Security guards at government building entrance

A layered, risk-based, PSPF-aligned security programme combining security zoning, electronic controls and trained personnel is the most defensible approach to protecting Australian government buildings. Getting that posture right means working through a structured sequence: risk assessment first, then Facility Security Level (FSL) determination, then integrated controls, and finally governance and testing.

Three things you need to address immediately:

  • Risk assessment and FSL determination — scope the facility, identify threats and vulnerabilities, and document the FSL before specifying a single piece of equipment.
  • Integrated physical and electronic controls — zoning, access control, CCTV and intrusion detection must be designed as a single system, not bolted together after the fact.
  • Governance and annual reporting — the Protective Security Policy Framework (PSPF) mandates annual maturity reporting; accountability sits with the Accountable Authority of each entity.

Table of Contents

What core security services does a government facility actually need?

The answer depends on your FSL, but most government facilities draw from the same catalogue of services. The challenge is matching each service to the right use case rather than defaulting to a one-size-fits-all contract.

Static guards are the backbone of high-traffic entry points: reception desks, screening stations and secure lobbies. They are most effective when their role is clearly defined and they are supported by technology rather than expected to substitute for it. For a multi-tenant office building with public access, a single static post at the main entry combined with CCTV coverage is often the minimum viable posture.

Mobile patrols suit large campuses, after-hours perimeter checks and facilities where a permanent static presence is not cost-justified for every zone. A patrol vehicle covering multiple buildings overnight costs considerably less than staffing each building independently, and the unpredictability of patrol timing is itself a deterrent.

Alarm monitoring and Security Operations Centre (SOC) integration is non-negotiable for any facility handling classified material. A 24/7 monitored SOC receives alarm signals, verifies events and dispatches response — the response time target should be written into the contract as a service level agreement (SLA). Government tenancies increasingly require SOC integration as a procurement condition.

Infographic showing core government security services

Access control installation and maintenance covers everything from card readers on Zone 2 doors to dual-factor biometric systems on Zone 5 secure rooms. Installation is a one-time cost; maintenance and firmware updates are ongoing obligations that are frequently undercosted in tenders.

CCTV design and monitoring requires a coverage plan tied to zone definitions, not just camera placement for its own sake. Footage retention, image resolution and chain-of-custody procedures for evidentiary material all need to be specified upfront.

Security consultancy and risk assessment is the service that should precede all others. Commissioning a risk assessment before designing any system avoids the common mistake of specifying equipment to a perceived threat rather than a documented one. For procurement guidance on managing security contractors, the scope of work and deliverables should be defined before going to market.

  • Static guards: entry control, reception, screening
  • Mobile patrols: campus coverage, after-hours, perimeter
  • SOC/alarm monitoring: 24/7 verified response, classified facilities
  • Access control: installation, maintenance, audit logging
  • CCTV: design, monitoring, retention management
  • Consultancy: risk assessment, FSL determination, compliance review

Pro Tip: When procuring for a multi-tenant government building, require the ISC best-practice resource allocation model: a Facility Security Committee with documented cost-sharing arrangements for shared infrastructure. Without it, disputes over who pays for perimeter upgrades will stall every subsequent decision.


How the PSPF and classification system drive your security decisions

The PSPF is the governing framework for all Commonwealth entities. It is not a guideline — Accountable Authorities must implement it and the Department of Home Affairs may quality-assure annual reports. Understanding its structure is the prerequisite for every procurement and design decision.

The PSPF’s six domains are Governance, Risk, Information, Technology, Personnel and Physical. Each domain contains mandatory requirements and supporting guidance. The domains are interdependent: a decision in the Physical domain (zone definitions) directly affects what is permissible in the Information domain (where classified material can be used).

Security classifications determine access controls, vetting requirements and physical handling arrangements. The Australian Government uses four classifications: OFFICIAL: Sensitive, PROTECTED, SECRET and TOP SECRET. Each classification prescribes minimum protections under PSPF Policy 8, including marking, handling, storage and disposal.

