ASIS Physical Asset Protection Standard Implementation Training Course
| Course code | SD-SM-009 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Security Management |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Physical asset protection programmes often develop as disconnected projects: a guard contract is renewed, access control is upgraded, CCTV coverage expands, and emergency procedures sit in separate manuals. This makes it difficult for security leaders to show that controls are risk-based, proportionate, consistently governed and auditable. The ASIS Physical Asset Protection Standard provides a structured method for moving from an asset-and-threat view to a documented protection programme that management can review, fund and improve.
This five-day course shows participants how to apply the ASIS Physical Asset Protection Standard across facilities, sites and critical assets. Participants practise defining protection objectives, identifying asset criticality, conducting threat and vulnerability assessments, selecting layered countermeasures, setting performance requirements and documenting residual risk. They learn to connect physical security measures—such as perimeter protection, access control, video surveillance, intrusion detection, guarding and response procedures—to a defensible risk treatment plan rather than selecting technology in isolation.
Teaching combines instructor-led standard interpretation with worked security scenarios, team design workshops and structured reviews of sample evidence. Participants use practical templates for asset registers, risk assessment matrices, security control plans, implementation roadmaps and assurance reviews. Each participant leaves with an ASIS-aligned Physical Asset Protection Implementation Pack, adapted to a selected site or asset portfolio, which can be refined with internal stakeholders after the course.
The course is suited to security professionals building or improving an enterprise physical security programme, as well as HSE, facilities and operational leaders who need a common method for protecting people, property, information-supporting infrastructure and business continuity-critical assets.
Course objectives
By the end of this course, participants will be able to:
- Interpret the ASIS Physical Asset Protection Standard clauses and translate them into site-level implementation requirements
- Create an asset criticality register that identifies protection priorities, ownership and business consequences
- Conduct a threat, vulnerability and consequence assessment using a documented risk matrix
- Develop a layered physical protection strategy covering deterrence, detection, delay, response and recovery
- Select proportionate access control, surveillance, intrusion detection and guarding controls against defined risks
- Produce a physical asset protection plan with control owners, performance measures, budgets and target dates
- Design assurance evidence and audit checks that test whether physical security controls operate as intended
- Present an implementation roadmap that records residual risks, management decisions and improvement actions
Benefits of attending
For you
- Gain a repeatable method for converting site security concerns into documented protection requirements
- Build confidence in challenging technology-led security proposals against asset risks and control objectives
- Produce ASIS-aligned plans and assurance evidence that strengthen professional credibility with senior management
- Improve cross-functional communication with facilities, HSE, IT, operations and contracted guard providers
- Create a portfolio-ready implementation pack demonstrating capability in physical security programme design
For your organisation
- Establish a common standard-based process for assessing and treating physical asset protection risks across locations
- Improve capital and operating security investment decisions through documented asset criticality and residual-risk analysis
- Reduce control gaps created by fragmented guarding, access control, surveillance and emergency response arrangements
- Strengthen audit readiness with defined control ownership, performance indicators and retained assurance evidence
- Create prioritised implementation roadmaps that help leadership sequence security improvements within available budgets
Target competencies
Who should attend
- Security Managers — who must establish a consistent, risk-based physical protection programme across sites
- Corporate Security Officers — who translate enterprise security policy into practical facility controls and procedures
- HSE Managers — who need to align security risks with site safety, emergency and resilience arrangements
- Facilities Managers — who manage buildings, contractors and security infrastructure throughout the asset lifecycle
- Business Continuity and Resilience Managers — who depend on protected critical assets and reliable incident response arrangements
- Project Managers and Security Consultants — who scope, deliver or assure physical security improvement projects
Requirements and prerequisites
Participants should be familiar with the basic purpose of physical security controls such as access control, CCTV, perimeter protection, visitor management and security guarding. Experience in security, facilities, HSE, resilience, operations or site management is useful because exercises use real organisational assets and operational constraints. Participants should also be comfortable reading policies, discussing risk ratings and working with simple spreadsheet tables. No prior ASIS certification, engineering qualification, specialist design software or detailed knowledge of ISO 31000 is required. A complete beginner can attend, but should expect to learn core risk and protection terminology before applying the standard.
Training methodology
The instructor introduces each stage of the ASIS Physical Asset Protection Standard, then participants apply it to a running multi-site facility scenario or an approved workplace case. Teams build asset registers, score threats and vulnerabilities, map layered controls and test response arrangements against realistic incidents. Short case discussions examine weak control integration, contractor interfaces and competing budget priorities. Facilitated peer reviews use an implementation checklist to challenge assumptions and evidence. On the final day, each participant consolidates their work into a practical implementation pack and presents priority actions for management review.
