Physical Security Risk Assessment for Arizona Businesses: Checklist and Action Plan

A structured, plain-language method for identifying critical assets, credible threats, physical and operational vulnerabilities, consequences, existing controls, and prioritized improvements. A physical security risk assessment identifies what matters, what could harm it, where the facility or procedures are vulnerable, what controls already exist, and which improvements deserve priority.

The short answer

Start here

A physical security risk assessment identifies what matters, what could harm it, where the facility or procedures are vulnerable, what controls already exist, and which improvements deserve priority. A useful assessment produces an action plan with owners, due dates, and a method for checking whether the improvement worked—not merely a list of cameras or guards to buy. CISA describes risk as influenced by threat, vulnerability, and consequence. Its Security Assessment at First Entry program similarly uses a structured review to identify good practices, observed vulnerabilities, and options for consideration.

Key takeaways

  • Begin with people, essential operations, information, and property—not products.
  • Consider intentional acts, accidents, natural hazards, and operational failures that could affect the facility.
  • Record existing controls and evidence before recommending new ones.
  • Examine outer, middle, and inner layers: approaches and perimeter, building envelope and shared space, then critical interior assets.
  • Score risks consistently enough to compare priorities, but do not confuse a simple number with certainty.
  • Assign every accepted or mitigated risk to a decision-maker and document the rationale.

Core terms in plain language

These working definitions are consistent with CISA’s risk-management material:

  • Asset: A person, operation, service, property, system, information set, or relationship the organization values.
  • Threat or hazard: A natural or human-caused occurrence, person, entity, action, or condition with the potential to cause harm.
  • Vulnerability: A physical feature or operational attribute that leaves the organization susceptible to a particular threat or hazard.
  • Consequence: The human, operational, financial, legal, environmental, or reputational effect if the event occurs.
  • Likelihood: A reasoned estimate of how plausible the event is in the defined period and conditions. It reflects relevant threat information and vulnerability, not intuition alone.
  • Control or mitigation: A physical, procedural, personnel, or technological measure that reduces likelihood, vulnerability, or consequence.
  • Residual risk: The risk remaining after current or proposed controls are considered.

A threat is not the same as a vulnerability. Theft may be a threat; an uncontrolled loading door is a vulnerability. The lost inventory, interruption, and employee impact are consequences. A repair, access procedure, camera view, or patrol may be one part of mitigation.

The eight-step assessment process

1. Establish scope, authority, and objectives

Define what is being assessed: one facility, a campus, an event, a construction project, a particular operation, or a portfolio. Set boundaries, time horizon, and decision owner.

Create a small assessment team representing the functions that understand the site. Depending on the organization, include facilities, operations, safety, human resources, information technology, legal/privacy, executive leadership, and people who work different shifts. Include law enforcement, fire, EMS, landlord, venue, insurer, or specialized advisers when appropriate and authorized.

Document:

  • Why the assessment is being conducted
  • Who owns the result and may accept risk
  • Areas, shifts, systems, and topics included or excluded
  • Sensitive information and distribution restrictions
  • Relevant laws, contracts, insurance, lease, accreditation, or industry requirements
  • Date, team members, methods, and evidence reviewed

2. Identify critical assets and functions

Ask what the organization must protect or continue. Include:

  • Employees, customers, patients, residents, students, visitors, vendors, and responders
  • Essential operations and services
  • Cash, inventory, equipment, vehicles, tools, medication, hazardous materials, and utilities
  • Keys, credentials, access records, plans, personnel information, and sensitive business data
  • Reputation, licenses, contractual commitments, and time-sensitive deliveries
  • Dependencies such as power, water, communications, suppliers, and building access

Rank criticality. An inexpensive key may be critical because it opens a high-consequence area. A loading dock may matter because a closure stops operations even if little property is stored there.