Personnel accessing classified resources must hold the corresponding clearance level:

  • Baseline — access up to and including PROTECTED
  • Negative Vetting 1 (NV1) — access up to and including SECRET, with limited temporary TOP SECRET access
  • Negative Vetting 2 (NV2) — access up to and including TOP SECRET
  • Positive Vetting (PV) — access to TOP SECRET including some caveated resources

A security clearance is not required for OFFICIAL or OFFICIAL: Sensitive information. The Australian Government Security Vetting Agency (AGSVA) manages vetting for Baseline through to Positive Vetting levels, with Top Secret-Privileged Access (TS-PA) eventually replacing the current PV level under ASIO management.

Facility Security Levels translate the classification and threat picture into a facility-wide rating that drives physical and electronic control requirements. FSL decisions are the responsibility of the Accountable Authority and must be documented and reviewed on the cycle prescribed by the risk management process.

Pro Tip: Do not conflate the classification of information handled in a facility with the FSL of the facility itself. A building that occasionally hosts PROTECTED discussions is not automatically a high-FSL facility — the FSL is determined by the five weighted factors, not by the highest classification of a single document.


How to assess risk and set your facility security levels

Risk assessment is where most government security programmes either succeed or fail. The methodology matters less than the discipline of completing each step before moving to the next.

The five-step workflow

  1. Scope the assessment — define the facility boundaries, tenant agencies, assets and information types in scope. For campuses, treat shared infrastructure (car parks, perimeters, courtyards) as a single FSL decision and document cost-sharing arrangements in the tender.
  2. Threat and vulnerability analysis — identify credible threats (insider, external, cyber-physical) and map them to known vulnerabilities in the current physical and electronic posture.
  3. Consequence evaluation — assess the impact of a successful attack or compromise on mission continuity, personnel safety and classified information.
  4. FSL determination — apply the five equally weighted factors: mission criticality, symbolism, facility population, facility size and threat to tenant agencies. The intangibles factor allows assessor judgement for site-specific risks not captured by the five primary factors.
  5. Level of Protection (LOP) and countermeasure selection — select countermeasures from the baseline LOP for the determined FSL, document deviations and obtain approval.

The ISC Risk Management Process requires reassessment every five years for Level I–II facilities and every three years for Level III–V. Build those cycles into your programme calendar now.

Zone matrix: what each zone permits

ZonePublic accessVisitor accessAuthenticationTypical use
Zone 1YesUnrestrictedNone requiredFoyer, public counters
Zone 2RestrictedRestrictedSingle factorGeneral staff areas
Zone 3NoEscorted, need-to-knowSingle factorOperational offices
Zone 4NoEscorted, need-to-know, clearedSingle factorSensitive work areas
Zone 5NoEscorted, need-to-know, clearedDual factorClassified/secure rooms

Pro Tip: The most common zoning mistake is treating all floors of a multi-storey building as Zone 3 because the building is “restricted.” Zone definitions must reflect actual access patterns and information handling at each location. A floor with public-facing services is Zone 2 regardless of what sits above it.


Physical security controls that actually hold up under scrutiny

Physical countermeasures are the most visible part of any government security programme and the most frequently under-specified in tenders. Vague requirements produce vague bids.

Perimeter hardening starts with standoff distance. The greater the distance between a vehicle access point and the building facade, the more time responders have and the less structural damage a vehicle-borne threat can cause. Where standoff is constrained by the urban environment, passive barriers — bollards, planters, raised kerbs — compensate. Landscaping that improves sightlines (low-profile planting, clear zones around entry points) is a low-cost measure that is consistently overlooked.

