5.1 Surveys, Interviews, Incident Data, Crime Stats & Benchmarking
Key Takeaways
- A physical security survey needs day and night conditions, occupied and unoccupied hours; a lunch-hour lobby walk is not a survey.
- Interviews with security, facilities, HR, and process owners surface paths drawings hide; interviewing only the director collects policy, not practice.
- Incident reports and near-misses are local evidence; crime statistics are external context that can mislead if treated as this parcel's risk.
- Turnover, overtime, and contractor access are vulnerability data, not gossip, and they change what a manned post actually delivers.
- Sampling is defensible only with a declared frame; 100 percent inspection belongs on critical openings named in the plan, not on a clipboard of lock brands.
Data Collection for a Vulnerability Assessment
A vulnerability is a weakness that would let a threat reach a named asset. You do not discover those weaknesses by staring at a logo on a lock, or by accepting the sentence that the site already has security. Independent OpenExamPrep teaching for published PSP Domain 1 Task 4 knowledge treats data collection as the work that comes before residual-risk ratings: an on-site survey under more than one operating condition, interviews with the people who actually run the site, incident and near-miss files, crime statistics used only as context, personnel facts, and benchmarking of similar organizations. Sampling and 100 percent inspection are methods you declare in the notes. Photographs and field notes are evidence only if they form a chain a later reader can follow.
Trap: a clipboard of lock brands
The professional trap is a survey that becomes a clipboard of lock brands. The assessor walks corridor to corridor recording Schlage, Best, Medeco, or a cheap cylindrical lock, then leaves. Nobody asked who issues keys, how a lost master is handled, whether the pharmacy practices dual custody, how a trailer seal is applied on Sunday, or what a night nurse does when the badge reader is slow. Hardware identity is one data point. A vulnerability assessment that never asks a process question is a catalog, not a survey.
On-site physical security survey: day, night, occupied, unoccupied
An on-site physical security survey is planned observation of how people, goods, vehicles, and information move, and of how current measures behave while they do. A single daylight walk of the public lobby is not that work. You need day and night, and occupied and unoccupied, because each condition hides a different failure.
Daylight, occupied hours show peak visitor processing, whether a receptionist can see the turnstile, and whether a warehouse checker is actually at the dock. Night, occupied hours—hospitals, data halls, second-shift distribution—show which doors are propped because the reader is slow, which posts are empty because one officer is covering two floors, and whether lighting still supports identification at the fence rather than a decorative glow on the flagpole. Unoccupied periods—Sunday morning on an office campus, a warehouse between outbound waves, a clinic after the last patient—show cleaning crews, maintenance, and the contractor who still has last year's code.
Worked hospital example: a noon survey of the main revolving door can look orderly. The same hospital at 02:00 often shows an emergency-department ambulance bay held open with a wheel chock, a staff entrance with cardboard in the latch so smokers can return, and a pharmacy anteroom whose delayed-egress alarm has been silenced because the night technician was tired of the sound. Those are not lock-brand problems. They are condition problems.
Worked warehouse example: during the outbound wave, checkers stand at dock doors and a supervisor can see the high-value cage. On an unoccupied Sunday a single rover may cover forty docks, the driver restroom remains unlocked and connects to the floor, and empty trailers sit against a dark fence. If you only surveyed Thursday at 10:00, you documented the show.
Worked data-center example: occupied white space with an escort looks controlled. The unoccupied loading dock between fuel deliveries, the roof hatch used by a cooling contractor, and the meet-me room after the last customer tour are the hours when shared PINs and propped doors appear.
Walk with the purpose named in the assessment plan: critical assets first or process first, not whichever corridor is nearest the parking space. Record time, location, occupancy, weather, and who escorted you. If photography is forbidden, sketches and measured notes still count.
| Condition | What you can actually see | Typical miss if you skip it |
|---|---|---|
| Day, occupied | Visitor flow, receptionist span of control, peak dock activity | Night props, after-hours PINs, lighting that fails identification |
| Night, occupied | Which posts are staffed, which doors are taped, lighting at the asset | Sunday contractor paths and empty-building maintenance |
| Occupied process peak | How goods, patients, or prototypes actually move | The closed door that is a shortcut during rush |
| Unoccupied / after hours | Cleaning, maintenance, fuel delivery, unescorted vendors | The lobby story the sponsor already believes |
Interviews: security, facilities, HR, and process owners
Drawings and cameras do not explain why a door is taped. Interviews do. Plan conversations with security, facilities, human resources, and process owners—nursing, fulfillment, laboratory management, the network-operations lead—not only the director who booked the engagement.
Security officers and console operators can tell you which post orders they actually follow, which camera tiles they never look at, and which doors they have been told to leave unlocked for convenience. Facilities owns work orders, roof hatches, after-hours keys, and the mechanical rooms that bypass public lobbies. HR holds turnover, termination recovery of badges, contractor onboarding, overtime patterns, and workplace-violence reports. Process owners know how medication, prototypes, or outbound cartons actually move when the written SOP is too slow.
Method matters. Ask for a walk-through of a recent incident, a typical after-hours arrival, and a contractor job. Ask who can waive escort. Ask what happens when the access-control server is down. Separate what people believe from what you will later verify on video or in logs. Interviewing only the security director in a conference room is how you collect policy, not practice.
