Assessment findings guide

How to Document Physical Security Assessment Findings

Turn field observations into clear, evidence-linked findings that help authorized decision-makers understand the condition, risk, practical response, ownership, and follow-up.

A strong assessment finding is more than a photograph and a warning. It explains what was observed, where it was observed, why the condition matters within the approved assessment method, what evidence supports it, and what practical action should be considered.

Professional boundary: This guide does not provide a universal risk-scoring formula, inspection standard, countermeasure specification, or replacement for applicable codes, engineering analysis, site authorization, threat information, or qualified professional judgment.

1. Separate field observations from final findings

During a site visit, record conditions before forcing them into conclusions. An observation may later become a finding, support another finding, document an effective practice, or prove irrelevant after the scope and evidence are reviewed. Preserve that distinction so the report does not imply certainty that was never established.

Give each potentially material observation a stable identifier. Record the facility, area, date, assessor, assessment scope, and any access or visibility limitation. If the assessor could not inspect a location, test a device, review a record, or speak with the responsible person, document the limitation rather than assuming the condition.

2. Describe the observed condition precisely

State what was present, absent, damaged, obstructed, inconsistent, or not demonstrated. Use location-specific language and distinguish direct observation from statements supplied by site personnel. Avoid vague labels such as “poor security” when the underlying condition can be described.

  • Identify the exact building, entrance, room, zone, asset, or system involved.
  • Record whether the condition was observed continuously, sampled, reported, or inferred.
  • Describe relevant operating context, such as normal staffing or public access.
  • Identify effective existing controls that affect the significance of the condition.
  • Avoid including sensitive operational detail that the intended audience does not need.

A finding should be understandable to a decision-maker who was not present during the walk-through. It should also be restrained enough that an authorized technical specialist can evaluate it without first correcting exaggerated claims.

3. Connect the finding to controlled evidence

Link photographs, diagrams, notes, interviews, policies, maintenance records, access-control data, prior assessments, and other supporting material using stable identifiers. A caption should say what the image shows and where it was taken; it should not silently add conclusions that the image cannot prove.

Preserve original filenames and relevant source information. Record collection dates and any changes made for reporting, such as cropping, redaction, or annotation. If an image contains sensitive security information, restrict access and use a safer report description where appropriate.

Evidence discipline: The report should allow an authorized reviewer to trace a material conclusion to its supporting record without exposing every security-sensitive detail to every reader.

4. Explain the risk without overstating certainty

Use the assessment method approved for the engagement. Define terms such as threat, vulnerability, consequence, likelihood, severity, and residual risk before using them. Do not mix numeric and descriptive ratings casually or borrow a scoring model whose assumptions do not fit the site.

Explain the pathway between the observed condition and the potential consequence. Consider existing protective measures, operational practices, detection, response, recovery, and exposure. State assumptions and important unknowns. A photograph of a condition may support a vulnerability finding, but it rarely proves that a particular event will occur.

CISA’s Security Assessment at First Entry describes a structured review that identifies good practices, vulnerabilities, and mitigation options. That distinction is useful: record effective measures worth sustaining as well as gaps requiring consideration.

5. Write recommendations that support decisions

A useful recommendation describes the intended security outcome and offers a proportionate direction for consideration. Avoid specifying products, staffing levels, construction methods, or technical settings beyond the assessor’s competence or mandate. Identify when specialist design, legal review, procurement, engineering, fire-code, accessibility, privacy, labor, or information-security input is required.

Where practical, distinguish immediate administrative actions from longer-term physical or technical options. Recognize operational constraints, budget, maintenance, training, emergency egress, user experience, and the interaction between controls. A recommendation that creates a new safety or operational hazard is not a successful security recommendation.

6. Assign priority using a consistent method

Apply the documented rating method across all findings. Record the factors that drove the priority rather than relying only on a color or number. Similar conditions should receive similar treatment unless site context explains the difference.

  • Separate inherent concern from the effect of existing controls when the method requires it.
  • Do not increase a rating merely to obtain management attention.
  • Flag life-safety or urgent operational issues through the authorized escalation process.
  • Record who accepted, modified, deferred, transferred, or rejected a recommended action.
  • Preserve the original assessment when later conditions or decisions change.

7. Track ownership, action, and verification

A report is not the end of risk management. Assign an accountable owner, target date, status, and intended evidence of completion for each authorized action. Distinguish a planned action from a completed and verified action.

Verification may require a document review, photograph, configuration record, work order, interview, observation, test, or return visit. Record who verified the action, when it was checked, what evidence was reviewed, and whether residual concerns remain. Reopening or changing a finding should leave a visible history rather than replacing the original record.

Common documentation mistakes

  • Using a photograph as the entire finding with no location or explanation.
  • Mixing raw observations, analysis, and recommendations into one unclear paragraph.
  • Assigning ratings without a defined and consistently applied method.
  • Ignoring effective controls or site-specific operating context.
  • Writing recommendations outside the assessor’s competence.
  • Storing photographs separately from the findings they support.
  • Marking work complete without verification evidence.
  • Overwriting original findings when conditions or decisions change.
Free practical tools

Organize field evidence before writing the report

Use the Physical Security Site Walk-Through Checklist and Security Assessment Photo Log. No purchase, account, or email address is required.

Sources and further reading

Professional caution: Physical-security assessments may contain sensitive information. Follow the engagement’s authorization, distribution, retention, privacy, and information-protection requirements.
The appropriate workspace

Keep every finding connected to its field record

FieldFindings Professional organizes assessment scope, guided observations, photographs and documents, risk ratings, recommendations, corrective actions, verification, and professional reporting in one Windows workspace.