Entry and internal controls include:

  • Secure doors rated to the relevant Australian Standard for forced-entry resistance
  • Turnstiles or mantraps at high-security entry points to prevent tailgating
  • Screening points (X-ray, walk-through detection) for facilities with public access or high symbolic value
  • Secure rooms constructed to PSPF specifications for classified discussions and document storage
  • Document-control spaces with clear-desk policies and secure storage for accountable material

Specification and maintenance requirements:

ComponentMinimum specificationTesting frequency
Perimeter bollardsAustralian Standard vehicle impact ratedAnnual inspection
Secure doorsForced-entry rated, self-closing, alarmedSix-monthly
Turnstiles/mantrapsAnti-tailgate sensor, alarm on breachMonthly functional test
Screening equipmentCalibrated to current threat profileQuarterly calibration
Secure roomPSPF Zone 5 construction standardAnnual certification

A recent policy update prohibits the use of SECRET materials in Zone 2 spaces, with transition periods of up to 24 months for entities needing to upgrade their physical environments. If your facility currently uses Zone 2 spaces for SECRET-level work, that remediation clock is already running.


Designing electronic security systems that meet FSL requirements

Electronic systems are only as good as their design brief. Specifying “CCTV and access control” without tying requirements to zone definitions and FSL produces systems that look complete on paper but fail under audit.

Access control design for government facilities must address credential type, network architecture and audit logging as a package:

  • Zone 3 and above: proximity card minimum; Zone 5 requires dual-factor (card plus PIN or biometric)
  • Biometric systems in sensitive zones must be on a segregated network segment, not the corporate LAN
  • Every access event must be logged with timestamp, credential ID and door ID; logs must be retained for a minimum period defined in the security plan
  • For server room access control and similar high-value spaces, audit logs should be reviewed weekly, not just retained

CCTV coverage principles:

  • Coverage must be designed from the zone plan outward, not from camera positions inward
  • Minimum image quality for evidentiary use: 1080p at the entry/exit points of each zone
  • Retention: 31 days minimum for general areas; longer for high-security zones (document the rationale)
  • Chain-of-custody procedures for exported footage must be written into the operational manual before go-live

Intrusion detection and SOC integration is where many programmes have a gap. An alarm that triggers but is not monitored in real time is a compliance checkbox, not a security control. SOC integration requires a defined escalation path: alarm event → SOC verification → dispatch or stand-down → incident log. False-alarm management is a contractual matter; require the provider to report false-alarm rates monthly and set a threshold that triggers a review.

Australia’s 2023–2030 national cyber security strategy supports whole-of-government cyber resilience, which directly affects how building management systems (BMS) and access control software are treated. Any networked physical security system is a potential cyber-attack surface.

Hands managing electronic security controls

Pro Tip: Require network segregation for all physical security systems as a non-negotiable tender condition. Access control software, CCTV recorders and BMS controllers on the same network segment as corporate IT create a lateral movement path for attackers. Segregation is cheap at design stage and expensive to retrofit.


Staffing, vetting and operational processes: the human layer

Technology fails without people who know what to do with it. The staffing model, vetting requirements and operational procedures are as important as any electronic system.

Vetting and clearance requirements by role

RoleMinimum clearanceRationale
Security managerNV1 (SECRET facility)Oversight of classified areas
Static guard (Zone 3–4)BaselineAccess to PROTECTED areas
Static guard (Zone 5)NV1 or NV2Access to SECRET/TOP SECRET areas
SOC operatorBaseline minimumAccess to alarm and CCTV data
Facility managerBaselinePhysical access to all zones
IT/electronic security technicianBaseline to NV1Access to security system infrastructure

For detailed guidance on security clearance levels and when each is required, the AGSVA definitions are the authoritative reference.

Operational roles and responsibilities

  1. Security manager — owns the security plan, FSL documentation, annual PSPF reporting and escalation decisions.
  2. Site supervisor — manages daily rosters, briefings, incident logs and guard welfare.
  3. SOC operator — monitors alarms and CCTV in real time, verifies events and dispatches response.
  4. Facility manager — coordinates maintenance access, contractor inductions and physical plant changes that affect security.
  5. Emergency coordinator — owns the emergency response plan, evacuation drills and liaison with emergency services.