3. Identify credible threats and hazards

Use several inputs rather than relying on recent headlines:

  • The organization’s incident, alarm, injury, access, complaint, and near-miss records
  • Local law-enforcement and emergency-management information suitable for the site
  • Employee and tenant observations, reviewed carefully for bias and accuracy
  • Property, industry, insurer, and vendor information
  • Known operating changes, disputes, events, construction, vacancies, or public exposure
  • Natural and technological hazards relevant to the location

Examples may include unauthorized entry, theft, vandalism, violence, vehicle intrusion, insider misuse, fire, medical emergencies, severe heat, power or communications failure, flooding, dust or monsoon conditions, wildfire impacts, hazardous release, and supply interruption. Not every item belongs in every assessment.

Do not label a person a threat through an informal facility checklist. Concerns about targeted violence require a trained multidisciplinary threat-assessment and management process, appropriate privacy, and legal/HR guidance.

4. Document existing controls and vulnerabilities

Observe how the site works, not only what policy says should happen. Review normal business hours, shift change, deliveries, opening/closing, and after dark where relevant.

Gather evidence such as:

  • Current floor and site plans
  • Photographs approved for the assessment
  • Access lists, key and credential records
  • Alarm, maintenance, visitor, daily activity, and incident reports
  • Post orders, emergency action plans, and continuity plans
  • Camera view tests during day and night
  • Training and exercise records
  • Repair work orders and open corrective actions

Test assumptions safely. Confirm that doors latch, emergency exits function as required, lighting works, contact lists are current, backup communications are available, and alerts reach someone authorized to act. Do not conduct covert or intrusive testing without written authorization and a safe plan.

5. Evaluate consequence and likelihood

Use a consistent scale. The following is an illustrative internal prioritization method—not an official CISA formula and not a regulatory standard.

Consequence scale

Score Working description
1 — Minimal Limited disruption or loss; handled through routine operations
2 — Minor Localized impact; short interruption; no serious injury expected
3 — Significant Material operational, financial, safety, privacy, or reputational impact
4 — Major Serious injury potential, major interruption, substantial loss, or regulatory/contract impact
5 — Severe Potential loss of life, prolonged mission failure, or catastrophic organizational effect

Likelihood scale

Score Working description
1 — Rare Not expected under current conditions; little supporting history or exposure
2 — Unlikely Plausible but limited indicators, opportunity, or history
3 — Possible Credible conditions or history exist; could occur in the assessment period
4 — Likely Repeated exposure, incidents, or clear opportunity make occurrence reasonably expected
5 — Very likely Frequent occurrence or compelling current indicators and vulnerability

Record the evidence and uncertainty behind each score. The number is less valuable than the reasoning. A low-frequency, high-consequence event may still require emergency planning even if its multiplication score is not the highest.

6. Prioritize risks without false precision

For a simple working matrix:

Initial risk score = likelihood × consequence

Score Working priority Expected action
1–4 Lower Maintain controls; monitor for change
5–9 Moderate Assign improvement or documented acceptance; review on schedule
10–16 High Develop a timely mitigation plan and interim controls
17–25 Critical Escalate promptly to leadership; implement appropriate interim action

The organization should tailor thresholds and escalation authority. Do not use a score to delay an emergency response, required legal correction, or clear life-safety action. Also consider dependencies: several individually moderate weaknesses may combine into a high-risk path.

7. Select and assign mitigations

Consider measures in layers:

  1. Remove or reduce the exposure. Change storage, scheduling, cash handling, access, or workflow where practical.
  2. Deter. Establish ownership and boundary through design, lighting, activity, signage, or visible security.
  3. Detect and assess. Use attentive personnel, alarms, cameras, sensors, reporting, and verification.
  4. Delay. Improve doors, locks, barriers, gates, glazing, key control, or compartmentation where qualified design supports it.
  5. Respond. Define who acts, when 911 is called, how people are warned, and how responders enter.
  6. Recover. Preserve records, continue essential operations, support affected people, repair controls, and capture lessons.

For each action, record the risk addressed, owner, due date, resources, interim control, expected risk reduction, dependencies, and validation method. A recommendation such as “add cameras” is incomplete without the required view, lighting, recording, monitoring, maintenance, privacy, and response process.

8. Validate, monitor, and reassess

After implementation, verify the control under relevant conditions. Examples:

  • Test the camera view during day and night.
  • Confirm an access revocation actually reaches every relevant system.
  • Time an authorized patrol route without creating unsafe shortcuts.
  • Run an approved communication exercise.
  • Review whether repaired gates continue to close and lock.
  • Examine reports for recurring conditions and incomplete corrective actions.

