Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!

Know Your Vulnerabilities

By Michael Khairallah
February 1, 2007


A vulnerability study is a comprehensive assessment of all current physical security measures and operational characteristics that affect the facility’s ability to detect, deter, delay and respond to threats.

Included in the study is an examination of the physical systems and procedures used by the response team to manage the system and respond to identified threats. During the vulnerability study, the system’s performance capabilities are tested to verify the life safety features of the systems. For example, a company may have an existing access control system. There is usually an interface between the electric locking systems and the building fire alarm system to meet fire code requirements. These interfaces are tested during the vulnerability study to ensure proper operation.

Prepare to Conduct the Survey

A vulnerability study begins with a review of the physical threat assessment. The threat assessment identifies the assets that require protection and the threats to those assets. To prepare for the vulnerability study and physical survey, develop a written plan to help keep the study on track. When conducting the study, there are many distractions. A written plan outlines the steps in the proper sequence to completion.

The plan should include at least the following:
  • An inspection of all identified assets.
  • Establishing a protected perimeter for each asset.
  • An assessment of the physical barricades that comprise the protected perimeter.
  • An identification of each opening that provides human access (of any kind) to the asset.
  • A definition of the use of that opening (e.g., ordinary and usual access, emergency exit only, freight only, etc.).
  • Means of control for each opening in each protected perimeter.
  • Lighting conditions around the protected perimeters.
  • An assessment of the means to affect the critical infrastructure that supports the asset (power, water, gas, etc.).
  • A review of employee identification procedures.
  • A review of visitor controls.
  • An evaluation of the effectiveness of existing security systems in light of identified threats.
  • A review of incident reporting procedures (if not done during the physical threat assessment).
  • A review of written security response procedures (if not done during the physical threat assessment).
  • A review of post instructions for the existing security force (if not done during the physical threat assessment).


Means and Methods

A comprehensive study includes all of the elements necessary to detect, deter, delay and respond to manmade physical security threats. The techniques used in making this determination are:

Technique 1: Inspect Asset and Establish a Perimeter

Using the floor plans and plot plans provided by the company, identify all of the assets in the protected areas. In many cases, the assets are simply the areas where work is taking place. A useful method of making these identifications is to highlight the asset in a meaningful way on the floor plans and plot plans.

Technique 2: Establish a Security Perimeter Around Each Asset

The perimeters are usually walls or fence lines that encircle the asset. Please note that the term “circle” when used to define protected perimeters is a general term and not used to mean a “round” circle. The perimeter is simply the parts of the infrastructure that enclose the asset. Often these circles follow the contours of the surrounding structure and have a variety of shapes.

Physical security perimeters are concentric circles around each asset with each succeeding circle widening and having progressively lower levels of security. In that way, the most valuable resources receive the greatest focus of security system measures. Define the perimeters on the floor and plot plans by marking the walls and fence lines that encircle the assets.

Some typical elements of perimeter development include:

  • An assessment of the likelihood of intrusion by unauthorized personnel to areas of critical assets (people or property).
  • The facility’s mission and objectives.
  • A determination of consequences of loss from perpetrators with deliberation and intent.
  • A review of existing countermeasures to threats, including emergency procedures and insurance reimbursement as a result of anticipated losses. 

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Michael Khairallah is president, Security Design Solutions of Covington, La. His book, Physical Security Systems Handbook – The Design and Implementation of Electronic Security Systems (Elsevier, Butterworth Heinemann), is available at $49.95 and can be ordered through the Elsevier Web site at www.elsevier.com or telephone (800) 545-2522 or write Elsever, Order Fulfillment, 11830 Westline Industrial Drive, St. Louis, Mo. 63146.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Soccer stadium

How the Current Iran-US Conflict May Impact World Cup Security

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Man with covered face

Why Most Workplace Violence Prevention Starts Too Late

SEC 2026 Benchmark Banner

Events

July 8, 2026

The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

LIVE: July 8, 2026 at 2 pm EDT In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Security for Next-Generation Voice and Video: Know Your Network

    See More
  • Know Your Phish: 4 Keys to Combating Spear-Phishing Campaigns

    See More
  • Know Your Disruptions

    See More

Related Products

See More Products
  • CPTED.jpg

    CPTED and Traditional Security Countermeasures: 150 Things You Should Know

  • 150 things.jpg

    Physical Security: 150 Things You Should Know 2nd Edition

  • 1119490936.jpg

    Solving Cyber Risk: Protecting Your Company and Society

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing