Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!

Completing the Vulnerability Survey

By Michael Khairallah
July 1, 2007


In the past few issues, the compilation of instructions for conducting a vulnerability study has been presented in snippets. To complete the survey, you will need to use key management strategies, understand the consequences of loss and conclude the survey in order to begin reviewing the collected data.

Key management strategies include access controls including mechanical locks and re-keying locks. Electronic security controls are not always required for every facility door. In many cases, door status switches are the only security devices needed. The door status switch will indicate to the system operators when improper door openings occur, but will not control the door.

Use mechanical locks to control doors in these cases. Prepare a key management schedule for these locks. This can be an arduous task. One of the reasons electronic security systems are required in a facility is because key management is out of control. Duplicate keys for sensitive areas are frequently given to occupants who do not have an essential need for access.

As part of an overall security plan, consider that all existing mechanical locks be re-keyed so that the existing metal keys will no longer work. Create a new set of metal keys for the re-keyed doors and institute proper distribution. Once again, documenting the possession of these metal keys will be an essential part of the overall security plan. Use a matrix to document key management. The matrix indicates which doors are keyed and who has possession of those keys.

Other reference sources are available that discuss the ways and means of using master and sub-master keying plans. It is not the intent of this column to address those issues but merely to remind the security professional that such plans exist and need to be studied carefully before a re-keying effort is made. Usually, the implementation of an electronic security system signals the re-evaluation of all security measures in a facility. But remember to issue only a minimum number of keys under any re-keying process.

Consequences of Loss

After gathering data on the facility’s security perimeters and assessing the vulnerabilities, consider the consequences of loss. Further interviews with the operations and financial employees of the company may be required to establish this analysis. The goal is to determine the impact of a violation of the security perimeter on the ongoing operation of your company.

Make a list of the critical assets of the company and then identify the ways in which you could successfully defeat the existing security measures. Next, examine what impact that attack would have on the operation and seek the assistance of company personnel in establishing a cost of that impact. Remember that the cost is not just the loss of the asset but also includes the loss of revenue in removing the asset from service. The conclusions from this analysis will help justify the investment in equipment and provide additional motivation to act.

Concluding the Survey

At the conclusion of the survey, document all findings and prepare a report for the management team. Base the conclusions of the report on the data gathered then formulate a recommendation on how best to proceed. A valid recommendation may be to do nothing at all. If your existing security measures and the facility’s configurations are adequate to protect it from the expected threats, the report can be used as a basis for the company’s decision to use resources for other operational requirements. The mission of the vulnerability study is to determine the company’s readiness to counter expected threats.

The report should detail the existing assets, the protected perimeters, the openings in the perimeters and the current methods of controlling those openings. The report should also provide the results of the tests conducted on the effectiveness of existing security systems and the life safety tests. Conclude the report with an explanation of the consequences of loss and a recommendation for improvements or changes needed to meet the company’s security goals as defined in your policy statement.

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Michael Khairallah is president, Security Design Solutions of Covington, La. His book, Physical Security Systems Handbook – The Design and Implementation of Electronic Security Systems (Elsevier, Butterworth Heinemann), is available at $49.95 and can be ordered through the Elsevier Web site at www.elsevier.com or telephone (800) 545-2522 or write Elsever, Order Fulfillment, 11830 Westline Industrial Drive, St. Louis, Mo. 63146.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

Diverse Team Collaborating on Business Analysis

12 Tips for Building an Effective Security Budget

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Nurse

Why De-Escalation Must Be Part of a Layered Safety Strategy in Healthcare

SEC 2026 Benchmark Banner

Events

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
Solutions by Sector webinar promo


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • The Door Detail Schedule

    See More
  • The Camera Detail Schedule

    See More
  • Devil in Design Details: Documenting the Preliminary System Design

    See More

Related Products

See More Products
  • Risk Analysis and the Security Survey, 4th Edition

  • s and the law.jpg

    Surveillance and the Law: Language, Power and Privacy

  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing