a nd idea s studied in cla ss, pa rticula rly those a ssocia ted

with ASIS International’s “General Security Risk Assessment Guideline,” “Security Management Standard: Physical Asset

Protection,” Silva Consulta nts “Concentric Circles of Protection,” Foresight Security Risk Management’s “Risk Analysis and

the Security Survey,” a nd other security a nd sa fety source documents presented during the eight week session.

To this end, a fter receiving a site selection a uthoriza tion from their company’s “fa ux supervisor,” the security pra ctitioners will initi-

a te a ctions to conduct a risk a ssessment tha t includes thorough resea rch of the designa ted orga niza tion a nd its opera tion; conducting

a ctua l site visits to ma ke observa tions a bout current security opera tions, possible risks to a ssets, a nd physica l a nd procedura l vulner-

a bilities; a nd interviews with ra nking security or site lea dership personnel, if possible. The prima ry document students will use to

collect the informa tion required to write the “Risk Assessment/Security a nd Sa fety Plan” is the “Risk Assessment/Security and

Safety Planning Instrument” a ssembled specifica lly for this course project. The pra ctitioners, or in this ca se, the security consult-

a nts, will record their site observa tions a nd ta ke notes a s they would in a n a ctua l workpla ce, simila r to a uditor a nd investiga tor

“work papers” tha t often must be produced in regula tory a nd a dministra tive procedures or other orga niza tiona l exa mina tions a nd

inquiries to support findings discussed in the issued report. This procedure provides the consulta nts a n opportunity to fa milia rize

themselves with one of ma ny different types of a ssessment tools used by industry officia ls in a rea l world setting. The instrument,

simila r to the workpla ce, will become a pa rt of the consultant’s officia l project file a nd must be submitted a s a sepa ra te document to

the Assignments Folder by the project due da te. While this document will not receive a n individua l gra de, it will be a ssessed for the

depth in which it is completed in a n element of the fina l project-gra ding rubric. It will a lso be used to support the findings of the

prepa red report should tha t become necessa ry.

The “Risk Assessment/Security and Safety Planning Instrument” is a significa nt document tha t supports a consultant’s pursuit to

a scerta in the informa tion necessa ry to write a comprehensive report. A completed instrument must be submitted a long with the re-

port to receive a gra de for the fina l project.

Guide to Completing the “Risk Assessment/Security and Safety Planning Instrument.”

This security a nd sa fety instrument conta ins a number of questions to which consulta nts must provide a written response rega rding

their site security a nd sa fety observa tions a nd the results of a ny resea rch conducted in a rea s for which there were no opportunities to

ma ke observa tions or a scerta in informa tion from a n orga niza tion representa tive responsive to the pa rticula r question. The instru-

ment is not unlike ma ny other security survey checklists used by professiona ls to record the informa tion they need to write a report.

See the reference pa ge for ma ny different exa mples. The instrument for this project ha s been enha nced in certa in sections to a ssist

consulta nts with specific references to the course rea ding a ssignments rela ting to risk a ssessment, mitiga tion, a nd ma na gement. It

a lso provides consulta nts with tea ching points a nd exa mples to fa cilita te a nd enha nce their lea rning while completing the project.

The instrument is orga nized in a sequentia l ma nner beginning with consulta nt informa tion a nd proceeding with the va rious func-

tiona l security a nd sa fety a rea s tha t must be a ddressed in most risk a ssessments. There a re numerous a rea s for consulta nts to write

their site observa tion a nd independent resea rch notes to be used la ter when writing the fina l report.

This instrument is designed to provide consulta nts the direction necessa ry to a scerta in informa tion required to write a comprehensive

report for this course. Consulta nts will find other commercia l a nd government risk a ssessment security survey checklists used by

professiona ls conta in ma ny more deta iled questions, ma ny of a proprieta ry na ture, which would be “off limits” for our consulta nts.

2

In fa ct, consulta nts will likely be una ble to respond to some of the questions listed this Risk Assessment/Security a nd Sa fety Pla n-

ning Instrument for the sa me rea sons unless they a re fortuna te enough to identify orga niza tion officia ls willing to provide security

informa tion during successfully a rra nged interviews. Some questions a re very sensitive, but a re listed to provide consulta nts exa m-

ples of the depth a nd complexity of inquiry required when conducting a n a uthentic security survey for a n orga niza tion under a con-

tra ctua l a greement a nd a ssuming the responsibility for providing a ccura te results a nd recommenda tions.

For this project, consulta nts will complete the Risk Assessment/ Security a nd Sa fety Pla nning Instrument by writing the informa tion

requested on the form, beginning with the sections on consulta nt, genera l survey, la w enforcement, a nd risk a sset eva lua tion infor-

ma tion. Beginning with Section V. Exterior – Site Perimeter, consulta nts must review a nd respond to ea ch question by “writing ” Y

(yes) N (no) U (unknown) in the specified underlined a rea just a fter the number a fter ma king their site observa tions or determining

the informa tion a s a result of independent resea rch. There a re a number of a rea s consulta nts must a lso “briefly describe” the site a nd

fa cility cha ra cteristics, security physica l a nd procedura l controls a nd fea tures, vulnera bilities, a nd sa fety issues a nd ra mifica tions.

