APCAF • Physical Security Control Assessment

Physical Security Control Assessment

A passive, standardised framework for assessing whether installed physical controls resist known bypass techniques.

45s Target Walk Budget
4 Objects Baseline Physical Scope
100% Passive Non-Invasive QA
Direct Field Entry

What are you inspecting right now?

Select a physical asset to immediately open its defined inspection procedure in the field triage workbench.

Methodology

How APCAF Works: The 5-Step Model

A standardised evaluation chain linking threat goals to verified technical remediation.

Step 1
Tactic
What the adversarial intruder wants to achieve (e.g., Portal Ingress).
Step 2
Technique
How they may achieve it through physical hardware bypasses (e.g., Latch Slip).
Step 3
Observation
What the assessor can directly establish with non-invasive tools (e.g., 4.5mm strike gap).
Step 4
Classification
What APCAF determines from that observation (Hardened vs Legacy/Soft).
Step 5
Remediation
What hardware or configuration correction is required (e.g., Full-height astragal).
Baseline Scope

The 4 Core MVP Techniques

Defined non-invasive inspection procedures tested during physical site walks.

PHY-T1001 Credential
Unencrypted RFID Harvesting
Checks if credentials broadcast static unencrypted UIDs without cryptographic challenge-response authentication.
Test in Triage →
PHY-T1002 Portal Ingress
Mechanical Latch Slip
Checks if outward door operating clearance exceeds 3.2mm without continuous protective steel astragal shielding.
Test in Triage →
PHY-T1003 Portal Ingress
REX Sensor Blind Activation
Checks if the interior Request-to-Exit motion sensor optical field is unhooded and visible through door margins.
Test in Triage →
PHY-T1004 Interface
Exposed Active Network Drop
Checks if unmonitored common area Ethernet wall jacks broadcast an active Layer 1 carrier without port shutdown.
Test in Triage →
Schema Validation Fixture

Synthetic Demonstration Walkthrough

A simulated case fixture illustrating how field observations map to YAML records and CISO warranty punch lists.

Schema Fixture: APCAF-CASE-001
Simulated Datacenter Suite Inspection
SYNTHETIC: NO REAL FACILITY ASSESSED
45s Target Inspection Budget
3 Controls Simulated Scope
2 Soft / 1 Hard Simulated Findings
YAML Case Schema Validation
Explore the Standard

Choose Your Pathway

Everything you need to evaluate, learn, or contribute to physical security engineering.

Cross-Walked to Selected Security & Building Standards
ISO 27001:2022 A.7 PCI DSS v4.0 Req 9 SOC 2 CC6.4 NIST SP 800-53 PE-3 NFPA 80 §6.3.1.7.1 ISO/IEC 14443-4