Training and testing schedule

  • Initial induction: all security personnel before first shift
  • Annual refresher: PSPF obligations, emergency procedures, use-of-force policy
  • Quarterly: evacuation drill (at least one unannounced per year)
  • Monthly: test all alarm points, review SOC incident logs
  • Six-monthly: access control audit (active credentials vs current staff list)

How to plan, procure and schedule a security upgrade

Procurement is where good security intentions most often stall. The sequence matters: design before procurement, procurement before installation, installation before commissioning, commissioning before acceptance testing.

Procurement checklist

  1. Commission a risk assessment and FSL determination before writing the specification.
  2. Define the zone plan and derive the technical requirements from it.
  3. Write a scope of work with measurable deliverables, not a list of equipment.
  4. Issue a Request for Proposal (RFP) with mandatory questions on integration, maintenance, warranties and PSPF alignment.
  5. Evaluate bids against the scope, not just price.
  6. Require a commissioning and acceptance testing plan as a contract deliverable.
  7. Build a 24-month implementation window into the programme for any SECRET-zone upgrades affected by the recent policy change.

Questions to ask every bidder

  • How does your proposed system align with the PSPF zone definitions and FSL requirements for this facility?
  • What is your SOC uptime SLA and how do you manage false-alarm rates?
  • Who holds the relevant security clearances in your team, and at what level?
  • What is the maintenance and firmware update schedule for all electronic components?
  • How do you handle network segregation for physical security systems?
  • What is your process for acceptance testing and sign-off against the specification?

Red flags in bids

  • No mention of PSPF or FSL in the technical response
  • SOC monitoring offered as a value-add rather than a core deliverable
  • Maintenance costs not itemised separately from installation
  • No commissioning or acceptance testing plan
  • Vague references to “industry standard” without citing the applicable standard

Cost and timeline bands

Upgrade typeIndicative timelineComplexity drivers
Single-zone access control upgrade4–8 weeksIntegration with existing systems
CCTV system replacement (single building)6 weeksRetention infrastructure, cabling
Full electronic security retrofit (multi-zone)6 monthsZone count, classified area construction
Major physical hardening (perimeter, entry)3 monthsSite constraints, council approvals

Pro Tip: For phased upgrades, sequence the highest-FSL zones first. Completing Zone 5 work before Zone 3 means the most sensitive areas are protected while lower-risk areas are still in transition. Documenting this sequencing in the programme plan also satisfies the PSPF requirement to demonstrate a credible remediation path.


How Abcosecurity delivers integrated, PSPF-aligned security programmes

Abcosecurity brings over 15 years of experience delivering integrated security programmes across government, healthcare, corporate and construction environments in Australia. The company holds ISO 9001 quality management certification, operates a 24/7 monitoring capability and employs licensed security personnel across all service lines.

Capability proof points:

  • Licensed static guards and mobile patrol officers deployable across all FSL zones
  • 24/7 SOC monitoring with documented escalation procedures and SLA-backed response times
  • Electronic security design, installation and maintenance covering access control, CCTV and intrusion detection
  • Security risk assessments and FSL determination services aligned to PSPF requirements
  • ISO 9001-certified quality management processes applied to all programme delivery

Service matrix aligned to FSLs:

FSL levelRecommended service bundle
Level I–IIMobile patrols, alarm monitoring, basic access control
Level IIIStatic guard (entry), SOC monitoring, CCTV, card access
Level IVStatic guard (multi-post), SOC, biometric access, CCTV, risk assessment
Level VFull integrated programme: guards, SOC, electronic systems, consultancy, annual review

Sample tender line items for RFPs:

  • SOC uptime SLA: 99.9% availability with documented escalation path and monthly false-alarm reporting
  • Vetting clause: all personnel accessing Zone 4 and above to hold minimum Baseline clearance; Zone 5 personnel to hold NV1 or above
  • FSL compliance deliverable: written FSL determination report with supporting evidence, reviewed annually
  • Maintenance schedule: all electronic security components to be maintained and firmware-updated on a schedule agreed at contract execution

Abcosecurity’s security management services are structured to align with PSPF domains, meaning a commissioning manager can map each service line directly to a mandatory requirement rather than having to justify the fit after the fact.


