What’s in a name? A lot, particularly when the subject is something as singularly critical as security assessments. Picture the following scenario: A facility manager gets a directive from up the chain to get a security assessment done before the next budget cycle. Three vendors respond to the RFP. One proposes a physical security assessment. Another quotes a risk assessment. A third offers a security survey, priced well under the aforementioned. The scope, price, and deliverable all differ, and no one signs off until someone can explain why.
What Is a Physical Security Assessment?
A physical security assessment is a structured evaluation of how well a facility’s physical protections defend its identified assets against its identified threats. It measures performance against a defined standard.
That distinction separates an assessment from a walkthrough or a routine inspection. A walkthrough confirms that cameras are mounted and doors lock. An assessment asks whether that coverage reaches what matters, whether that lock buys enough time for a response to arrive, and whether the answer gets documented well enough to act on: asset-based, threat-informed, and backed by findings.
Scope extends beyond the built environment, too. It examines fences, doors, and camera coverage, but it also looks at the people staffing those systems and the procedures they follow.
For the fundamentals behind these layers, read our blog: What is Physical Security?
What a Physical Security Assessment Covers
This kind of security review looks at protection in categories:
- Perimeter and access control: Fences, gates, vehicle barriers, badge systems, and visitor management at every entry point
- Detection and surveillance: Intrusion alarms, sensors, and camera coverage
- Response capability: Guard force posture, response times, and coordination with local law enforcement
- Interior controls: Restricted areas, storage of sensitive material, and key or credential management once someone is already inside, which is where findings often connect to a facility’s broader personnel security and investigations program
- Procedures and human factors: Post orders, training currency, and after-hours protocol
- Documentation and compliance posture: How the facility’s protections measure up against the orders, standards, or regulations that apply to it
Each category raises the same question: Does this layer perform the way it’s supposed to, given what it’s protecting and what it’s supposed to be protecting against?
Physical Security Assessment vs. Physical Security Risk Assessment
Now for more terminology differentiation. A physical security assessment evaluates whether existing protections work as designed. A physical security risk assessment weighs likelihood and consequence, to decide which gaps need to get funded first. Put another way, the former tells a facility manager what’s broken; the latter tells them what to fix first.
A physical assessment might find a blind camera spot, an intermittent badge reader, and a low fence line behind a maintenance shed. A physical security risk assessment ranks those findings against the assets nearby, the threats they attract, and the consequence of a breach, then points to where the next budget spend should go.
Where a Threat Vulnerability Risk Assessment (TVRA) Fits
A threat vulnerability risk assessment, or TVRA, is the integrated methodology that pairs threat characterization with vulnerability analysis and consequence in a single framework. It builds on the same foundation as a standalone vulnerability assessment, but folds the threat and consequence pieces in from the start.
Where a general risk assessment works from a broad threat category, a TVRA builds out the threat side first: who is likely to target the facility, what their capability looks like, and what they’re after. It then maps that picture against specific vulnerabilities and consequences, producing a risk rating precise enough to defend in front of a funding board.
TVRAs show up most often in federal and critical infrastructure work, where the standard is set by regulation rather than preference. A threat vulnerability risk assessment built to federal standards operates at a different tier than a walkthrough scored against a commercial checklist.
Physical Security Survey vs. Security Site Survey
A physical security survey is narrower than an assessment and typically observational: a scoped look at specific controls, usually a precursor to a full assessment or a subset of one. Some vendors call this same walkthrough a site survey or a security site survey. The name changes, the scope doesn’t.
Vendors sometimes market a survey as an assessment, especially when the price needs to look competitive. The tell is in the deliverable: a survey returns a list of what’s present and missing, while an assessment returns findings tied to specific assets and threats, prioritized and ready to act on. If a proposal never names the assets or threats it’s evaluating, it’s describing a physical security survey.
What Happens During an Assessment
Every credible assessment follows the same methodology, even when the details vary by facility:
- Asset identification and characterization: Cataloging what needs protecting and why it matters
- Threat definition: Identifying who or what could target those assets, and how
- Data collection and site work: Interviews, document review, and observation of the facility in operation
- Analysis against protection objectives: Measuring existing controls against what the assets and threats require
- Findings and prioritized recommendations: Documented gaps, ranked by what matters most
- Out-brief: A walkthrough of findings with the people who will act on them
Skipping straight to recommendations without defining assets and threats first produces a report full of generic fixes that don’t match the facility’s risk.
Who Needs One and How Often
Rather than a calendar, most facilities schedule around triggers:
- A new mission or new asset arrives onsite
- The threat environment around the facility changes
- A physical or procedural change alters how the facility operates
- An inspection or audit turns up a finding that needs a closer look
- A contract or governing order requires one on a set schedule
Federal and critical infrastructure facilities are often driven by the last two triggers. A shift in any of these can also trigger a physical security risk assessment, since a changed threat picture changes which findings matter most. Commercial facilities have more latitude, but the same logic applies: An assessment scheduled around a real change in risk holds up better than one scheduled around a date on a calendar.
Know What You’re Asking For
These three common terms aren’t interchangeable. A survey isn’t a stand-in for either of the other two, and knowing which one a project needs is what separates a report that gets used from a binder that sits on a shelf.
If it’s not clear yet which one fits a specific facility, GEM’s Safeguards & Security team can help sort that out long before the scope gets written.