top of page
SASECON article explaining how physical security design translates the approved Security Risk Assessment (SRA) into practical security measures for SAIS-regulated projects, including perimeter protection, access control, surveillance, control-room functions, manpower support, infrastructure, and operational security plans.
Physical security design starts with the approved risk basis.

The approved SRA is the basis that turns security design from equipment placement into a defensible protection strategy.

In SAIS-regulated projects, physical security design should not begin as an isolated engineering activity. It should begin after the Security Risk Assessment (SRA) has established the facility’s risk basis, identified the relevant threats and vulnerabilities, developed credible security scenarios, and defined the required countermeasures.

The purpose of design is to convert that approved security reasoning into a physical and operational solution. The drawing must show more than equipment locations. It must show how the facility will be protected, how access will be controlled, how sensitive areas will be separated, how events will be detected, how response will be supported, and how the security measures will function together.

A physical security design that cannot be traced back to the SRA may look complete, but it will be difficult to defend. In a SAIS-regulated project, the strength of the design depends on the strength of the assessment behind it.

The SRA gives each design decision its reason.

Every major security measure should be traceable to a risk, vulnerability, scenario, or countermeasure identified in the SRA.

The approved SRA should explain what must be protected, what may threaten it, where the site is exposed, how an event may develop, and what countermeasures are required. The physical security design then translates those conclusions into practical measures.

A perimeter line should not be drawn simply because the site needs a fence. It should reflect the protection level required for the facility, the surrounding conditions, the exposure of the boundary, and the delay or deterrence expected from that layer.

An access-control point should not be placed only where it is convenient. It should reflect movement patterns, operational needs, screening requirements, separation between public and controlled areas, and the risk associated with unauthorized entry.

A camera should not be placed only to cover an empty area on the drawing. It should support a defined surveillance objective, whether that objective is early detection, verification, monitoring of critical movement, protection of an asset, or support for response.

This is where a security design becomes different from a device layout.

Design must translate countermeasures into layers.

Physical security design should organize countermeasures into coordinated layers, not disconnected systems.

The SRA identifies countermeasures. Physical security design must organize them into a coherent protection scheme.

For SAIS-regulated facilities, this usually requires a defense-in-depth approach. Protection is created through coordinated layers: outer site conditions, perimeter protection, vehicle and pedestrian access control, internal zoning, surveillance, intrusion detection, lighting, barriers, control-room functions, communication links, guard deployment support, and emergency interfaces.

No single layer carries the full burden.

The perimeter may delay and deter. Access control may regulate movement. Surveillance may detect and verify. Intrusion detection may alert. Lighting may support observation and response. The control room may coordinate monitoring, escalation, and communication. Security manpower may operate, patrol, verify, respond, and enforce procedures.

The design must show how these layers work together. If the layers are disconnected, the project may have many systems, but not a coherent security solution.

The site layout must support the security concept.

If the site layout does not support the security logic, the design will later depend on costly systems or difficult procedures to compensate.

A good physical security design cannot be separated from the site layout.

The location of gates, roads, parking areas, loading zones, pedestrian routes, visitor areas, utilities, storage areas, control rooms, and critical assets affects the security of the facility. Once those elements are fixed without security logic, the design may be forced to compensate later through additional systems, complicated procedures, or inefficient guard deployment.

The approved SRA should guide the design team in understanding which areas require separation, which routes require control, which assets require protection, and which interfaces require monitoring.

For example, a vehicle route that passes too close to a sensitive area may create unnecessary exposure. A visitor entrance placed without proper separation may complicate access control. A control room located without regard to visibility, communication, resilience, or operational supervision may weaken the facility’s ability to manage security events.

Security design is therefore not only about what is installed. It is also about how the facility is organized.

Systems must be supported by infrastructure.

Security systems cannot operate properly unless power, network, mounting, civil works, maintenance access, and integration requirements are designed from the beginning.

Physical security systems require infrastructure. This point is often underestimated.

Cameras need mounting locations, power, network connectivity, field of view, lighting conditions, maintenance access, and integration with monitoring systems. Access-control devices need door hardware, readers, controllers, cabling, power, network infrastructure, and operating procedures. Vehicle barriers need civil foundations, road geometry, approach distances, drainage coordination, safety arrangements, and maintenance access. Intrusion detection systems need suitable perimeter conditions, stable installation environments, communications, alarm management, and response arrangements.

If these requirements are not considered during design, the project may later discover that the selected security measures cannot be installed efficiently, cannot be maintained properly, or cannot operate as intended.