Emergency preparedness and response planning

A security programme without a tested emergency response plan is incomplete. The plan must cover three distinct scenarios: evacuation, lockdown and coordination with external emergency services.

Evacuation procedures need to account for the zone structure of the building. Classified material cannot simply be left at workstations during an evacuation; the plan must specify who is responsible for securing or destroying accountable material before leaving, and under what time constraints. Warden roles, assembly points and re-entry procedures all need to be documented and drilled.

Security team emergency planning session

Lockdown protocols are triggered by a different threat profile: an active threat inside or approaching the facility. The lockdown plan must specify who has authority to declare a lockdown, how staff are notified (PA, SMS, visual signal), which doors are secured automatically by the access control system and which require manual intervention. Zone 5 areas with dual-factor access control provide a natural lockdown boundary, but the plan must not assume technology will work under all threat conditions.

Coordination with emergency services requires pre-established relationships, not just phone numbers. The security manager should brief the local police, fire and ambulance services on the facility’s layout, zone structure and any classified areas that responders should not enter without escort. Some facilities require a memorandum of understanding (MOU) with the relevant emergency services to formalise this arrangement. Annual joint exercises are the most effective way to identify gaps before an incident does.


Cybersecurity integration with physical security systems

Physical security systems are now networked, and that changes the threat model. Access control software, CCTV recorders, intercoms and building management systems are all potential entry points for a cyber adversary.

The principle is straightforward: treat physical security systems as IT assets. That means they are subject to the same patch management, access control and audit logging requirements as any other networked system. In practice, many government facilities have legacy physical security infrastructure that was installed before this principle was widely understood, and it sits on the corporate network with default credentials and years of unpatched firmware.

Network segregation is the single most effective control. Physical security systems should sit on a dedicated VLAN or physically separate network segment, with firewall rules that permit only the traffic necessary for monitoring and management. The national cyber security strategy emphasises whole-of-government cyber resilience; physical security systems are explicitly within scope of that obligation.

For facilities handling SECRET or TOP SECRET material, penetration testing of physical security systems should be included in the annual security review cycle. A test that covers only IT systems but ignores the access control server is an incomplete assessment.


Visitor management and contractor security protocols

Visitors and contractors are the most common source of uncontrolled access in government facilities. A visitor management system that relies on a paper sign-in book at reception is not a security control; it is a record-keeping exercise.

Visitor management for a government facility should include pre-registration (name, organisation, purpose, host), identity verification on arrival, a temporary credential (visitor badge) that is visually distinct from staff credentials, and an escort requirement for all zones above Zone 2. The host is responsible for the visitor’s behaviour and for returning the credential at departure. Access logs must capture entry and exit times for every visitor.

Contractor security protocols are more complex because contractors often need unsupervised access to plant rooms, roof spaces and IT infrastructure. Every contractor should be inducted before first access, with the induction covering the zone structure, prohibited areas, emergency procedures and the requirement to report anything unusual. For contractors accessing Zone 4 or above, a Baseline clearance should be a contract condition. Supply chain security obligations extend to the sub-contractors a primary contractor brings on site.

A commercial building inspection at the outset of a major upgrade — covering structural condition, existing security infrastructure and access point locations — gives the security manager a documented baseline for the tender. Services like commercial building inspections can provide that baseline condition report before the security specification is written.


Secure rooms, classified areas and document control

Zone 5 spaces require construction standards that go beyond a locked door. A secure room for classified discussions must meet the PSPF’s physical construction requirements: walls, floors and ceilings built to prevent acoustic and electronic emanation, with no penetrations that are not sealed and documented.

Document control for accountable material (SECRET and above) requires a register, a custodian and a defined lifecycle from receipt through use to destruction. The register must be auditable: every item in, every item out, every person who accessed it. Destruction must follow the approved method for the classification level and be witnessed and recorded.