As mentioned a bove, consulta nts likely will be una ble to respond to certa in questions a nd will write U in the specified a rea . Some

questions rela te to very importa nt risk mitiga tion pra ctices a nd policies a nd must be a ddressed, but beca use it is sensitive a nd pri-

va te, the informa tion is not ma de a va ila ble to the public. In these situa tions, where informa tion is unknown, consulta nts will expla in

a s a note how a n organization’s security a ppa ra tus ca n be enha nced in tha t pa rticula r line of inquiry within the fra mework of the risk

ma na gement principles lea rned in cla ss. This informa tion should a lso be discussed in the fina l report. For exa mple, orga niza tions

ma y not wa nt to publicize a ll the a rea s tha t a re a la rmed in the building under review, if a ny. Ala rms a re a significa nt security con-

trol tha t must be a ddressed, so consulta nts need to note in the instrument a nd write in the report, ba sed on their a ssessment, wha t

they believe should be a la rmed in the building given the proba bility a nd critica lity of the risks identified, a s well a s the fea sibility

a nd cost considera tions. Any questions a bout this should be directed to the consultant’s fa ux supervisor.

UMUC CCJS 345

3

RISK ASSESSMENT/ SECURITY AND SAFETY PLANNING INSTRUMENT

I. CONSULTANT INFORMATION

1. Name: ___________________________________________ 2. CCJS 345 Section: _________________________________ 3. Final Project Site Selection:

a. Name of Organization/Facility - ____________________ b. Complete Site Address - __________________________ c. Instructor Site Selection Approval Date - _____________

(Attach Email Approval Document) 4. Survey Dates and Times:

a. Daylight Observations - ___________________ b. Night Observations - ___________________ Additional Comments:

II. GENERAL SURVEY INFORMATION

1. Describe the building a nd surrounding a rea of the site under review. Include a sta tement a bout the na ture a n/or mission of the

business, compa ny, or orga niza tion a nd the purpose of the building:

General Information:

2. List the norma l opera ting hours:

Hours

M-F 8am-7pm

Sa t closed

Sun closed

Holida ys closed

3. Actua l or Estima te: (Circle) a . Number of employees -750 – Ma ny telework 1-2 times per week

b. Number of visitors/vendors - 50

4

4. Site Conta ct/Assista nce Provided By (As Applica ble): a . Na me – Willia m Broga n

b. Title - Director of Secuirty c. Interview Da te – 5/6/2020 d. Phone Number - 301-985-7471

5. Employing the ASIS International’s “General Security Risk Assessment Guideline,” identify a dditiona l informa tion a bout the site tha t will a ssist you to more thoroughly understa nd the orga niza tion, its va rious a ssets, its property, a nd its opera tions.

These notes will a ssist you when dra fting the Fina l Project. (See ASIS Practice Advisory #1.)

Understanding the Organization:

All a ca demic depa rtments a re loca ted a t this loca tion. Students services offers a dvising for students. 7 cla ssrooms, Audito-

rium, computer la b a nd ca feteria . We do not rent out a ny of the spa ce to outside a gencies.

III. LAW ENFORCEMENT AND OTHER FIRST RESPONDER ASSISTANCE

1. Releva nt Police Depa rtment:

a . Na me – Prince George’s Police a re the responding a gency

b. Address - ___________________ c. Phone Number - ______________ d. Emergency Response Time to Site - ________________

e. Crime Prevention Progra ms Ava ila bility - ___________

2. Releva nt Fire/Medica l Emergency Responders

a . Na me – Prince George’s County Fire & EMS b. Address - ____________________ c. Phone Number - ______________

d. Emergency Response Time to Site - ________________ e. Fire/Medica l Sa fety Tra ining Progra m Ava ila bility - ___

IV. RISKS TO ASSETS

1. Crime Risk Eva lua tion: Using crime da ta obtained from the releva nt police depa rtment or from other independent resea rch (Uni-

form Crime Reports published by the U.S. Depa rtment of Justice, etc.) a nd persona l interviews, including informa tion provided by

the orga niza tion under review, identify the incidence of crime a nd the ca lls for service a t the site a nd in the immedia te vicinity over

the pa st two yea rs. Ana lyze the crime da ta in conjunction with demogra phic/socia l condition da ta , economic conditions in the a rea ,

popula tion densities, tra nsience of the popula tion, unemployment, etc. These notes will a ssist the consulta nt when dra fting the Fina l

Project. (See ASIS Practice Advisory #2.)

5

Crime Risk Evaluation:

Please see the UMGC Annual Safety and Security report (https://www.umgc.edu/current-students/student-life- and-support/safety-and-security/annual-report.cfm). See also the Prince George’s County crime mapping

(https://spotcrime.com/md/prince+george%27s+county) It is a secure building with two access points with manned security desks. We do not have a lot of transient people in the area. Numerous County Office buildings surround us. Next door is a DEA facility. Crime is low.

