Planning & AssessmentSelf-assessment

Business and Property Physical Security Self-Assessment Checklist

A physical security assessment examines how people, property and operations are protected through layers such as site design, lighting, access control, visitor procedures, cameras, alarms, trained personnel and emergency planning. This checklist helps a business owner or property manager conduct a documented first review, separate urgent concerns from longer-term improvements and assign an owner to each follow-up item. It is not a professional risk assessment, code inspection, insurance survey or promise that a site is secure. Conditions, operating hours, prior incidents and local requirements should be reviewed with qualified security, safety, facilities, legal and emergency-response professionals.

Why it matters

Use a system view, not a single-control view

Physical security is a system, not a single device. A well-lit entrance can still be undermined by uncontrolled keys, unclear visitor rules or an alarm notification list that is out of date.

A repeatable assessment creates a dated baseline. It helps decision-makers prioritize gaps according to actual exposure, document why improvements were selected and revisit controls as tenants, construction, staffing or site use changes.

Before you begin

How to use this checklist

  1. Choose a knowledgeable site representative and walk the property during both normal operations and, when safe, after dark.
  2. Mark Yes only when the condition is present and you can identify supporting evidence; use Not applicable only with a brief reason.
  3. Do not enter restricted, unsafe or suspicious areas to complete the checklist, and do not record access codes or camera blind spots in this public tool.
  4. Assign each Needs attention item an owner, priority and target date, then have a qualified person validate life-safety, legal and technical decisions.
  5. Repeat the review after a significant incident, renovation, occupancy change or change in operating hours.
Interactive checklist

Answer each question from current evidence

Use Not applicable only when the item genuinely does not apply, and follow the site’s approved escalation process for any urgent condition.

Section 1 of 5

Security ownership and site context

Establish who owns the process and what conditions the assessment must reflect.

01A named person is responsible for coordinating physical security decisions and follow-up.

Evidence to look for: The responsible role, backup and escalation authority are documented and known to relevant managers.

02The review considers current hours, occupancy, public access, deliveries, valuable assets and prior incidents.

Evidence to look for: Use current operational information and incident trends rather than a generic building description.

03Current emergency contacts and notification responsibilities are available to authorized personnel. Priority review item

Evidence to look for: Lists identify primary and backup contacts and are dated, controlled and accessible without exposing personal data publicly.

Section 2 of 5

Perimeter and exterior conditions

Review whether the property boundary and approaches support visibility, controlled movement and safe operations.

04Property boundaries, public areas and restricted areas are understandable to visitors and staff.

Evidence to look for: Fences, landscaping, signs, pavement markings or building design clearly distinguish intended access without creating hazards.

05Exterior lighting supports safe observation at entrances, walkways, parking and service areas.

Evidence to look for: Fixtures operate during the hours needed, avoid severe glare and do not leave obvious public-use areas unobservable.

06Landscaping, stored materials and temporary structures do not unnecessarily obstruct views or access routes.

Evidence to look for: The review includes seasonal growth, dumpsters, signs, scaffolding and other changing conditions.

07Exterior doors, gates, windows and visible hardware appear intact and close as intended. Priority review item

Evidence to look for: No forcing, bypassing or technical testing is performed; visible defects and routine operating failures are documented safely.

Section 3 of 5

Access, visitors and restricted areas

Check how authorization is granted, used, reviewed and removed.

08The number of routinely used entry points is appropriate for operations and can be supervised or monitored as planned.

Evidence to look for: Emergency exits remain available for their intended life-safety purpose and are not treated as ordinary convenience entrances.

09Employee, tenant and contractor access is authorized by role and reviewed when responsibilities change.

Evidence to look for: There is a documented method to issue, audit and promptly deactivate credentials or permissions.

10Keys, badges, fobs and other access devices are inventoried and reported promptly when missing. Priority review item

Evidence to look for: Records identify custody without publishing key identifiers, combinations or sensitive access details.

11Visitor, vendor and delivery procedures define where people check in, where they may go and when an escort is required.

Evidence to look for: Procedures match actual operations, include after-hours situations and protect visitor information according to policy.

Section 4 of 5

Detection, communication and response

Confirm that protective technology is maintained and connected to a realistic response process.

12Cameras, alarms and other detection systems have defined purposes, responsible owners and maintenance schedules.

Evidence to look for: Documentation identifies what each system is expected to support without exposing coverage gaps or system settings.

13Authorized personnel periodically verify that security technology is operating and time settings are accurate.

Evidence to look for: Checks are documented and include notification paths, storage capacity and visible equipment condition as applicable.

14Staff know how to report an emergency, a suspicious condition and a routine maintenance issue through different channels. Priority review item

Evidence to look for: Instructions distinguish 911 emergencies from internal escalation and non-emergency service requests.

15Critical security notifications have a primary and backup communication method.

Evidence to look for: The plan accounts for foreseeable phone, internet, power or staffing disruptions without publishing sensitive details.

Section 5 of 5

People, emergencies and improvement

Connect day-to-day security controls with trained people and documented follow-through.

16Relevant staff receive role-specific orientation on access, reporting and emergency procedures.

Evidence to look for: Training is understandable, documented and refreshed when procedures or responsibilities change.

17Emergency routes, assembly or shelter locations and accountability responsibilities are current and accessible. Priority review item

Evidence to look for: The arrangements address employees, visitors and people who may need assistance and align with the site emergency action plan.

18Assessment findings are prioritized, assigned and reviewed to closure.

Evidence to look for: The action log records the issue, interim measure if any, owner, target date and validation of completion.

Current result

Complete the checklist to see a summary

Results are informational and do not certify compliance or eliminate risk.

Common mistakes

What can weaken the review

  • Treating cameras as a substitute for access control, lighting, trained people or response procedures.
  • Assessing only in daylight even though the property operates after dark.
  • Recording access codes, exact patrol times or camera blind spots in a broadly shared report.
  • Marking an item complete because equipment was purchased without verifying installation, ownership and maintenance.
  • Using the checklist as proof of legal compliance or as a replacement for qualified fire, building, accessibility, insurance or security review.
Practical questions

Frequently asked questions

How often should a business complete a physical security assessment?

Use a risk-based schedule and reassess after meaningful changes such as an incident, renovation, new tenant, changed hours, new high-value assets or a major access-control change. A qualified reviewer can help set the interval for the site.

Is a physical security checklist the same as a professional security assessment?

No. This checklist is a structured screening tool. A professional assessment can examine site-specific threats, vulnerabilities, operations, technology and response capabilities in more depth and may include confidential recommendations.

Should every physical security gap be fixed the same way?

No. Select measures according to the site's actual risks, operations, legal obligations and available resources. Layered procedural, personnel and physical measures are often more useful than relying on one product.

What information should be kept out of a shared assessment?

Do not broadly distribute alarm details, access codes, exact patrol schedules, camera blind spots, sensitive floor plans or personal contact information. Store detailed findings according to the organization's access and retention rules.

Sources and evidence baseline

These references support the general planning baseline. Site-specific decisions still require the responsible organization and appropriate qualified professionals.

  1. Security Assessment at First Entry (SAFE)Cybersecurity and Infrastructure Security Agency

    Structured physical-security review, observed vulnerabilities and improvement options.

  2. NIST Special Publication 800-171 Revision 3, Physical Protection RequirementsNational Institute of Standards and Technology

    Access authorization, visitor control, access logs, keys and physical monitoring concepts.

  3. Emergency Action Plan ChecklistOccupational Safety and Health Administration

    Emergency contacts, communication, evacuation and plan-review considerations.

Source links checked: July 19, 2026