ASIS Physical Asset Protection Standard Implementation Training Course

5 days Security Management Certificate on completion
Course codeSD-SM-009
Duration5 days
LevelFoundation to Intermediate
CategorySecurity Management
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Physical asset protection programmes often develop as disconnected projects: a guard contract is renewed, access control is upgraded, CCTV coverage expands, and emergency procedures sit in separate manuals. This makes it difficult for security leaders to show that controls are risk-based, proportionate, consistently governed and auditable. The ASIS Physical Asset Protection Standard provides a structured method for moving from an asset-and-threat view to a documented protection programme that management can review, fund and improve.

This five-day course shows participants how to apply the ASIS Physical Asset Protection Standard across facilities, sites and critical assets. Participants practise defining protection objectives, identifying asset criticality, conducting threat and vulnerability assessments, selecting layered countermeasures, setting performance requirements and documenting residual risk. They learn to connect physical security measures—such as perimeter protection, access control, video surveillance, intrusion detection, guarding and response procedures—to a defensible risk treatment plan rather than selecting technology in isolation.

Teaching combines instructor-led standard interpretation with worked security scenarios, team design workshops and structured reviews of sample evidence. Participants use practical templates for asset registers, risk assessment matrices, security control plans, implementation roadmaps and assurance reviews. Each participant leaves with an ASIS-aligned Physical Asset Protection Implementation Pack, adapted to a selected site or asset portfolio, which can be refined with internal stakeholders after the course.

The course is suited to security professionals building or improving an enterprise physical security programme, as well as HSE, facilities and operational leaders who need a common method for protecting people, property, information-supporting infrastructure and business continuity-critical assets.

Course objectives

By the end of this course, participants will be able to:

  • Interpret the ASIS Physical Asset Protection Standard clauses and translate them into site-level implementation requirements
  • Create an asset criticality register that identifies protection priorities, ownership and business consequences
  • Conduct a threat, vulnerability and consequence assessment using a documented risk matrix
  • Develop a layered physical protection strategy covering deterrence, detection, delay, response and recovery
  • Select proportionate access control, surveillance, intrusion detection and guarding controls against defined risks
  • Produce a physical asset protection plan with control owners, performance measures, budgets and target dates
  • Design assurance evidence and audit checks that test whether physical security controls operate as intended
  • Present an implementation roadmap that records residual risks, management decisions and improvement actions

Benefits of attending

For you

  • Gain a repeatable method for converting site security concerns into documented protection requirements
  • Build confidence in challenging technology-led security proposals against asset risks and control objectives
  • Produce ASIS-aligned plans and assurance evidence that strengthen professional credibility with senior management
  • Improve cross-functional communication with facilities, HSE, IT, operations and contracted guard providers
  • Create a portfolio-ready implementation pack demonstrating capability in physical security programme design

For your organisation

  • Establish a common standard-based process for assessing and treating physical asset protection risks across locations
  • Improve capital and operating security investment decisions through documented asset criticality and residual-risk analysis
  • Reduce control gaps created by fragmented guarding, access control, surveillance and emergency response arrangements
  • Strengthen audit readiness with defined control ownership, performance indicators and retained assurance evidence
  • Create prioritised implementation roadmaps that help leadership sequence security improvements within available budgets

Target competencies

Asset criticality analysisPhysical risk assessmentLayered protection designControl selectionSecurity assurance planningImplementation roadmapping

Who should attend

  • Security Managers — who must establish a consistent, risk-based physical protection programme across sites
  • Corporate Security Officers — who translate enterprise security policy into practical facility controls and procedures
  • HSE Managers — who need to align security risks with site safety, emergency and resilience arrangements
  • Facilities Managers — who manage buildings, contractors and security infrastructure throughout the asset lifecycle
  • Business Continuity and Resilience Managers — who depend on protected critical assets and reliable incident response arrangements
  • Project Managers and Security Consultants — who scope, deliver or assure physical security improvement projects

Requirements and prerequisites

Participants should be familiar with the basic purpose of physical security controls such as access control, CCTV, perimeter protection, visitor management and security guarding. Experience in security, facilities, HSE, resilience, operations or site management is useful because exercises use real organisational assets and operational constraints. Participants should also be comfortable reading policies, discussing risk ratings and working with simple spreadsheet tables. No prior ASIS certification, engineering qualification, specialist design software or detailed knowledge of ISO 31000 is required. A complete beginner can attend, but should expect to learn core risk and protection terminology before applying the standard.

Training methodology

The instructor introduces each stage of the ASIS Physical Asset Protection Standard, then participants apply it to a running multi-site facility scenario or an approved workplace case. Teams build asset registers, score threats and vulnerabilities, map layered controls and test response arrangements against realistic incidents. Short case discussions examine weak control integration, contractor interfaces and competing budget priorities. Facilitated peer reviews use an implementation checklist to challenge assumptions and evidence. On the final day, each participant consolidates their work into a practical implementation pack and presents priority actions for management review.

Course outline

Day 1: ASIS standard foundations and protection scope

  • Purpose, structure and implementation logic of the ASIS Physical Asset Protection Standard
  • Physical asset protection governance, policy and accountabilities
  • Defining organisational context, site boundaries and protection objectives
  • Asset categories, asset ownership and criticality criteria
  • Protection of people, property, critical infrastructure and sensitive areas
  • Stakeholder mapping for security, HSE, facilities, operations and contractors
  • Baseline evidence collection through documents, site data and control inventories

Workshop: Participants create a protection scope statement and asset criticality register for a selected site or the course case study.