Practical requirements for classified areas:

  • No personal electronic devices (phones, tablets, smartwatches) in Zone 5 spaces unless specifically approved and documented
  • Clear-desk policy enforced at the end of every working day
  • Secure storage (combination-locked containers rated to the classification level) for all accountable material not in active use
  • TEMPEST considerations for facilities handling TOP SECRET electronic information (specialist advice required)

The recent policy update prohibiting SECRET material in Zone 2 spaces means any facility that has been operating classified discussions in general office areas needs a remediation plan. The 24-month transition window is a ceiling, not a target.


Threat-specific security measures: terrorism, protests and natural disasters

Government buildings face a threat profile that commercial facilities do not. The combination of symbolic value, public access requirements and classified information makes them attractive targets for a range of threat actors.

Terrorism and hostile vehicle threats are addressed through the physical hardening measures described earlier: standoff distance, vehicle barriers and screening. The Australian Security Intelligence Organisation (ASIO) publishes a national threat level that should inform the frequency of security reviews and the stringency of screening at high-symbolism facilities. When the threat level is elevated, additional measures — increased guard presence, vehicle search protocols, enhanced screening — should be triggered by a pre-written contingency plan rather than improvised.

Protests and civil disruption require a different response posture. The security plan should distinguish between lawful protest (which requires facilitation, not suppression) and unlawful activity that threatens building access or personnel safety. Guards must be briefed on the legal boundaries of their authority, and the escalation path to police must be clear and pre-agreed. Crowd control planning for facilities with regular public access should be part of the base security plan, not an afterthought.

Natural disasters — bushfire, flood, cyclone depending on location — affect both the physical integrity of the facility and the ability to maintain security operations. The business continuity plan must address how classified material is secured or evacuated, how SOC monitoring is maintained if the primary facility is inaccessible, and how access control systems behave during a power failure (fail-secure vs fail-safe decisions must be made at design stage and documented).


Key takeaways

Effective security for government buildings requires a documented, PSPF-aligned programme that integrates physical controls, electronic systems and trained personnel within a clear governance structure.

PointDetails
PSPF compliance is mandatoryCommonwealth entities must report maturity across all six PSPF domains annually; the Accountable Authority is responsible.
FSL drives every control decisionDetermine the Facility Security Level before specifying any equipment; the five weighted factors plus intangibles set the baseline.
Zone definitions are bindingZones 1–5 prescribe permitted devices, authentication strength and visitor access; treating zones as interchangeable undermines all controls.
Cyber and physical security are one systemPhysical security systems must be network-segregated, patched and tested as IT assets under the national cyber security strategy.
Abcosecurity delivers end-to-end programmesWith 15+ years of experience, ISO 9001 certification and 24/7 SOC capability, Abcosecurity aligns service delivery directly to PSPF and FSL requirements.

The ownership gap that undermines most government security programmes

The most persistent problem in government facility security is not a technology gap. It is a governance gap: no single person owns the whole programme.

Physical security sits with the facilities team. Electronic security sits with IT. Personnel vetting sits with HR. The security manager writes the plan but has no authority over the budget lines that fund it. The result is a programme that looks complete on paper and falls apart under an audit or, worse, an incident.

The ISC guidance on centralised security oversight is direct on this point: designate a Director of Security or equivalent with consolidated authority over strategy, technology and personnel decisions. That single change — one owner, one budget line, one accountability — does more for programme effectiveness than any individual technology upgrade.

The practical tip: before you commission a risk assessment or write an RFP, map who currently owns each security function in your organisation. If the answer involves more than two teams, fix the ownership structure first. A well-designed system run by a fragmented team will always underperform a simpler system run by a unified one.


Abcosecurity can help you build a compliant, audit-ready security programme

Government security managers face a specific challenge: the stakes of getting it wrong are high, the compliance obligations are detailed, and the procurement process is slow. What you need is a provider who understands PSPF obligations from the inside and can translate them into a programme that holds up under audit.

Abcosecurity

Abcosecurity delivers integrated security programmes for government facilities across Australia, combining licensed static guards, mobile patrols, 24/7 SOC monitoring and electronic security installation under a single managed contract. Every programme is aligned to industry best practices and structured to meet PSPF reporting requirements. With ISO 9001 certification and over 15 years of experience in regulated environments, Abcosecurity gives commissioning managers the documentation and audit trail they need.