2. Non-Crimina l Risk Eva lua tion: Identify the va rious types of non-crimina l risk events tha t COULD occur a t the site ba sed histori-

ca l records of pa st incidents; risks common to the type of business; risks ba sed on geogra phic loca tions; risks common to simila rly

situa ted sites; a nd risks ba sed on recent developments a nd trends. These notes will a ssist you when dra fting the Fina l Project. (See

ASIS Practice Advisory #2.)

Non-Criminal Risk Evaluation:

The ma jority of non-crimina l situa tions we dea l with a re medica l emergencies. Ma ybe a disgruntled employee or student.

V. EXTERIOR - SITE PERIMETER

1. __N__(Y/N/U) Perimeter of the fa cility grounds is clea rly defined by a fence, wa ll, bolla rds, pla nters, vehicle ga te controls, or

other types of physica l ba rriers. Briefly describe below the type of ba rrier, height, dista nce from building, clea red a rea s, ba rbed-wire

top, roof or wa ll a rea s close to the fence, a nd its condition (da ma ged, etc.). Use the a rea below to dra w a ny dia gra ms required to

fully a pprecia te the building in rela tion to the property perimeter a nd other surrounding commercia l, residentia l, or other buildings

a nd properties.

2.__N__(Y/N/U) Ba rriers limit or control vehicle or pedestria n a ccess to the fa cility.

3.__N__ (Y/N/U) Perimeter ba rriers a re considered to be a security sa fegua rd.

4.__N__ (Y/N/U) All entra nce points to perimeter ba rriers a re gua rded or secured.

5.__N__ (Y/N/U) Perimeter ba rriers a re under surveilla nce a t a ll times.

6.__N__ (Y/N/U) Site building forms a pa rt of the perimeter ba rrier.

7.__N__ (Y/N/U) Site building forms a pa rt of the perimeter ba rrier a nd presents a

ha za rd.

9._Y___ (Y/N/U) Security officers pa trol the perimeter. If unknown,

should this be the policy? Expla in below.

6

10. __N__(Y/N/U) La ndsca ping obstruct view of security officers or surveilla nce

ca mera s or interfere with lighting or intrusion device systems.

11.__Y__ (Y/N/U) Intrusion a la rm devices protect the perimeter. If unknown,

should intrusion a la rms be insta lled? Expla in below.

Perimeter Notes:

12.__Y__ (Y/N/U) Perimeter a nd building a re protected by lighting.

13.__Y__ (Y/N/U) Lighting provides a mea ns of continuing during the hours of da rkness

the sa me degree of protection a va ila ble during da ylight hours.

14.__Y__ (Y/N/U) Lighting is positioned to overla p to provide covera ge when a bulb

burns out.

15.__Y__ (Y/N/U) Additiona l lighting is provided a t a ctive ga tes, building doors, a nd

other points (define the points) of possible intrusion.

16.__Y__ (Y/N/U) There a re provisions for emergency lighting. If unknown,

should emergency lighting be insta lled? Expla in below.

17.__Y__ (Y/N/U) Lights a re mounted to provide a strip of light both inside a nd outside

the perimeter.

18.__Y__ (Y/N/U) Lights opera te in ma nner tha t increa ses the likelihood of detecting a nd

deterring crimina l a cts on the property a nd enha nces the ca pa bility of security

ca mera s to record ima ges tha t ca n effectively reconstruct a n incident a nd

identify individua ls.

19._Y___ (Y/N/U) There is 360-degree lighting covera ge a round the exterior of the

fa cility.

21.__Y__ (Y/N/U) All lights a re working. If not, identify loca tion?

22.__Y__ (Y/N/U) Lighting ha s a n a uxilia ry source of power. If unknown,

should a uxilia ry power be insta lled? Expla in below.

7

Perimeter Lighting Notes:

23. Describe below the vulnera bilities of the employee a nd visitor pa rking lots a nd the

security fea tures currently in pla ce, if a ny. Any other notes a bout the site perimeter

ca n be listed below.

Other Perimeter Notes:

Sufficient lighting a nd ca mera s.

VI. BUILDING, INTERIOR LIGHTS, LOCKS AND SURVEILLANCE SYSTEMS/ALARMS

1. Describe below the vulnera bilities of the employee a nd visitor pa rking lots a nd the

security fea tures currently in pla ce, if a ny. Any other notes a bout the site perimeter

ca n be listed below.

Vulnerabilities, et. al. :

8

2. Describe the building design a nd composition (brick, block, concrete, meta l pa nels, gla ss exterior, etc.).

Include comments a bout the number of stories (floors) a bove a nd below ground; tota l number of

entra nces/exits a nd construction (solid core, hinges, hinge pins, etc.); ground floor windows a nd height

a nd construction; other windows a nd how they a re secured; a nd roof construction a nd openings. Also

comment on a dja cent occupancies a nd if there a re a ny security issues with those orga niza tions tha t might

impa ct the site under review in this project. Identify the dista nce in ya rds from the building to the

nea rest public street.