Course outline
Day 1: ASIS standard foundations and protection scope
- Purpose, structure and implementation logic of the ASIS Physical Asset Protection Standard
- Physical asset protection governance, policy and accountabilities
- Defining organisational context, site boundaries and protection objectives
- Asset categories, asset ownership and criticality criteria
- Protection of people, property, critical infrastructure and sensitive areas
- Stakeholder mapping for security, HSE, facilities, operations and contractors
- Baseline evidence collection through documents, site data and control inventories
Workshop: Participants create a protection scope statement and asset criticality register for a selected site or the course case study.
Day 2: Risk assessment for physical assets
- Threat identification using intentional, accidental and environmental threat sources
- Vulnerability assessment of sites, buildings, processes and security operations
- Consequence analysis for safety, operational, financial, legal and reputational impacts
- Risk matrix design, rating definitions and risk acceptance thresholds
- Scenario-based assessment of intrusion, theft, sabotage and unauthorised access
- Recording existing controls, control dependencies and control weaknesses
- Residual risk statements and escalation of unacceptable exposures
Workshop: Participants complete a threat-vulnerability-consequence assessment and produce a ranked physical asset protection risk register.
Day 3: Layered protection strategy and control selection
- Defence-in-depth principles of deterrence, detection, delay, response and recovery
- Perimeter, boundary and environmental design controls
- Access control zoning, credential management and visitor management requirements
- Video surveillance, intrusion detection and alarm monitoring performance requirements
- Guard force deployment, patrol design and contracted security service specifications
- Security control selection using effectiveness, feasibility, cost and operational impact criteria
- Control treatment plans for avoidance, reduction, transfer and acceptance
Workshop: Teams design a layered protection concept for a high-criticality asset and justify each selected control against the risk register.
Day 4: Operational integration and assurance
- Security operating procedures, post orders and response escalation workflows
- Integration of physical security with emergency management and business continuity plans
- Security technology interfaces, alarm response and incident information flows
- Contractor, supplier and visitor security management controls
- Control performance indicators for availability, response, compliance and incident trends
- Inspection, testing, maintenance and impairment management for security systems
- Audit evidence, nonconformity reporting and corrective action tracking
Workshop: Participants build an assurance plan containing control tests, evidence sources, performance measures and corrective-action ownership.
Day 5: Implementation planning and management review
- Gap analysis against ASIS Physical Asset Protection Standard requirements
- Prioritising treatment actions by risk reduction, dependency, cost and implementation effort
- Security project charters, milestones, resources and budget assumptions
- Risk ownership, decision records and residual-risk acceptance
- Management review packs for protection performance and investment decisions
- Internal communication and change management for revised security practices
- Continual improvement cycles, lessons learned and standard reassessment
Workshop: Participants assemble and present an ASIS-aligned Physical Asset Protection Implementation Pack with a 90-day action roadmap.
Tools & standards covered
ASIS Physical Asset Protection Standard, ISO 31000:2018 Risk Management Guidelines, Microsoft Excel, Microsoft Visio
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
28 Sep – 02 Oct 2026Book
Dubai · USD 4,500 -
05 – 09 Oct 2026Book
Mombasa · USD 3,200 -
12 – 16 Oct 2026Book
Cape Town · USD 4,200 -
12 – 16 Oct 2026Book
Kigali · USD 3,500 -
12 – 16 Oct 2026Book
Mombasa · USD 3,200 -
19 – 23 Oct 2026Book
Nairobi · USD 3,000 -
26 – 30 Oct 2026Book
Dar es Salaam · USD 3,500 -
09 – 13 Nov 2026Book
Nairobi · USD 3,000
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Security Management
Advanced Security Management for Enterprise Risk Leaders Training Course
Enterprise security leaders are expected to protect people, facilities, information, supply chains and business continuity while giving exec…
Security Management for Healthcare Facility Protection Training Course
Healthcare facilities must protect patients, staff, visitors, medicines, records and critical services while remaining accessible to people …
Genetec Security Center for Physical Security Operations Training Course
Physical security teams need to detect, verify, coordinate and document incidents without losing time between cameras, access-control events…
Security Management for Oil and Gas Facilities Training Course
Oil and gas facilities face security exposures that can interrupt production, endanger personnel, damage critical assets and create regulato…