Skip to main content

The Administrative Arrangements Order of 3 August 2023 transferred responsibility for protective security policy, including the Protective Security Policy Framework, to the Department of Home Affairs from the Attorney-General’s Department. These Machinery of Government (MOG) changes commenced on 4 August 2023.

Policy 16: Entity facilities

  • Physical security
Publication date
Last updated


This policy describes how to plan, select, design and modify facilities to ensure people, information and assets are protected.


Entities must fully integrate protective security when they plan, select, design and modify facilities to ensure people, information and assets are protected.

To determine the access requirements for facilities and define restricted access areas (referred to as Security Zones), entities must consider the highest risk level to entity resources.

ASIO’s Technical Notes, available on GovTEAMS, support Policy 16 with information on designing and modifying government facilities and security zones. The Technical Notes provide specifications on building construction, perimeter hardware, security alarm systems and access control.

Before being used operationally, Security Zones must be certified and accredited in line with ASIO’s Technical Notes and the PSPF.

Additional Australian Signals Directorate accreditation is required for Zone Five facilities used to secure and access compartmented information. Security Zone certification is time-limited. This means that facilities may require recertification from time to time.

For outsourced ICT facilities, entities must obtain ASIO-T4 physical security certification to hold information that has a catastrophic business impact level.

Technical surveillance countermeasures (TSCM) protect security classified discussions from technical compromise. This can involve real-time audio interception using electronic transmitting and receiving equipment or a TSCM inspection that searches for surveillance devices. Where security classified discussions occur, entities must undertake TSCM inspections.

Return to the Physical security page