detections
- ID: DT163
- Created: 01st August 2026
- Updated: 01st August 2026
- Contributor: The ITM Team
Physical Security Patrols
Conduct routine and targeted physical security patrols within restricted and high-impact areas to identify subjects who are not authorized to be present or whose activity is inconsistent with the purpose of the area.
Security personnel should verify physical identity tokens, access permissions, work schedules, visitor records, maintenance activity, and approved out-of-hours access. Patrols may identify subjects who are present without a clear operational purpose, remain in an area beyond their authorized period, enter locations outside their assigned responsibilities, or engage in unexpected activity involving equipment, records, infrastructure, or physical security controls.
Particular attention should be given to shift changes, closure periods, low-occupancy hours, maintenance windows, and other times when unauthorized presence may be less visible. Findings should be recorded and correlated with physical access logs, closed-circuit television, visitor-management records, and area-specific schedules.
A physical identity token should be checked against the subject presenting it and should confirm authorization for the specific area and time period. General building access should not be treated as authorization for a restricted area.
Sections
| ID | Name | Description |
|---|---|---|
| IF031 | Unauthorized Presence in Restricted Physical Areas | A subject deliberately enters or remains within a physical area as a trespasser, knowing they are not authorized to be present, where that presence alone creates a credible risk of harm to the organization.
|
| IF031.006 | Remaining in a Restricted Area Outside Authorized Hours | A subject knowingly remains within a restricted physical area after their authorized access period has ended, or enters the area during a time when their role, assignment, escort approval, or access authorization does not permit their presence.
The subject may have legitimate daytime or task-based access to the location, but that authority does not extend to the time at which the presence occurs. Relevant behaviors include remaining after a shift or escorted visit, entering during a closed period, concealing continued presence after other personnel depart, or returning outside an approved access window.
The infringement is distinguished from accidental overstay by evidence that the subject understood the temporal restriction and deliberately remained or entered regardless. |
| IF031.005 | Unauthorized Presence in Records or Evidence Storage Areas | A subject deliberately enters or remains within an area used to store physical records, legal files, personnel documents, investigative material, evidential items, archived media, regulated records, or chain-of-custody material without authorization.
Unauthorized presence may expose confidential information or provide an opportunity to inspect, remove, substitute, contaminate, damage, or interfere with stored material. The infringement applies where the subject knowingly enters the controlled area, even where subsequent access to a specific record or evidential item cannot be established. |
| IF031.004 | Unauthorized Presence in Research, Laboratory, or Production Areas | A subject deliberately enters or remains within a restricted research facility, laboratory, prototype area, test environment, manufacturing floor, production line, formulation area, engineering workspace, or other location containing sensitive development or operational activity without authorization.
The area may expose unreleased intellectual property, prototypes, formulas, samples, research data, specialized equipment, manufacturing methods, safety-critical processes, or regulated materials. The subject’s presence may create risks to confidentiality, product integrity, safety, regulatory compliance, or operational continuity even where no additional action is observed. |
| IF031.003 | Unauthorized Presence in Executive or Board Areas | A subject deliberately enters or remains within an executive office, boardroom, senior leadership meeting space, executive support area, or other restricted location used for confidential organizational decision-making without authorization.
The subject’s presence may expose strategic discussions, merger or acquisition information, financial results, legal advice, personnel decisions, security matters, executive schedules, authentication material, or confidential documents. The infringement applies even where the subject does not remove information or interrupt the meeting, because unauthorized observation or proximity may compromise sensitive organizational matters. |
| IF031.002 | Unauthorized Presence in Security Operations Areas | A subject deliberately enters or remains within a Security Operations Center, incident response room, insider threat investigation area, physical security control room, crisis-management room, or other restricted security operations environment without authorization.
Presence in these areas may expose active alerts, investigative information, subject identities, security architecture, surveillance feeds, response plans, detection capabilities, access credentials, or operational discussions. The subject does not need to interact with a security system or obtain a copy of information; unauthorized proximity to visible or audible security operations is sufficient for the infringement. |
| IF031.001 | Unauthorized Presence in Data Center or Communications Areas | A subject deliberately enters or remains within a data center, server room, network operations area, telecommunications room, cable distribution area, or other restricted environment containing critical information technology or communications infrastructure without authorization to be present.