Reassess at a defined interval and after incidents, construction, occupancy changes, new hours, major events, system replacement, organizational change, or threat information that affects the site.

Physical security checklist by layer

Governance and planning

  • A named leader owns physical security and can assign corrective action.
  • Assessment scope, date, participants, assumptions, and exclusions are recorded.
  • Current emergency, continuity, and communication plans are available.
  • Staff know how to report suspicious behavior, hazards, access problems, and urgent threats.
  • Contact lists, 911 address information, and backup communication methods are current.
  • Security-sensitive documents and assessment results have controlled access and retention.

Outer layer: approaches, site, and perimeter

  • Property boundaries are understandable and consistent with lawful access.
  • Fences, gates, barriers, and vehicle approaches match the risks and emergency-access needs.
  • Parking, pickup/drop-off, transit, pedestrian routes, and neighboring activity are considered.
  • Landscaping, signs, stored items, and structures do not create avoidable concealment or climbing aids.
  • Lighting supports safe travel and observation without severe glare or shadow.
  • Loading, waste, utility, roof, and service access are included—not treated as “back of house” exceptions.
  • Emergency responders can locate and access the correct entrance.
  • Outdoor cameras or sensors have tested views, maintenance, and response ownership.

Middle layer: building envelope and shared space

  • Exterior doors, windows, locks, latches, hinges, and glazing are appropriate and maintained.
  • Emergency exits remain compliant and are not improperly obstructed for security.
  • Public, employee, visitor, vendor, and delivery entrances have distinct procedures where needed.
  • Reception, lobby, mail, package, and delivery areas limit unnecessary interior access.
  • Tailgating, propped-door, lost-key, and lost-credential procedures exist.
  • After-hours access and exceptions require authorization and are logged appropriately.
  • Alarm events reach a named person or service with a verified response path.
  • Shared landlord/tenant responsibilities are documented.

Inner layer: critical people, spaces, and assets

  • Sensitive or high-consequence areas have access limited to operational need.
  • Keys, master keys, badges, codes, and credentials have issuance, inventory, return, and deactivation procedures.
  • Cash, medication, high-value inventory, tools, records, and hazardous materials use appropriate controls.
  • Server, utility, control, records, and communications rooms are included.
  • Duress, medical, evacuation, shelter, or lockdown procedures are defined where appropriate.
  • Privacy is considered in camera, access-log, visitor, and incident-record practices.
  • Backup power or manual procedures support critical security functions where justified.

People, procedures, and security personnel

  • Employees receive role-appropriate security and emergency orientation.
  • Contractors, vendors, temporary staff, and volunteers follow clear access rules.
  • Opening, closing, lone-work, cash-handling, delivery, and key-control procedures are documented.
  • Security officer duties are site-specific and written in current post orders.
  • Fixed-post, patrol, camera-monitoring, and response duties are realistically staffed.
  • Officers’ Arizona registration and assignment-specific training are verified.
  • Daily and incident reports capture time, location, observations, actions, notifications, and follow-up.
  • Call-outs, missed shifts, equipment failure, and supervisor escalation are addressed.

Technology and information

  • Every camera, alarm, sensor, reader, and checkpoint has a defined purpose.
  • Field of view, lighting, power, connectivity, storage, retention, and time synchronization are checked.
  • Alert thresholds, verification, false-alarm handling, and response are documented.
  • Access privileges are reviewed and revoked promptly when roles change.
  • Vendors and administrators have only necessary access, with appropriate agreements and security.
  • Outage and manual fallback procedures are known and tested.

Arizona operating conditions and all-hazards coordination

  • Heat exposure is considered for outdoor posts, patrol duration, equipment, water, shade, and communications.
  • Dust and monsoon wind/rain effects on visibility, power, cameras, gates, and travel are considered.
  • Flood, drainage, wildfire/smoke, utility outage, and severe-weather exposure are evaluated for the actual location.
  • Physical security measures do not conflict with fire, accessibility, workplace-safety, or emergency-egress requirements.
  • Local emergency-management and public-safety information is incorporated where relevant.