This is why physical security design must be coordinated with architectural, civil, electrical, ICT, mechanical, and operational planning. Security is not a separate layer drawn after the project is complete. It must be coordinated with the systems and infrastructure that allow it to work.

The control room is an operational function, not only a room.

A control room must support monitoring, alarm handling, communication, escalation, and response, not simply contain screens and workstations.

In many projects, the control room is treated as a space on a plan. In SAIS-regulated facilities, it should be treated as an operating function.

The control room must support monitoring, alarm handling, access oversight, communication, incident escalation, coordination with guards, and emergency response. Its location, size, equipment, staffing assumptions, workstation layout, display requirements, communication systems, redundancy, and operating procedures should reflect the role defined by the SRA.

A control room that receives alarms but has no clear response arrangement is incomplete. A control room with cameras but no defined monitoring priority is weak. A control room that is physically present but operationally disconnected from guard posts, patrols, emergency procedures, or site management will not deliver the protection expected from it.

The design must therefore connect the control room to the wider security operation.

Manpower must be reflected in the design.

Guard posts, patrol routes, screening points, and control-room staffing must be supported by the physical layout, not added after the design is complete.

The SRA may define manpower requirements, guard posts, patrol arrangements, screening points, control-room staffing, visitor control, vehicle inspection, and response duties. These requirements must be considered during physical security design.

A guard post needs visibility, protection, communication, power, access to procedures, and a position that supports the task assigned to it. A patrol route needs safe access, clear coverage, checkpoints where required, and communication with the control room. A vehicle-screening point needs enough space for queuing, inspection, rejection, and safe movement. A visitor process needs a controlled location, separation from sensitive areas, and integration with identification and access procedures.

If the design ignores manpower, the facility may later depend on guards to compensate for poor layout, unclear routes, insufficient visibility, or weak operational interfaces.

That is not a sound security design. It is an operational burden created by design decisions.

Security plans must be anticipated during design.

Operational procedures only work when the facility layout, access routes, control points, and response arrangements are designed to support them.

Physical security design should also support the plans that will later govern the facility.

Access procedures, visitor management, contractor control, emergency response, patrols, post orders, incident reporting, escalation, evacuation support, and coordination with external entities all require a facility that can be operated in accordance with those procedures.

The design should make those plans practical.

If the facility needs vehicle screening, the design must provide a place where screening can occur safely. If visitors must be controlled before entering operational areas, the layout must allow that separation. If a security team must respond to alarms within a reasonable time, routes and access arrangements must support that response. If emergency coordination is required, communication and control points must be available.

A plan written after construction cannot solve a layout that was never designed to support it.

The design must be defensible during review.

A strong SAIS security design is one that can explain why each measure exists and how it responds to the approved SRA.

A SAIS-regulated security design should be capable of explanation.

The project team should be able to explain why each major measure exists, what risk it addresses, how it supports the protection strategy, and how it relates to the approved facility classification and SRA findings.

This is where many weak designs become exposed. They may show equipment, but they cannot explain the reasoning. They may include cameras, but cannot identify the surveillance objective. They may include barriers, but cannot connect them to the threat, approach route, or asset being protected. They may show access control, but cannot explain the movement logic. They may include a control room, but cannot show how it will operate.

A defensible design is not necessarily the most complex design. It is the design whose measures can be traced back to the assessment, the facility classification, the protection objectives, and the operating requirements.

SASECON’s approach to physical security design.

At Saudi Ansary Security Consultancy LLC (SASECON), we treat physical security design as the translation of the approved SRA into coordinated and practical security measures.

Our work does not begin with equipment placement. It begins with the facility classification, the SRA findings, the threat and vulnerability analysis, the security scenarios, and the countermeasures required to protect the facility. From that basis, we align perimeter protection, access control, surveillance, intrusion detection, barriers, control-room requirements, manpower support, infrastructure, and operational security plans into a design that can be implemented and defended.

This approach helps owners, developers, project managers, designers, and contractors avoid treating security design as a drawing exercise. It supports a project path where the design reflects the approved risk basis, the regulatory expectations, and the way the facility will actually operate.

In Part 7 of this series, we will examine why operational readiness is the point where approved security design, installed systems, manpower, procedures, and compliance documentation must come together.

UNDERSTANDING SAIS – Part 6: How Physical Security Design Translates the Approved SRA into Practical Security Measures

Copyright © 2013-2026 Saudi Ansary Security Consultancy LLC. All Rights Reserved

bottom of page