712-50 Question 275
Single answerA newly appointed CCISO is integrating physical security across a global organization after an internal review found inconsistent badge access practices, undocumented visitor handling at regional offices, and no formal testing of CCTV retention or alarm response. The board has asked for a comprehensive physical security plan that can be measured and audited consistently across all sites without creating excessive operational overhead. Which approach is MOST appropriate to implement first to establish an effective enterprise physical security program with meaningful audit scheduling and performance metrics?
- A
Mandate identical physical controls and quarterly full-scope audits for every location, using the same checklist and performance targets regardless of site risk profile
- B
Develop a risk-based physical security baseline with site-specific control enhancements, define key performance indicators such as tailgating incidents, badge access exceptions, alarm response time, and visitor log reconciliation rates, and schedule audits based on criticality and prior findings
- C
Outsource all physical security operations to a single guard services provider and require the vendor to supply monthly compliance attestations instead of internal audits
- D
Focus first on deploying additional cameras and biometric readers at headquarters, then extend controls to other sites after one year if incident rates decline
Show answer and explanation
Correct answer: B
Explanation
The best answer is the risk-based, enterprise-wide approach. For a CCISO, physical security should be governed as part of a coordinated security program rather than as isolated site projects or purely operational guard functions. Best practices from security governance and risk management frameworks support defining minimum control baselines, tailoring controls based on risk, and measuring effectiveness through specific, repeatable KPIs and KRIs. Relevant references include ISO 27001 and ISO 27002 guidance on physical and environmental security controls, NIST concepts on control assessment and continuous monitoring, and general audit principles that prioritize higher-risk assets and recurring deficiencies. In practice, an effective physical security plan should include: enterprise standards for access control, visitor management, surveillance, alarm handling, and media/asset protection; site-specific risk assessments; a documented audit schedule tied to criticality, incident history, and prior deficiencies; and performance metrics that show whether controls are functioning, not merely whether technology has been installed.
- A. Incorrect.
This is incorrect because a uniform control set and identical quarterly audits for all locations ignore business impact, threat environment, regulatory exposure, and site criticality. A small sales office and a data center should not necessarily have the same audit frequency or control depth. This option reflects a common misconception that standardization alone equals maturity; in practice, effective enterprise physical security requires standard minimum controls plus risk-based tailoring.
- B. Correct.
This is correct because it aligns with how senior security leaders should build a holistic and measurable physical security program. A risk-based baseline establishes enterprise consistency while allowing stronger controls at higher-risk sites. The proposed metrics are operationally meaningful and auditable: tailgating incidents measure access control effectiveness, badge exceptions reveal process gaps, alarm response time evaluates incident handling, and visitor log reconciliation checks administrative discipline. Scheduling audits by criticality and prior findings supports efficient assurance and continuous improvement.
- C. Incorrect.
This is incorrect because outsourcing operations does not transfer accountability for governance, assurance, or risk management. Vendor attestations can be useful inputs, but they are not a substitute for an internal audit strategy, management oversight, or independent validation of control effectiveness. This option represents the misconception that third-party service delivery eliminates the need for enterprise control monitoring.
- D. Incorrect.
This is incorrect because it prioritizes technology deployment at one site rather than establishing an enterprise program framework. Adding cameras and biometrics may improve control strength in some environments, but without governance, standards, metrics, and an audit plan, the organization will still lack coordinated oversight. It also neglects known weaknesses at regional offices and delays remediation across the broader enterprise.