The subject’s proximity may provide direct access to servers, storage systems, network appliances, cabling, console interfaces, removable media, environmental controls, or out-of-band management equipment. The infringement applies where the subject knowingly crosses an established physical boundary, regardless of whether they subsequently interact with the equipment. |
| PR009.001 | Restricted Area Reconnaissance | A subject observes, explores, or informally surveys access routes, entrances, barriers, internal layouts, staffing patterns, and operational routines associated with a restricted physical area.
The subject may seek to identify which doors are badge-controlled, when an area is unattended, how visitors are processed, whether personnel challenge unfamiliar individuals, or where movement is not covered by security personnel or closed-circuit television. The activity may appear innocuous in isolation, but repeated or unexplained observation can indicate preparation for unauthorized entry, theft, sabotage, data access, or another physical infringement. |
| PR009.002 | Identification of Unsecured Physical Assets | A subject searches for or identifies physical assets that are unattended, insufficiently secured, or accessible outside normal control processes.
These assets may include laptops, removable media, physical identity tokens, keys, printed records, unlocked cabinets, exposed network ports, backup media, prototype equipment, or devices left in shared or low-occupancy areas. The subject may test whether an asset can be handled, removed, connected to, photographed, or accessed without attracting attention.
This behavior is operationally relevant where it indicates that the subject is identifying opportunities that could later support theft, credential misuse, unauthorized system access, data loss, or physical sabotage. |
| PR009.003 | Entry and Exit Route Reconnaissance | A subject identifies or assesses routes through which they or another person could enter, leave, or move through an organizational facility while reducing the likelihood of challenge or detection.
The subject may observe loading areas, emergency exits, service corridors, shared tenant spaces, stairwells, parking access points, delivery entrances, maintenance routes, or locations with limited physical security coverage. They may also assess whether doors are routinely propped open, whether exit routes permit re-entry, or whether movement between zones can occur without an additional credential check.
The behavior may indicate preparation to bypass normal entry controls, facilitate unauthorized third-party access, remove assets, or move between restricted areas without creating a complete access record. |
| PR009.004 | Security Patrol Pattern Observation | A subject observes the timing, route, frequency, staffing, or behavior of physical security patrols to identify periods or locations where monitoring is reduced.
The subject may repeatedly remain near patrol routes, note when security personnel enter or leave an area, track shift changes, observe response times, or determine whether patrols follow predictable schedules. They may also identify areas that are checked only intermittently or periods when security personnel are occupied elsewhere.
This behavior can support later unauthorized presence, theft, sabotage, tampering, or access to sensitive areas by allowing the subject to act during a predictable gap in physical oversight. |
| PR040.002 | Testing Access Controls | A subject attempts to access a system, repository, application, physical area, account, record set, or other restricted resource to determine whether the applicable access control prevents entry or generates a response.
The subject may use their own identity to request or attempt access slightly outside their normal responsibilities, test an expired or unauthorized physical identity token, navigate directly to a restricted application resource, or attempt to view information associated with another team, customer, case, or business function.
The action may be deliberately limited so that it can be described as accidental if challenged. Repeated denied attempts, access testing across several resources, or a later successful entry may indicate that the subject is mapping authorization boundaries before conducting unauthorized access or another infringement. |
| PR040.005 | Testing Physical Security Controls | A subject performs a limited physical action to determine whether access controls, security personnel, surveillance, visitor procedures, alarms, or other physical safeguards prevent or identify unauthorized presence.
The subject may test a restricted door, present a credential at an unauthorized area, follow another person through a controlled entrance, remain in an area after their approved access period, or enter a sensitive location without a clear operational reason. They may also observe whether security personnel challenge unfamiliar subjects or whether physical access violations generate follow-up activity.
The behavior is distinct from general physical exploration because the subject actively interacts with or crosses a security boundary to evaluate the result. The test may support later unauthorized entry, physical sabotage, theft, access to infrastructure, or facilitation of another person’s presence. |