Learn APCAF
A practical, 15-minute introduction to adversarial physical-control assessment. Master the mental model, passive inspection boundaries, and core techniques without technical fluff.
The Problem: Why "Paper Existence" Fails
In traditional compliance audits (like ISO 27001 or PCI DSS), an assessor walks through a facility with a clipboard and checks: "Is there a physical lock on the server room door? [Yes / No]".
"The door has a lock" ≠ "The door resists known bypass techniques."
A facility can have 100% paper compliance while remaining completely vulnerable to trivial, seconds-long physical bypasses. A door can have an expensive electronic lock installed, but if the contractor leaves an outward-swinging 4.5mm frame gap without an astragal guard, an attacker can slip the latch in 5 seconds with a $5 shove tool.
Verifies whether hardware is physically mounted on the door. Concludes the control is "Compliant" regardless of installation defects or bypass susceptibility.
Deterministically measures whether the installed hardware resists common bypass mechanics under passive 45-second verification.
The APCAF Model: The 5-Step Evaluation Chain
To replace arbitrary checklists with rigorous engineering, APCAF structures all physical assessments around a deterministic 5-step mental pipeline. We use a single server room door example throughout:
Notice how Step 5 finishes with a Contractor Warranty Remediation. APCAF findings are not expensive capital requests; they are installation defects that general contractors must fix at $0 additional cost to the client before final invoice payment.
Tactics vs. Techniques: Understanding the Matrix
APCAF borrows MITRE ATT&CK's core behavioral separation:
- Tactic = What the attacker wants to achieve (Spatial or access objective).
- Technique = How the attacker attempts to achieve it (Specific physical/hardware mechanism).
APCAF organizes the entire physical attack surface into 5 Core Tactics:
Passive Assessment: The Non-Invasive Safety Boundary
This is the most critical distinction in APCAF:
APCAF does not require you to break or pick the control to assess it.
Many organizations avoid physical security testing because they believe it requires aggressive red-teaming: lockpicks, broken doors, or unauthorized trespassing. APCAF replaces destructive testing with non-invasive QA verification:
"Let me try to defeat this door."
Uses lockpicks, shove knives, or bypass tools to breach the threshold. Carries high operational risk and legal liability.
"Let me determine whether the physical conditions required for this bypass exist."
Uses pocket feeler gauges and passive RF listeners to inspect compliance with engineering standards (e.g. NFPA 80 3.2mm limit).
Because APCAF is completely passive and non-destructive, it can be executed legally during standard facility commissioning walks under a single-sentence SOW authorization.
The Four MVP Techniques in Plain English
Here are the four active baseline techniques evaluated during an APCAF walkthrough. We explain each in human terms before referencing the technical standard ID:
1. Wireless Badge Interception (RFID Harvesting)
PHY-T1001In Plain English: An attacker gets close to an employee's badge in a coffee shop or elevator and wirelessly copies their ID in under 3 seconds without touching them.
2. Door Latch Manipulation (Latch Slip & UDT)
PHY-T1002In Plain English: An attacker slips a thin plastic card or shove knife through the gap between the door and frame to pop the lock open.
3. Request-to-Exit Sensor Blind Activation
PHY-T1003In Plain English: An attacker sprays cold air or slides a tool under the door to trick the interior exit sensor into unlocking the door for them from the outside.
4. Unauthenticated Physical Network Port Tap
PHY-T1004In Plain English: An attacker plugs a laptop or rogue mini-device into an active wall jack in a conference room and gets immediate internal network access.
Run Your First APCAF Assessment
Put the fundamentals to work. Walk through a simulated inspection of "Acme Financial Data Center" and match each real-world observation to its corresponding APCAF technique:
You inspect an employee badge with a pocket interrogator. The screen immediately displays an unencrypted 125 kHz carrier transmitting a static 26-bit facility code in plaintext. Which APCAF technique applies?
You inspect the outward-opening server suite door. Inserting a pocket feeler gauge reveals a 4.5mm clearance gap between door edge and jamb with direct visibility to the latch bolt bevel and no steel astragal. Which APCAF technique applies?
Looking through the clear glass transom above the locked door, you observe an unhooded wide-angle PIR motion sensor mounted directly above the interior frame facing the gap. Which APCAF technique applies?
In a publicly accessible lounge, you insert a passive zero-packet LED tester into an RJ-45 wall drop. The link pulse LED illuminates steady green without 802.1X quarantine. Which APCAF technique applies?