DISP Physical Security Requirements Explained

Physical security is a core pillar of the Defence Industry Security Program (DISP). While cyber security and personnel clearances often receive the most attention, physical security remains fundamental to protecting Defence information, assets, and environments.

For many organisations, physical security is also one of the most misunderstood DISP domains. Assumptions are often made that standard office controls are sufficient, or that physical security only applies to high-classification environments. In practice, physical security expectations apply across all DISP membership levels, scaling with risk and information sensitivity.

This article explains what physical security means under DISP, how requirements differ by membership level, and what Defence looks for when assessing physical security arrangements.

Why physical security matters under DISP

Physical security protects against unauthorised physical access to information, systems, and environments that support Defence activities.

Even in highly digital environments, physical access remains a critical attack vector. Unauthorised entry to offices, server rooms, or storage areas can undermine cyber controls, expose sensitive information, or compromise operations.

DISP treats physical security as an essential layer of defence that complements personnel and cyber controls.

Physical security as a risk-based requirement

Physical security requirements under DISP are risk-based, not uniform.

Defence assesses physical security arrangements based on:

  • The classification of information handled
  • The facilities used to store or process information
  • The level of access personnel require
  • The organisation’s DISP membership level

This means physical security controls must be appropriate and proportionate, rather than excessive or minimal by default.

Physical security at Entry Level DISP

At Entry Level, organisations typically handle OFFICIAL or OFFICIAL: Sensitive information.

Physical security expectations at this level focus on:

  • Preventing unauthorised access to work areas
  • Controlling entry to offices or premises
  • Securing information when not in use

Common controls may include basic access control measures, clear desk practices, and defined visitor management procedures.

Defence does not expect complex infrastructure at Entry Level, but it does expect deliberate and documented arrangements.

Physical security at DISP Level 1

DISP Level 1 applies where organisations handle PROTECTED information.

At this level, physical security controls become more structured and formalised.

Organisations are typically expected to:

  • Control access to areas where PROTECTED information is handled
  • Secure storage for sensitive material
  • Manage visitor access and supervision
  • Define after-hours access arrangements

Physical controls must align with how information is actually handled, not just how it is described in policy.

Physical security at DISP Level 2

DISP Level 2 applies where organisations handle information classified up to SECRET.

Physical security requirements at this level are significantly more rigorous.

Organisations are expected to:

  • Clearly define secure areas
  • Implement stronger access controls
  • Restrict and monitor access to sensitive spaces
  • Ensure secure storage and handling of classified material
  • Prevent unauthorised observation or access

Facilities supporting SECRET information are subject to closer scrutiny, and controls must be demonstrable and consistently enforced.

Physical security at DISP Level 3

DISP Level 3 applies where organisations handle TOP SECRET information.

At this level, physical security controls are highly restrictive and tightly controlled.

Expectations typically include:

  • Dedicated secure facilities
  • Strong access segregation
  • Continuous monitoring and oversight
  • Formalised procedures for access, storage, and movement of information

Level 3 physical security arrangements are uncommon and generally limited to organisations supporting highly sensitive Defence capabilities.

Shared and commercial office environments

Many DISP members operate from shared or commercial office environments.

This is acceptable under DISP, provided physical security arrangements are appropriate to the classification of information handled.

Key considerations include:

  • Separation of Defence and non-Defence activities
  • Control of shared access points
  • Visitor supervision
  • Secure storage for sensitive material

Assumptions that shared offices automatically fail physical security requirements are incorrect. The focus is on risk management and control effectiveness.

Visitor management and supervision

Visitor management is a consistent focus during DISP assessments.

Organisations are expected to:

  • Define who can enter secure areas
  • Record and manage visitor access
  • Ensure visitors are supervised where required
  • Prevent inadvertent access to sensitive information

Informal or inconsistent visitor practices are a common source of physical security findings.

Physical security and personnel behaviour

Physical security is not only about infrastructure. It is also about how people behave.

DISP assessments often consider whether:

  • Personnel challenge unauthorised access
  • Secure areas are respected
  • Procedures are followed consistently
  • Security awareness is reinforced

Strong physical security culture complements technical controls.

Documenting physical security arrangements

Documentation plays an important role in demonstrating physical security compliance.

Defence typically expects organisations to be able to describe:

  • Facility layouts and secure areas
  • Access control arrangements
  • Storage practices
  • Visitor procedures
  • After-hours security measures

Documentation must reflect reality. Discrepancies between documented and actual practices are commonly identified during assessment.

Managing changes to facilities

Facilities change over time, and physical security must change with them.

Examples include:

  • Office relocations
  • Fit-out changes
  • Expansion into new spaces
  • Changes in access arrangements

DISP expects physical security to be reassessed when facilities change, rather than assumed to remain compliant.

Common physical security issues under DISP

Common issues identified during DISP assessment include:

  • Uncontrolled access to sensitive areas
  • Inadequate storage for classified material
  • Poor visitor supervision
  • Overreliance on informal practices
  • Controls that exist in policy but not in practice

These issues are usually the result of oversight rather than intent.

Physical security as part of an integrated approach

Physical security under DISP does not operate in isolation.

It must align with:

  • Personnel security controls
  • Cyber security measures
  • Governance and oversight arrangements

An integrated approach ensures that physical, personnel, and cyber controls reinforce one another.

Final thoughts

Physical security remains a foundational requirement under DISP.

While controls scale with risk and classification, every DISP member must demonstrate that physical access to Defence information and environments is appropriately controlled.

Understanding physical security expectations early helps organisations design practical, proportionate controls that support compliance without unnecessary complexity.

In DISP environments, physical security is not about fortification, it is about deliberate control, consistent behaviour, and alignment with real operational risk.

Most organisations entering the Defence supply chain underestimate what DISP actually requires or assume existing policies are enough.

The DISP Readiness Quiz gives you a fast, structured way to understand where your organisation really stands.

more insights