Comprehensive Building Description:

Concrete a nd gla ss. 3 stories + ba sement. 8 entra nces. However, ma jority of the sta ff ha ve a ccess to only two entra nces. Meta l fra me

doors with gla ss. Windows encompa ss la rge a rea of the building. They a re solid windows tha t ca nnot be opened. One roof a ccess

point from interior of the building only.

Ma jority of the buildings a long McCormick Drive a re occupied by county a gencies. To the left on the property is a secure DEA fa cil-

ity. Across the street is a n Iron Workers union ha ll. UMGC ha s a nother building a cross the street a s well.

3._N___ (Y/N/U) Public pa rks, pla za s, or other public a rea s a re immedia tely a dja cent to the building.

4.__Y__ (Y/N/U) Public tra nsit systems a re nea r the building.

5. __Y__(Y/N/U) Entra nces/exits a re supervised/controlled.

6. __Y__ (Y/N/U) Interior lighting is a ppropria te for surveilla nce by night security

gua rds, loca l la w enforcement, a nd closed circuit television covera ge.

7. __Y__ (Y/N/U) Emergency lighting is a va ila ble for power outa ges. If unknown, should a uxilia ry

power be insta lled? Expla in below.

Building Notes:

8. Describe the types of entra nce/exit door key a nd combina tion locks in use a t the fa cility.

9

Door Key and Combination Lock Notes:

All locks a re on a n electronic locking system, a ccessible via key ca rd.

9._Y___ (Y/N/U) A key control officia l ha s been a ssigned a nd is responsible for

issua nce, repla cement, a nd control of locks a nd keys. If unknown, should

there be? Expla in below.

10._Y___ (Y/N/U) Keys a re secured when not in use. If unknown, should they be

be secured? Expla in below.

11. __Y__ (Y/N/U) There is a ma ster key system with ___ ma ster keys issued. If

unknown, should there be a system? Expla in below.

12. __Y__ (Y/N/U) Key inventories a re routinely conducted. If unknown, should there

be? Expla in below.

13. __Y__ (Y/N/U) Employees a uthorized to receive keys sign for them. If unknown,

should signa tures be obta ined for a ccounta bility? Expla in below.

14. __N__ (Y/N/U) Remova l of keys from the premises is prohibited. If unknown,

should this be the policy? Expla in below.

15. __Y__ (Y/N/U) Records a re ma inta ined of those who ha ve a ccess to codes for

combina tion locks. If unknown, should such records be ma inta ined? Expla in

below.

16. __Y__ (Y/N/U) Combina tion lock codes a re cha nged routinely a nd a record of

those cha nges is ma inta ined. If unknown, should this be the policy?

Expla in below.

17. __Y__ (Y/N/U) Combina tions codes a re cha nged when a user no longer requires

a ccess. If unknown, should this be the policy? Expla in below.

18. __Y__ (Y/N/U) There is a ca rd key rea der or simila r system tha t records employee

a nd/or visitor or entries/exits. If unknown, should this be a security control

employed by the orga niza tion? Expla in below.

Key and Combination Lock Notes:

Employees a re issued key ca rds tha t a cts a s their ID ba dge a s well. Ea ch user is a ssigned their own persona l a c-

cess pla n a s a ssigned by their ma na ger a nd a pproved by security. Ba dges a re returned a t end of employment. If

not, the ca rds a re immedia tely de-a ctiva ted by security. HR provides security with sepa ra tion notices in rea l

time.

10

19. _Y___ (Y/N/U) The fa cility ha s a n intrusion a la rm system with 24/7 monitoring

ca pa bility. If unknown, should this be a security control employed by the

orga niza tion? Expla in below.

20. __Y__ (Y/N/U) There is a written policy a nd procedure for a ctiva ting a nd

dea ctiva ting this system. If unknown, should this be the policy? Expla in

below.

21. _N___(Y/N/U) The a la rm system is centra lly ma naged. If unknown, should this be

the policy? Expla in below.

22. __Y__ (Y/N/U) The a la rm system is linked a nd ma naged by a n outside priva te service

vendor/police force. I f unknown, should this be the procedure? Expla in below.

23. __Y__ (Y/N/U) The a la rm system for a ctive a rea s of the fa cility a re disenga ged

during opera tiona l hours. If unknown, should this be the policy? Expla in

below.

24. _Y___ (Y/N/U) All externa l doors, ground windows, loa ding dock a rea s, a nd

interna l doors a re covered by the a la rms. If unknown, should this be the

policy? Expla in below.

25. __N__ (Y/N/U) The a la rms a re linked to CCTV. If unknown, should the a la rms be

linked? Expla in below.

26. __Y__ (Y/N/U) There is a n emergency power source for a ll a la rms. If unknown,

should a n emergency source of power be a va ila ble? Expla in below.

Alarm Notes:

27. Describe below the other a rea s in the fa cility tha t a re a la rmed (da ta system

loca tion, sa fes, high va lue a sset stora ge a rea s, executive suite offices, duress

signa ls, etc.). Also, describe the procedures for ta king a ction when a la rms a re

a ctiva ted. If unknown, a re there other a rea s a t the fa cility tha t should be a la rmed

a nd should there be a response pla n a nd wha t might it include? Expla in below.