To request a site security assessment or get assistance preparing your RFP, contact Abcosecurity directly at abcosecurity.com.au or review the ISO 9001 quality management credentials before your next procurement round.


Useful sources

The following primary references cover mandatory requirements and best-practice guidance for Australian government facility security.

  • Protective Security Policy Framework — the mandatory framework for all Commonwealth entities; contains all six domain policies including Physical (Policy 15) and Classification (Policy 8). Use this as the primary compliance reference.
  • PSPF Policy 8: Classification system — mandatory requirements for marking, handling, storage and disposal of classified information. Use when designing document-control procedures and secure room specifications.
  • Security classifications and protective markings — Style Manual — authoritative reference for the four classification levels and their handling requirements. Use when briefing staff or writing classification policy.
  • Australian Government Security Vetting Agency (AGSVA) — defines the four clearance levels (Baseline, NV1, NV2, PV) and the forthcoming TS-PA level. Use when specifying vetting requirements in contracts and position descriptions.
  • ISC Risk Management Process — 2024 Edition — the five-step FSL methodology and assessment cycle requirements. Best-practice reference for risk assessment methodology; note this is a US standard applied as best practice in Australia.
  • ISC Best Practices for Planning and Managing Physical Security Resources — guidance on centralised security governance, resource allocation and multi-tenant cost sharing. Use for governance structure and procurement planning.
  • NSW Government Information Classification, Labelling and Handling Guidelines — state-level implementation of PSPF classification requirements including zone definitions. Useful for NSW entities and as a practical implementation reference for other jurisdictions.
  • Protective Security news — Policy update on sensitive and classified information — details the prohibition on SECRET material in Zone 2 spaces and the 24-month transition window. Mandatory reading for any facility currently using Zone 2 for classified work.
SourceTypeUse for
PSPF (protectivesecurity.gov.au)MandatoryAll six domains; annual reporting
PSPF Policy 8MandatoryClassification handling and secure rooms
Style ManualMandatoryClassification levels and markings
AGSVAMandatoryVetting and clearance requirements
ISC RMP 2024Best practiceFSL methodology and assessment cycles
ISC Physical Security ResourcesBest practiceGovernance structure and procurement
NSW Classification GuidelinesState guidancePractical implementation reference
PSPF Policy update (Zone 2)MandatorySECRET zone remediation planning

FAQ

What are the four Australian Government security classifications?

The four classifications are OFFICIAL: Sensitive, PROTECTED, SECRET and TOP SECRET, as defined in the PSPF and the Style Manual. Each level prescribes minimum handling, storage and disposal requirements under PSPF Policy 8.

What are the four security clearance levels in Australia?

The Australian Government Security Vetting Agency defines four levels: Baseline (up to PROTECTED), Negative Vetting 1 (up to SECRET), Negative Vetting 2 (up to TOP SECRET) and Positive Vetting (TOP SECRET including caveated resources). A clearance is not required for OFFICIAL or OFFICIAL: Sensitive information.

What is a Facility Security Level and who determines it?

A Facility Security Level (FSL) is a rating derived from five equally weighted factors — mission criticality, symbolism, facility population, facility size and threat to tenant agencies — plus an intangibles factor for site-specific risks. The Accountable Authority of the entity is responsible for determining and documenting the FSL.

How often must a government facility risk assessment be reviewed?

Under the ISC Risk Management Process, Level I–II facilities require reassessment every five years and Level III–V facilities every three years. The PSPF also requires annual maturity reporting across all six security domains.

What is the most secure type of government building space?

Zone 5 spaces represent the highest physical security standard under the PSPF zone framework: no public access, escorted cleared visitors only, dual-factor authentication and construction standards that prevent acoustic and electronic emanation. Abcosecurity designs and delivers Zone 5-compliant programmes for government clients across Australia.

Leave A Comment

related posts