Day 2: Risk assessment for physical assets

  • Threat identification using intentional, accidental and environmental threat sources
  • Vulnerability assessment of sites, buildings, processes and security operations
  • Consequence analysis for safety, operational, financial, legal and reputational impacts
  • Risk matrix design, rating definitions and risk acceptance thresholds
  • Scenario-based assessment of intrusion, theft, sabotage and unauthorised access
  • Recording existing controls, control dependencies and control weaknesses
  • Residual risk statements and escalation of unacceptable exposures

Workshop: Participants complete a threat-vulnerability-consequence assessment and produce a ranked physical asset protection risk register.

Day 3: Layered protection strategy and control selection

  • Defence-in-depth principles of deterrence, detection, delay, response and recovery
  • Perimeter, boundary and environmental design controls
  • Access control zoning, credential management and visitor management requirements
  • Video surveillance, intrusion detection and alarm monitoring performance requirements
  • Guard force deployment, patrol design and contracted security service specifications
  • Security control selection using effectiveness, feasibility, cost and operational impact criteria
  • Control treatment plans for avoidance, reduction, transfer and acceptance

Workshop: Teams design a layered protection concept for a high-criticality asset and justify each selected control against the risk register.

Day 4: Operational integration and assurance

  • Security operating procedures, post orders and response escalation workflows
  • Integration of physical security with emergency management and business continuity plans
  • Security technology interfaces, alarm response and incident information flows
  • Contractor, supplier and visitor security management controls
  • Control performance indicators for availability, response, compliance and incident trends
  • Inspection, testing, maintenance and impairment management for security systems
  • Audit evidence, nonconformity reporting and corrective action tracking

Workshop: Participants build an assurance plan containing control tests, evidence sources, performance measures and corrective-action ownership.

Day 5: Implementation planning and management review

  • Gap analysis against ASIS Physical Asset Protection Standard requirements
  • Prioritising treatment actions by risk reduction, dependency, cost and implementation effort
  • Security project charters, milestones, resources and budget assumptions
  • Risk ownership, decision records and residual-risk acceptance
  • Management review packs for protection performance and investment decisions
  • Internal communication and change management for revised security practices
  • Continual improvement cycles, lessons learned and standard reassessment

Workshop: Participants assemble and present an ASIS-aligned Physical Asset Protection Implementation Pack with a 90-day action roadmap.

Tools & standards covered

ASIS Physical Asset Protection Standard, ISO 31000:2018 Risk Management Guidelines, Microsoft Excel, Microsoft Visio

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No prior use of the standard is required. The course explains its structure and terminology before participants apply it through guided exercises, although familiarity with basic site security controls will help.

A laptop is recommended for completing the supplied spreadsheets, planning templates and implementation pack. Participants may bring non-sensitive examples of asset lists, site plans, risk registers or security procedures, subject to their organisation's information-handling rules.

It is designed for professionals who own, manage, design or assure physical security arrangements at facilities and critical sites. Security, HSE, facilities, operations, continuity and project personnel will all benefit from the common implementation method.

This course does not train participants to install or operate a particular security technology. It teaches how to select, combine, govern and assure those controls within an ASIS-aligned physical asset protection programme.

You can use the asset criticality, risk assessment, control selection and assurance templates to assess one site or asset category. The final roadmap gives a practical basis for discussing priorities, ownership and budget with management.

Participants leave with an ASIS-aligned Physical Asset Protection Implementation Pack developed during the course. It includes a scoped asset register, risk register, layered control concept, assurance plan and prioritised action roadmap.

Upcoming sessions

  • 28 Sep – 02 Oct 2026
    Dubai · USD 4,500
    Book
  • 05 – 09 Oct 2026
    Mombasa · USD 3,200
    Book
  • 12 – 16 Oct 2026
    Cape Town · USD 4,200
    Book
  • 12 – 16 Oct 2026
    Kigali · USD 3,500
    Book
  • 12 – 16 Oct 2026
    Mombasa · USD 3,200
    Book
  • 19 – 23 Oct 2026
    Nairobi · USD 3,000
    Book
  • 26 – 30 Oct 2026
    Dar es Salaam · USD 3,500
    Book
  • 09 – 13 Nov 2026
    Nairobi · USD 3,000
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Security Management

5 Days Certificate

Advanced Security Management for Enterprise Risk Leaders Training Course

Enterprise security leaders are expected to protect people, facilities, information, supply chains and business continuity while giving exec…

5 Days Certificate

Security Management for Healthcare Facility Protection Training Course

Healthcare facilities must protect patients, staff, visitors, medicines, records and critical services while remaining accessible to people …

5 Days Certificate

Genetec Security Center for Physical Security Operations Training Course

Physical security teams need to detect, verify, coordinate and document incidents without losing time between cameras, access-control events…

5 Days Certificate

Security Management for Oil and Gas Facilities Training Course

Oil and gas facilities face security exposures that can interrupt production, endanger personnel, damage critical assets and create regulato…