11

Other Alarmed Areas and Response to Alarms:

Ca shiers office ha s it’s own sepa ra te a la rm pa rtition.

28. _Y___ (Y/N/U) The fa cility employs CCTV ca mera s externa lly. Releva nt

notifica tion signs a re displa yed. (Note: A brief discussion a nd dia gra m

showing the loca tion of the ca mera s would enha nce the fina l project

presenta tion.)

29. _Y___ (Y/N/U) The fa cility employs CCTV ca mera s interna lly. (Note: A brief

discussion a nd dia gra m showing the loca tion of the ca mera s would enha nce

the fina l project presenta tion.)

30. __Y__ (Y/N/U) Recordings a re continuous ra ther tha n event a ctiva ted. If unknown,

should recordings be continuous or event a ctiva ted? Expla in below.

31. _Y___ (Y/N/U) The ca mera feed is monitored in rea l time on site. If unknown,

should the ca mera s be monitored in rea l time onsite or elsewhere? Expla in

below.

CCTV Notes:

VII. SELECTED PROCEDURAL CONTROLS

1. Describe the significa nt procedura l controls employed by the orga niza tion to protect a ssets, pa rticula rly from risks a ssoci-

a ted with interna l theft schemes. Include comments rela ted to security controls for ha ndling ca sh a nd negotia ble instruments;

inventory a nd a udit control processes; shipping a nd receiving sta nda rds; sepa ra tion of duties a nd responsibilities a mong em-

ployees, pa rticula rly for those with a uthorities rela ted to the organization’s fina ncia l ma tters. For insta nce, would it be pru-

dent for a ca shier a lso be responsible for record keeping? As a nother exa mple, might it be wise for a n orga niza tion to prohibit

the sa me employee would it be wise to ha ve the sa me employee select, a uthorize, order, a nd receive mercha ndise for the or-

ga niza tion? Wha t a bout a ccess to personnel records?

Should a n orga niza tion a llow the sa me person responsible for stocking mercha ndise or ordering compa ny equipment to con-

duct periodic inventories? How might the organization’s ma ilroom be a security cha llenge?

12

If informa tion is unknown ba sed on your observa tions a nd interviews a s a ppropria te, briefly describe (a fter conducting the

a ppropria te resea rch) wha t procedura l controls in the specific a rea s mentioned a bove would enha nce the protection of a ny

orga niza tion’s a ssets, pa rticula rly one simila r in mission a nd purpose to the site of your a ssessment.

Selected Procedural Controls:

VIII. GUARD FORCE

1.__Y__ (Y/N/U) The orga niza tion employs a gua rd force a t the fa cility. If unknown,

should a gua rd force be employed, proprieta ry or contra ctual? Expla in below

2.__Y__ (Y/N/U) Written instructions a re provided to the security gua rds rega rding their

responsibilities. If unknown, should such instructions be provided a nd wha t

informa tion might be included? Expla in below.

3. __N__ (Y/N/U) Security Gua rds a re a rmed. If unknown, should security officers a t

this site be a rmed? Expla in below.

4. __N__ (Y/N/U) The security gua rds on site a re licensed in complia nce with sta te or

other jurisdictiona l requirements. If unknown, should security officers a t this

site be licensed? Describe the sta te or jurisdictiona l licensing a nd registra tion requirements for

priva te security officers. Expla in below.

5. __Y__ (Y/N/U) Security gua rds ha ve a distinctive uniform. If unknown, should

security officers ha ve such uniforms? Expla in below.

6. __Y__ (Y/N/U) Security gua rds check employee a nd visitor identifica tions. If

unknown, should security officers ha ve such duties? Expla in below.

7. _N___ (Y/N/U) Security gua rds conduct entry a nd exit sea rches of personnel a nd/or

vehicles. If unknown, should security officers ha ve such duties? Expla in below.

8. __Y__ (Y/N/U) Security gua rds protect the entra nce reception a rea of the fa cility. If

unknown, should security officers ha ve such duties? Expla in below.

13

9. __Y__ (Y/N/U) Security gua rds ha ve a pla n to rea ct to intruders. If unknown, should

security officers rea ct to intruders a nd wha t might those a ctions include?

Expla in below.

Guard Force Notes:

IX. INTERIOR – ACCESS CONTROLS

1. _Y___ (Y/N/U) The orga niza tion issues employee a nd visitor identifica tion. If

unknown, should the orga niza tion issue such identifica tion documents?

Expla in below.

2. __Y__ (Y/N/U) Visitors a re prevented from moving a round unescorted. If unknown,

should visitors be prevented from moving a round the fa cility unescorted?

Expla in below.

3. _Y___ (Y/N/U) Employees displa y ba dges.

4. _Y___ (Y/N/U) There is visible distinction between employees a nd visitors.

Access Controls Notes:

5. Describe other fea tures of the a ccess control system a t the fa cility, i.e., electric ca rd

rea ders for employees, escorts for limited a ccess a rea s such a s the da ta center a nd

other sensitive a rea s, security post control points, visitors/vendors/shoppers enter

the fa cility from a different entra nce/exit door then employees, vehicle

identifica tion/pa rking control, etc.