Incident reports and near-misses
Incident files are local evidence: theft, trespass, lost badges, tailgating, workplace violence, copper theft, medication diversion, missing seals. Request a defined period—often twelve to twenty-four months—and sort by location, hour, asset, and adversary type. A cluster at one dock door is a survey target. A single executive-suite complaint may be noise.
Near-misses are often richer than closed incidents. Found-unsecured doors, cancelled alarms with no cause code, shrink that operations almost proved, a visitor found unescorted in a lab, a contractor badge that still worked a week after the job—these events have not always been reduced to a sanitized legal narrative. A hospital that logs door-ajar fifty times on the same stair, or a warehouse that finds broken seals and nothing missing, is telling you where to spend hours. Pull the near-miss log even when Legal would rather you see only closed cases.
Crime statistics—and how they mislead
Neighborhood crime figures, police maps, and commercial crime-forecast products are context for external threat, not a substitute for site evidence. They mislead in predictable ways. Jurisdiction is not your parcel: a precinct total can be driven by a nightclub three blocks away while your loading dock is quiet, or the reverse. Underreporting is real, especially for internal theft and shrink that never become police reports. A mix of commercial and residential crime can make a district look high-crime when the events never reach your fence. Time lag means last year's burglary spike may already have moved. The most dangerous miss is the safe neighborhood story that blinds you to insider theft, contractor access, and process shrink—losses crime maps were never built to show.
Use crime data to decide whether a night survey of the fence is justified, to talk honestly with a sponsor about street robbery at the parking structure, and to avoid pretending the neighborhood is irrelevant. Then return to this site's incidents, near-misses, and observed conditions. A warehouse with a low precinct burglary rate and a high internal shrink rate is not a low-risk site.
Personnel issues are assessment data
Turnover, overtime, and contractor access are not human-resources gossip. They are vulnerability data. High officer turnover means post orders are tribal knowledge and the new temporary officer does not know which delayed-egress device is supposed to be armed. Chronic overtime means the same person covering two posts cannot see either asset. Contractor access that is issued quickly and recovered slowly is a standing insider path: badges, shared PINs, and the culture in which everyone in Facilities knows the code.
Ask HR and security operations for vacancy rates, average overtime on posts that protect critical assets, how quickly badges are disabled at termination, and how vendor PINs are rotated. A data hall with excellent mantraps and a revolving contract-guard force is not the residual risk the drawing suggests. Record those personnel facts in the same notebook as the door notes. They explain why a measure that looks present on Tuesday afternoon fails on Saturday night.
Benchmarking similar organizations
Benchmarking asks what peer hospitals, other colocation operators, or other third-party logistics sites typically do. It is useful for spotting an outlier—no visitor log, no key inventory, no camera retention—and for talking with a sponsor who wants to know what others do. It is not a finding that your site is safe because a peer has the same camera count. Peers can share the same false confidence. Benchmarks describe common practice; they do not certify adequacy for this asset, this adversary, and this operating hour. Steal a question from a peer (do you inventory masters?) rather than stealing a camera count.
Sampling versus 100 percent inspection
You will not open every interior office on a forty-building campus, and you should not pretend you did. Sampling is legitimate when the population is homogeneous and the frame is declared: twenty percent of interior office suites, every nth dock door in a row of identical positions, a random set of badge-exception users. 100 percent inspection belongs on the small set of critical openings and assets named in the plan: pharmacy vault doors, infant-unit exits, generator and fuel fills, cage doors, roof hatches, high-value cages, data-hall mantraps.
The method error is sampling the pretty lobby and calling it a complete hospital survey, or inspecting 100 percent of decorative storefront locks while sampling none of the roof. Write the frame in the notes: what was in the population, what was selected, and why critical items were not left to chance.
| Approach | When it is defensible | When it is a method failure |
|---|---|---|
| 100% of critical openings | Vaults, hatches, mantraps, fuel fills, infant exits, high-value cages | Using critical as a slogan while skipping the rooms operations named |
| Sampling a homogeneous set | Identical interior offices, identical dock positions, similar camera tiles | Sampling the lobby and generalizing to the pharmacy |
| Mix | 100% of jewels, sample of the rest, frame written down | No frame, no notes, a camera full of convenient doors |
Evidence: photographs, notes, and a chain of observations
Evidence is what lets a later reader believe you. Photographs, where the site allows, should show the condition and a reference for scale or location—not a patient's face, not a badge number in the filename, not a screen full of personal data. Notes should carry time, location, condition, occupancy, and who was present. A chain of observations is stronger than a single snapshot: you saw the staff door latched with cardboard; video later showed it open from 01:10 to 04:40; the night supervisor said the crew always does that for smokers; the access log showed no forced-door events because the contact never opened. That chain is a finding. A photo of a lock brand is not.
Keep a running gap list as you walk. Do not wait until Friday to remember which door failed to latch. The survey is the data-collection engine of the vulnerability assessment. Interviews, incidents, crime context, personnel facts, and benchmarks fill what a walk cannot see. Then you are ready to judge whether current technology, people, and procedures actually protect the asset.
An assessor walks a hospital recording the brand and function of every lock cylinder and leaves without asking how keys are issued, how dual custody is practiced, or how night staff defeat delayed egress. What is the professional problem with that survey?
A warehouse sits in a precinct whose published burglary rate is below the regional average. Internal shrink reports and broken trailer seals are common on this parcel. How should crime statistics enter the vulnerability survey?
Which inspection choice is the soundest for a mixed hospital campus with one pharmacy vault, many similar medical-office suites, and a large roof?