A foundational government security risk assessment, paired with a refreshed site inspection program, gave a government agency an evidence-based roadmap for one of its operational sites.
THE CHALLENGE
The agency needed to translate high-level protective security policy into practical, site-specific measures at an operational site within a government precinct. It had no foundational assessment of the site to identify its critical assets, including people, services, processes, information and equipment, or to test how governance, policies and procedures were working in practice. Leadership also wanted a clearer picture of the threat environment in and around the location, from petty crime and trusted insiders to issue motivated groups, serious and organised crime and foreign intelligence interest. At the same time, the agency’s physical security site inspection program had to keep pace with the requirements of its protective security framework.
OUR APPROACH
Agilient applied a structured, high-assurance security threat and risk assessment method. Agilient’s lead security consultant carried out a physical security assessment of the site and ran face-to-face engagement with leadership and operational stakeholders. The consultation drew out views on critical assets, risk control considerations, security culture and risk tolerance, and observations about potential threat actors at or near the site. Threat sources considered included serious and organised crime, foreign intelligence entities and their proxies, issue motivated groups and individuals, petty crime, trusted insiders and the indirect effects of terrorism and violent extremism. In parallel, Agilient reviewed the agency’s physical security site inspection checklist against the framework, so that routine inspections would continue to test the controls that matter most at the site.
THE OUTCOME
The agency has an evidence-based roadmap for strengthening protective security at the site.
- A review report setting out findings and recommendations to improve the agency’s protective security management system and meet the requirements of its framework
- A foundational site security threat and risk assessment identifying critical assets, relevant threat sources and risk control considerations
- An updated physical security site inspection checklist aligned with the framework for ongoing use
Related services: protective security and PSPF consulting, security risk management, government security consultant. Sector experience: building security consultant. To discuss a similar project, contact Agilient.