3.1 Asset Types, Terminology, Value, Criticality & Loss Impact

Key Takeaways

  • An asset is what the organization must protect; a threat is a source of harm; a vulnerability is a weakness a threat could use; risk combines likelihood and impact for that chain
  • Tangible assets include people, facilities, equipment, cash, vehicles, and materials; intangible assets include reputation, trade secrets, formulas, brand, licenses, and data
  • Loss impact is the operational, safety, legal, and reputational consequence of harm and is not the same as replacement cost or book value
  • People—employees, contractors, visitors, and VIPs—are assets with different exposure patterns, not just occupants of a building you are locking
  • Information still needs physical protection in server rooms, records warehouses, and prototype labs; capital-equipment lists omit many of the holdings that actually stop operations
Last updated: September 2026

Asset Types, Terminology, Value, Criticality, and Loss Impact

Physical security assessment does not begin with cameras, fences, or a favorite lock. It begins with a disciplined inventory of assets—the people, places, things, information, and reputation the organization must keep available, intact, and confidential enough to perform its mission. Domain 1 Task 2 on the PSP exam tests whether you can name those holdings, keep four closely related terms from collapsing into one another, and distinguish loss impact from the accounting figures that already live in Finance.

Exam focus: Name the asset first. Threat, vulnerability, and risk come after. Book value is not loss impact, and a capitalization threshold is not a criticality ranking.

Four Terms You Must Keep Separate

An asset is anything of value that the organization needs in order to operate. Value may be monetary, operational, legal, humanitarian, or reputational. Assets are not problems. They are the objects of protection: a night-shift nurse, a blood-bank refrigerator, a fiber entrance, a formula notebook, a license to operate, or public confidence in a brand.

A threat is a potential source of harm to an asset. Threats include people (internal theft, protest, robbery, sabotage, workplace violence), natural events (flood, wind, earthquake, wildfire), and accidents (chemical spill, vehicle impact, utility failure). A threat can be real even when a particular door is locked.

A vulnerability is a weakness, gap, or enabling condition that would allow a threat to succeed, or that would make a hazard more damaging than it otherwise would be. Uncontrolled keys, an unmonitored loading dock, a hollow-core door on a server room, badge issuance without escort rules, and a generator sitting in an unlocked yard are vulnerabilities. They live in design, procedure, staffing, maintenance, and the surrounding environment.

Risk is the combination of the likelihood that a threat will act against a vulnerable asset and the impact if that event occurs. Risk is not the adversary standing outside. Risk is not the hole in the fence. Risk is the evaluated chance that a named asset will suffer a named kind of harm, plus how severe that harm would be for people, operations, law, and reputation.

Keep the chain in that order: identify the asset, identify credible threats to that asset, identify the vulnerabilities that would let those threats succeed, then estimate risk. Mixing the terms produces circular writing that cannot justify a countermeasure. If a finding says only that "security is a risk," you do not yet have an assessment.

Tangible Assets

Tangible assets have physical form. A physical-security register usually includes the classes below.

Tangible classTypical examplesWhy the assessment records them
PeopleEmployees, contractors, visitors, patients, customers, VIPsHarm to people is a life-safety loss that a purchase order cannot restore
FacilitiesPlants, warehouses, clinics, data halls, labs, offices, yardsBuildings concentrate people, processes, and other assets
EquipmentProduction lines, medical devices, generators, test standsLong lead times can idle a site even if the building still stands
Cash and negotiablesCurrency, checks, precious metals, high-street-value samplesDirect theft is frequent and attracts repeat offenders
VehiclesFleet trucks, executive cars, tankers, mobile clinicsVehicles are both assets and a way to remove other assets from the site
Raw materials and goodsIngredients, semiconductors, pharmaceuticals, retail stockShrinkage, contamination, and diversion begin as physical-access problems

People are assets. Employees, contractors, visitors, and VIPs create different exposure patterns. A contractor with after-hours access to a tool crib is not the same protection problem as a visiting executive on site for ninety minutes. A visitor who should never leave the lobby unescorted is a third pattern. If the register says only "personnel," you cannot later justify different screening, escort, parking, or emergency-action measures. Duty of care attaches to people even when they do not appear on a depreciation schedule.