Blank risk register

Asset/function Threat or hazard Vulnerability Existing controls Likelihood 1–5 Consequence 1–5 Initial score Proposed action Owner/date Residual risk/validation

Hypothetical completed example

This example is fictional and illustrates the method. It is not an assessment of an Arrow client.

Asset/function Threat or hazard Vulnerability Existing controls L C Score Proposed action
Receiving inventory and uninterrupted loading Unauthorized after-hours entry and theft Side gate sometimes remains open; camera view is obstructed; authorization list is inconsistent Perimeter fence, general lighting, incident reporting 4 3 12 — High Repair gate closure; assign roster owner; clear/test camera view; define alert recipient; use documented variable patrol checks during highest-risk window; review findings after 30 days

The score does not prove that an event will occur. Its purpose is to show why a combined procedural, physical, technology, and personnel response deserves priority. After implementation, the assessor should rescore residual risk and record evidence that the gate, roster, camera, alert, and patrol controls work.

Choosing guards, patrol, cameras, or access control

Start with the required function:

  • On-site officer: Human judgment, interaction, visible presence, fixed access administration, patrol, immediate communication, and response under post orders.
  • Mobile patrol: Intermittent documented presence and checks where continuous staffing is not required.
  • Cameras or portable towers: Observation, recording, and alerting across suitable views, with defined monitoring and response.
  • Electronic access control: Consistent credential decisions, schedules, and access records, with procedures for exceptions and outages.
  • Physical improvements: Boundary, lighting, locks, barriers, doors, sightlines, storage, and delay.
  • Procedures and training: Authorization, reporting, key control, emergency action, visitor management, and employee awareness.

Most significant risks need more than one layer. A badge reader may not detect tailgating. A camera cannot physically guide a visitor. One officer cannot watch every screen and patrol several remote areas at once. Define how the layers interact and who owns each alert or exception.

When to use a qualified professional assessment

Obtain specialized help when the facility has high-consequence operations, credible violent threats, regulated or hazardous materials, vulnerable populations, complex public access, critical infrastructure, major design changes, repeated incidents, or uncertainty about legal, engineering, privacy, fire, accessibility, or safety requirements.

Also consider government resources. CISA’s SAFE assessment is designed as a rapid structured review for facility owners and operators and produces observed good practices, vulnerabilities, mitigation options, contacts, and references. Availability and eligibility should be confirmed directly with CISA.

A professional assessment should state qualifications, scope, methods, evidence, limitations, findings, priorities, and deliverables. Before engaging a provider, confirm whether the consultation is a sales or staffing discussion, a documented assessment, or another service, and request the scope and deliverables in writing.

Frequently asked questions

What is the difference between a risk assessment and a security audit?

Usage varies. A risk assessment evaluates assets, threats, vulnerabilities, consequences, and priorities. An audit usually compares practices with defined requirements, policies, or standards. A walkthrough or sales consultation may be narrower than either. Define the scope and deliverable rather than relying on the label.

How often should a physical security assessment be completed?

Set a regular review based on the facility and risk, then reassess after incidents, material threat changes, construction, new occupancy, altered hours, major events, or new systems. A yearly review may be a workable baseline for a lower-change site, but some facilities require more frequent review based on risk, operations, incidents, and applicable requirements.

Can a checklist replace an on-site assessment?

No. A checklist can reveal obvious gaps and organize questions, but it cannot fully evaluate site context, interactions among controls, specialized requirements, or emerging threats. Use it as a first step and a record of issues requiring deeper review.

Is a camera always the best first improvement?

No. Repairing a gate, controlling keys, changing storage, improving lighting, clarifying authorization, or assigning response may reduce a risk more directly. Select measures after defining the vulnerability and desired function.

Does hiring a security guard transfer responsibility for safety or emergency planning?

No. Security duties must be clearly assigned, but the organization and other responsible employers retain their legal and operational responsibilities. Guards can support observation, communication, access, patrol, and response under post orders; they do not automatically become safety officers, emergency managers, or police.