14

Other Access Control Features:

Electronic ca rd rea ders for employees. Security is posted a t entra nces during opera ting hours.

X. PERSONNL SECURITY AND TRAINING

1. __Y__ (Y/N/U) Employees a re subject to ba ckground checks. If unknown,

should employees ha ve a ba ckground investiga tion completed prior to

employment a nd if so, wha t should it include? Expla in below.

2. __N__ (Y/N/U) Additiona l checks a re conducted for personnel ha ndling ca sh or

holding more sensitive a nd/supervisory positions. If unknown,

should these employees ha ve a more extensive ba ckground investiga tion

completed prior to employment, a nd if so, wha t should it include? Expla in

below.

3. _N___ (Y/N/U) Ongoing (periodic) ba ckground checks a re conducted for a ll

employees. If unknown, should employees ha ve periodic checks conducted?

Expla in below.

4. __Y__ (Y/N/U) New employees a re provided with security orienta tion a nd ongoing

security a wa reness tra ining. Wha t other tra ining is provided? If unknown, should

new employees be given such a n induction a nd tra ining, a nd if so, wha t should it

include? Expla in below.

Personnel Security and Training Notes:

XI. UTILITY CONTROL POINTS AND FIRE PROTECTION

1. Describe how utility a nd HVAC systems a re protected so a ccess is limited to only those

a uthorized. Include a discussion of the electrica l a nd telephone closets, mecha nica l a rea s,

roof a ccess, etc. Also note how a ny fuel stored in or a round the fa cility is protected a nd

how the wa ter supply is protected, if known.

15

Utilities Notes:

All utility a rea s a re secured with a ccess only given to ma intena nce sta ff a nd security sta ff. Limited I.T. sta ff ha ve a ccess

to I.T. closets. Emergency genera tor a nd it’s fuel a re secured by a 10 foot fence a nd secured entry point.

2. Describe the proa ctive fire protection systems in pla ce a t the fa cility, including whether or not the entire building is

equipped with sprinkler systems; loca tions where there a re no such systems; whether the fire a la rms a re loca l, proprieta ry, or

centra l sta tion, if known; loca tion of fire extinguishers a nd fire hose va lves, if known. Describe a ny fire esca pes or sta irwells

a t the fa cility; whether or not the fire depa rtment ha ve la dder trucks tha t ca n rea ch the top floors a nd the roof of the building;

number of a va ila ble fire hydra nts within a city block a ny direction; combustibles such a s pa int, oil, ga s, etc. stored on site;

whether eva cua tion tra ining exercises a re routinely conducted, etc. Fire Depa rtment response time?

Fire Protection Notes:

Entire fa cility is equipped with a sprinkler system. Fire a la rm system is monitored loca lly a nd by a n outside vendor a fter

hours.

XII. SAFETY AND OTHER LOSS CONTROLS

1. List the da ngerous items a nd substa nces stored a t the fa cility (wea pons, a mmunition, chemica ls, pa thogens, ra dioa ctive

ma teria l, other, etc.) a nd sta te how a nd where they a re secured. Also discuss the a ccountability procedures for these items.

Dangerous Items:

N/A

2. Given the type of orga niza tion, fa cility, or business you a re reviewing, identify the potentia l OSHA sta nda rds a pplica ble to

the site a nd note whether or not complia nce is being ma inta ined.

16

OSHA Standards and Compliance:

3. _Y___ (Y/N/U) The fa cility ha s a n Occupa nt Emergency Pla n (OEP). If unknown,

should the orga niza tion ha ve such a pla n a nd, genera lly, wha t informa tion

should be included? Expla in below.

4. _Y___ (Y/N/U) The fa cility ha s a Continuity of Opera tions Pla n (COOP. If unknown,

should the orga niza tion ha ve such a pla n a nd, genera lly, wha t informa tion

should be included ba sed on your study of the provisions of the ASIS International’s “Business

Continuity Guideline: A Practical Approach for Emergency Preparedness, Crisis

Management, and Disaster Recovery? Expla in below.

5. __YY__ (Y/N/U) The fa cility ha s tra ined OEP designees with specific a ssignments

during emergencies. If unknown, should the orga niza tion ha ve such designees?

Expla in below.

OEP and COOP Notes:

6. __Y__ (Y/N/U) There is a “Shelter in Pla ce Plan” for the fa cility. If unknown,

should the orga niza tion ha ve such a pla n? Expla in below.

7. __Y__ (Y/N/U) There is a fa cility public a ddress system. If unknown, should

the orga niza tion ha ve such a system? Expla in below. XIII. INFORMATION SECURITY 1. __Y__ (Y/N/U) The orga niza tion ha s a n a pproved informa tion security policy tha t ha s

been dissemina ted to a ll employees a nd contra ctors. If unknown, should the

orga niza tion ha ve such a pla n? Expla in below.