Intangible Assets That Still Occupy Rooms

Intangible assets lack a convenient shape, yet they still sit in rooms, cabinets, notebooks, servers, and conversations. Reputation, trade secrets, formulas, brand identity, licenses and certifications, customer lists, and data—including backup media—are typical classes. A product formula may live in a bound notebook, a restricted file share, and the memory of three chemists. If the notebook leaves a prototype lab in a backpack, the intangible asset has already suffered a physical-security failure.

Information is an asset that still needs physical protection. Server rooms, records warehouses, prototype labs, evidence lockers, and off-site media vaults are physical spaces. Badge readers, cages, cameras, locked containers, and escort rules are how physical security contributes to protecting data and know-how. The carton, the server chassis, or the whiteboard is rarely the thing of value. Assess the content, then protect the spaces and paths that hold it.

Loss Impact, Replacement Cost, and Book Value

Assessment teams routinely confuse three numbers.

Replacement cost (or restoration cost) is what it takes to return the organization to a comparable operating position: purchase or rebuild, install, recertify, and recover lost work-in-process. For a specialized freeze dryer, that figure includes unit price, freight, utility work, validation, and months of lost output while the equipment is on order.

Book value is an accounting remainder: original cost minus accumulated depreciation. A fully depreciated autoclave can still be the only sterile-processing bottleneck in a hospital. Book value near zero does not mean the asset is unimportant. A high remaining book value does not automatically mean the asset is mission-essential.

Loss impact is the operational, safety, legal, financial, and reputational consequence of compromise, destruction, theft, disclosure, or interruption. It includes downtime, missed deliveries, regulatory penalties, harm to people, loss of exclusive know-how, and public loss of confidence. Loss impact is usually larger than replacement cost and almost never equal to book value.

Criticality is the importance of the asset to mission, life safety, legal duty, or continuity. It answers: if this asset is gone, delayed, contaminated, or disclosed for a defined period, what happens? A low-cost blood-bank refrigerator can outrank an expensive courtyard fountain because interruption of transfusion capability is a life-safety and mission failure. Criticality is not purchase price. Value explains magnitude; criticality ranks; loss impact is the consequence you would still be explaining a year later. They are related fields, not one number.

Trap: Protecting Only Capitalized Equipment

A distribution campus listed every capitalized asset above a finance threshold and posted officers at the high-dollar locations: a new stretch-wrapper, a refurbished forklift fleet, and a conference-room video wall. Walking the same campus with operations revealed a paper pick-ticket printer that was not on the capital list, a fiber entrance that was not on the capital list, and a binder of customer routing sheets on an open shelf. Losing the printer for a day stopped outbound shipping. Cutting the fiber stopped warehouse management. Photographing the routing binder would have given a competitor the week's delivery sequence. None of those items had a book value that survived the capitalization cutoff.

The trap is protecting only capitalized equipment. Physical security inventories what operations cannot function without, what law and contract require you to safeguard, what would harm people if it failed, and what an adversary would actually want—not only what Finance placed on the fixed-asset register. Uncapitalized process enablers, people, and information containers are still assets. When you write a finding, force four blanks: the asset, the threat, the vulnerability, and the resulting risk. If any blank says only "the facility" or "general security," the finding is not ready for a spending recommendation.

Loading diagram...
Keep Asset, Threat, Vulnerability, and Risk as Separate Links
Illustrative Ranking: Book Value vs Loss Impact (Not Purchase Price)
Test Your Knowledge

Which statement correctly keeps asset, threat, vulnerability, and risk as separate ideas in a physical security assessment?

A
B
C
D
Test Your Knowledge

A hospital blood-bank refrigerator is fully depreciated. A courtyard fountain remains on the books at a much higher figure. For loss-impact ranking, which conclusion is soundest?

A
B
C
D
Test Your Knowledge

Which inventory practice is the classic trap in physical security asset identification?

A
B
C
D