Physical Information Security Assurance

Protecting confidential information beyond the 
conventional cyber boundary.

What is Physical Information Security Assurance?

Physical Information Security Assurance (PISA) is a structured approach to understanding and assuring the protection of confidential information within the physical environment.

Modern information security is highly developed, yet information does not exist only within networks, systems and digital infrastructure. It is spoken in meetings, displayed on screens, discussed in offices, carried by people and transmitted through the physical and technical environments in which organisations operate.

These exposures can sit between established disciplines including physical security, cyber security,   information security, Technical Surveillance Countermeasures (TSCM) and organisational governance PISA provides an assurance perspective across these boundaries.

It considers how people, information and places interact, where confidential information may become vulnerable, whether appropriate controls are in place and whether those controls provide the level of  assurance required.

PISA does not replace established security disciplines, standards or frameworks. It brings relevant elements together around a specific objective: the protection and assurance of confidential information within the physical environment.

This may include the environments in which sensitive conversations take place, physical and technical infrastructure, speech privacy, surveillance risk, operational behaviours, executive and boardroom environments, and the effectiveness of existing protective measures.

The approach moves beyond simply searching for evidence of compromise. The absence of an identified threat does not, by itself, provide assurance that an environment is appropriately protected.

Effective assurance requires an understanding of the environment, the information being protected, the threats and vulnerabilities that may affect it, the controls already in place and the level of residual uncertainty.

For organisations, PISA provides a means of bringing these considerations into a more structured assurance process — supporting proportionate risk treatment, informed decision-making and confidence at security, risk, governance and executive level.

People. Information. Places.

Physical Information Security Assurance brings them together.

Cope Whiterock Limited is a company registered in England and Wales. Company No. 03063360

Registered Office: 167-169 Great Portland Street, London, W1W 5PF. VAT No. GB 669 1293 04.

Information icon

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.