2.__Y__ (Y/N/U) All employees a nd contra ctors ha ve a cknowledged they understa nd the

policy a nd a gree to comply with it. If unknown, should there be a record of

employees a nd contra ctors a greeing to policy complia nce? Expla in below.

3.__Y__ (Y/N/U) The organization’s IT resources and data (e.g., computer and

network equipment, storage media, wiring closets) are physically secured

17

from unauthorized access, tampering, damage, and/or theft. If unknown, should these resources be protected from loss or ha rm? Expla in below.

4._Y___ (Y/N/U) The organization maintains a business continuity plan for its information and data support system that includes system backups, off-site data backup storage, emergency notification, replacement IT and office resources, alternate facilities, and detailed recovery procedures. If unknown, should such a pla n be implemented a nd ma inta ined? Expla in below.

Information Security Notes:

5. Describe other fea tures of the organization’s informa tion security policy a nd progra m. Include comments rega rding da ta pro-

tection techniques; pa ssword controls; orga niza tion policy for ema ils; ongoing employee tra ining rega rding informa tion security

a wa reness; prohibitions of loa ding sensitive da ta on persona l computers; a nd procedures for employees to report suspected vio-

la tions, etc.

If this informa tion is unknown a fter conducting observa tions a nd interviews a s a pplica ble, a fter conducting your own independ-

ent resea rch, note how the organization’s informa tion security progra m ca n be enha nced in ea ch of the a rea s described a bove

a nd a ny other a rea s you deem a ppropria te.

18

Information Security Notes Continued:

XIV. RECOMMENDATION NOTES FOR SITE SECURITY IMPROVEMENTS

1. Ba sed on the results of the risk a ssessment, including site observa tions, interviews conducted with officia ls from the orga ni- za tion (a s a ppropria te), a nd extensive resea rch a bout the orga niza tion, describe the physica l a nd procedura l controls you be-

lieve need to be enha nced to strengthen the organization’s current security opera tion to protect a ssets. Also, identify a nd dis-

cuss the wa ys the orga niza tion ca n more effectively prevent losses a nd ha rm from a ccidents, emergencies, a nd na tura l disa sters,

a nd when such risk events do occur, initia te a proficient response to mitiga te da ma ge to the organization’s property a nd re-

sources.

When considering the possible security a nd sa fety control options to mitiga te risks (See ASIS Practice Advisory #5), be sure

to consider the fea sibility of implementing the options (See ASIS Practice Advisory #6) a long with a ba sic cost/benefit eva lu-

a tion (See ASIS Practice Advisory #7). Also, you should identify the priority of the recommenda tions with supporting justifi-

ca tions.

19

Prioritized Recommendations:

XV. CONSULTANT RESEARCH AND OTHER SUPPORTING PROJECT NOTES

20

REFERENCES

This CCJS 345 Risk Assessment/Security a nd Sa fety Pla nning Instrument wa s developed using the following sources:

Ha lkyn Consulting Ltd. (2010). Physical Security Assessment Form. Flintshire, UK. Retrieved August 1, 2017 a t:

http://www.ha lkynconsulting.co.uk/security -resources/downloa ds/physical_security_assessment_form.pdf

ISACA. (No Da te). Physical Security Survey Checklist. Rolling Hills, IL. Retrieved August 1, 2017 a t:

http://www.isa ca .org/Groups/Professiona l-English/physica l-security/GroupDocuments/physica lsecurity.pdf

University of Illinois a t Urba na . (2006). Risk Management Audit Checklist. Urba na , IL. Retrieved August 1, 2017 a t:

http://citebm.business.illinois.edu/TWC%20Cla ss/Project_reports_Spring2006/Business%20Risk%20Ma nagement/Manzoor/Au-

dit%20Checkilist.pdf

21

U.S. Depa rtment of Agriculture. (No Da te). USDA Physical Security Inspection Checklist. Wa shington, D.C. Retrieved August 1,

2017 a t: https://www.dm.usda .gov/physica lsecurity/physica lcheck.pdf

U.S. Fish a nd Wildlife Service. (2016). Physical Security Survey – Level 3. Wa shington, D.C. Retrieved August 1, 2017 a t:

https://www.fws.gov/forms/3-2419.pdf

U.S. Geologica l Survey. 2005. Physical Security Survey Checklist. Wa shington, D.C. Retrieved August 1, 2017 a t:

https://www2.usgs.gov/usgs-ma nua l/ha ndbook/hb/440-2-h/440-2-h-a ppc.pdf

Consulta nts ca n enha nce their study, understa nding, a nd a pplica tion of risk a ssessment a nd ma nagement processes by reviewing the

following sources:

America n Ba nkers Associa tion. (2003). Physical Security Checklist and Inventory. Wa shington, D.C.

Retrieved August 1, 2017 a t: https://www.a ba .com/aba/toolbox/brd/1tool.pdf

America n Red Cross. (2012 ). Multi-Building Physical Security Checklist. Retrieved August 1, 2017 a t: http://www.rea dyra t-

ing.org/Porta ls/1/PropertyAgent/2255/Files/26/Rea dy%20Ra ting%20 -%20SAMPLE%20Building%20Security%20Checklist.docx

ASIS Founda tion. (2007). ASIS.SIA Risk Assessment Survey: Results a nd Ana lysis. Alexa ndria , VA. Retrieved August 1, 2017 a t:

https://foundation.asisonline.org/Founda tionResearch/Publica tions/Documents/asis -sia RickAssessment.pdf

Austra lia n Hotels Associa tion (South Austra lia n Bra nch). (2013). AHAISA Hotel Security Assessment Checklist. Retrieved August 1,

2017 a t: http://www.a ha sa.com.au/__files/f/4010/AHA_Security_Assessment_Checklist.pdf

Broomfield Police Depa rtment (No Da te). Construction Site Security Survey Checklist. Broomfield, CO. Retrieved August 1, 2017

a t: https://www.broomfield.org/DocumentCenter/View/3380

Depa rtment of the Army. (2010). Physical Security. Wa shington, D.C. Retrieved August 1, 2017 a t: https://fas.org/irp/dod- dir/a rmy/a ttp3-39-32.pdf

Depa rtment of Homela nd Security. (No Da te). Risk Assessment. Wa shington, D.C. Retrieved August 1, 2017 a t:

https://www.rea dy.gov/risk-a ssessment

Federa l Emergency Ma na gement Agency. (No Da te). Building Vulnera bility Assessment Checklist. Wa shington, D.C. Retrieved

August 1, 2017 a t: https://www.fema .gov/media -libra ry-da ta/20130726-1524-20490-4937/fema452_a.pdf

Foresight Security Risk Ma na gement. (2013). Risk Analysis and the Security Survey. Retrieved August 1, 2017 a t: https://foresight-

securityriskma na gement.wordpress.com/about/

Ga rdner, Robert A. a nd Wolf Avia tion. (2002). Rural & Small Town Airport

Security Manual and Checklist. La s Vega s, NV. Retrieved August 1, 2017 a t: http://www.crimewise.com/a irport/ma nua l.pdf HELPNET SECURITY. (No Da te). Information Security Checklist. Retrieved August 1, 2017 a t: https://www.helpnetsecu-

rity.com/2003/09/08/information -security-checklist/

Ka ba y, M.E.. (2012). Facilities and Security Audit Checklist. Northfield, VT. Retrieved August 1, 2017 a t: http://www.meka ba y.com/infosecmgmt/facilities_checklist.pdf

Missouri Depa rtment of Hea lth a nd Senior Services. (2011). Sample Threat/Risk Assessment Checklist.

Retrieved August 1, 2017 a t: http://health.mo.gov/emergencies/pedia trictoolkit/SchoolResources/SampleRisk -Threa tAssessment-

Checklist.pdf

Na tiona l Clea ringhouse for Educa tiona l Fa cilities. (No Da te). NCEF Safe School Facilities Checklist. Wa shington, D.C. Retrieved

August 1, 2017 a t: http://www.ct.gov/demhs/lib/demhs/school_security/school_safety_checklist.pdf

22

Richa rdson Police Depa rtment. (No Da te). Home Security Assessment Checklist. Richa rdson, TX. Retrieved August 1, 2017 a t:

https://www.cor.net/modules/showdocument.a spx?documentid=298

Rowe, Tina Lewis. (2009). How to Assess the Safety and Security of Your Place of Worship. Denver, CO. Retrieved August 1, 2017

a t: https://www.sa nta rosa.fl.gov/coad/documents/SafetyinChurch.pdf Sa ns Technology Institute. (2015). Physica l Security. Retrieved August 1, 2017 a t:

https://www.sa ns.edu/cyber-resea rch/security-la bora tory/article/281

Siva Consulta nts. (2017). Physical Security Assessments. Covington, Wa shington. Retrieved August 1, 2017 a t: http://silva consult-

a nts.com/physical-security-a ssessments-by-silva -consulta nts.html

U.S. Depa rtment of Agriculture. (No Da te). Risk Based Methodology for Physical Security Assessments. Washington, D.C. Re-

trieved August 1, 2017 a t: https://www.dm.usda .gov/physica lsecurity/riskma nagementapproachpresentation.pdf

West Virginia Depa rtment of Hea lth a nd Human Services. (No Da te). Risk Assessment – Informa tion Security Policy. Sta te of Wet

Virginia . Retrieved August 1, 2017 a t: https://www.wvdhhr.org/ha n/security/Riskchecklist.pdf

SRMC. (2013). Pima Community College Security Assessment Report and Recommendations. Columbus, Ohio. Retrieved August 1,

2017 a t: https://www.pima .edu/a dministra tive-services/college-police/docs/security-risk-report.pdf

Tech Republic Aca demy. (2010). Perform a Physica l Security ga p Ana lysis. http://www.techrepublic.com/blog/it-security/perform-

a -physica l-security-ga p-a na lysis/

Va ngua rd Surveilla nce a nd Security. (No Da te). 7 Step Security Survey. Retrieved August 1, 2017 a t: http://www.va ngua rd-

sa s.co.uk/contents/en-uk/d26.html

Revised: November 7, 2017