Summary
In short
- The insider is the design case for most operational security exposures, and perimeter controls do not constrain someone with legitimate access.
- Workplace violence toward staff is now a regulated subject in a growing number of jurisdictions rather than a general duty matter.
- California's SB 553 requires most employers with any California location to hold a written workplace violence prevention plan, a violent incident log and annual training, in force since July 2024, with penalties for serious violations reaching into five figures.
- There is no exemption for organisations headquartered elsewhere. Any California location brings the obligation.
- Cal/OSHA was directed to propose a general industry workplace violence standard by December 2025 with adoption due by the end of 2026, while federal rulemaking has not produced a proposed rule.
- Assessment should cover people first, then product and premises. Most assessments run that order backwards.
What it is
What it is
What is a security risk assessment?
An assessment of threats to people, premises, product and information, the controls in place, and the gaps between them. In an operational setting it spans workplace violence toward staff, unauthorised access, theft and, where food or pharmaceutical product is handled, deliberate contamination.
How does it relate to food defense?
Food defense under the FSMA Intentional Adulteration rule is a specific regime addressing deliberate contamination intended to cause wide-scale public health harm, organised around actionable process steps. A general security assessment is broader and does not satisfy it. Where both apply, they should reference each other rather than merge.
When to use it
When to use it, and when not to
This assessment covers security threats across people, premises, product and information. Specific regimes sit alongside it.
Use it for
- Threats to staff including aggression from the public, service users, contractors and colleagues
- Unauthorised access to premises, restricted areas and vehicles
- Theft of product, equipment, materials and data
- Site security supporting food defense, where a separate plan is also required
- Following an incident, a threat, or a change to site layout, occupancy or operating hours
Not for
- The food defense plan under 21 CFR Part 121, which is a distinct regime organised around actionable process steps
- The workplace violence prevention plan, which in California has prescribed content and its own log
- Information security risk assessment, which addresses systems and data with its own methodology
- Lone working assessment, which addresses a specific exposure this may reference
- Physical access control administration, which implements the conclusions rather than reaching them
Standards
What it is built against
Security spans an occupational safety duty, a fast-moving workplace violence regime, and product-specific requirements where food or pharmaceuticals are handled.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.6.1.2 | Hazard identification including violence and work organisation factors | Threats considered |
| Cal Labor Code 6401.9 | Written workplace violence prevention plan, violent incident log, training and post-incident investigation | Controls in place |
| OSHA General Duty Clause | Duty to address recognised hazards including workplace violence where feasible controls exist | Threats considered |
| 21 CFR Part 121 | Food defense plan with vulnerability assessment and mitigation strategies, where the IA rule applies | Controls in place |
| GFSI schemes | Site security and food defense requirements including access control and visitor management | Controls in place |
| CTPAT | Supply chain security criteria including yard security, seal verification and container inspection | Controls in place |
| ISO 27001 A.7 | Physical entry controls, securing offices and facilities, and working in secure areas | Controls in place |
| ISO 45001 cl.8.2 | Emergency preparedness covering security incidents alongside other emergencies | Outcome |
What it does not cover
- The food defense plan under the Intentional Adulteration rule, which is a distinct regime with its own required components.
- The workplace violence prevention plan, which where required has prescribed content, training and a separate incident log.
- Information security risk assessment, which addresses systems, data and access with a different methodology.
- Access control administration, which implements the conclusions rather than producing them.
- Lone working assessment, which covers a specific exposure this assessment should reference.
Filling it in
Filling it in well
Order matters here more than in most assessments, because the default order produces the wrong controls.
Start with who is exposed to aggression, when, and with what support available. Counter staff, drivers, home visitors, night shift, lone workers and anyone handling refusals or enforcement. Premises and product follow. Assessments that start with the building reliably conclude with cameras and gates and leave the front desk unaddressed.
For each restricted area, who holds access, why, and when it was last reviewed. Access accumulates through role changes and project work and is almost never removed. The list of people who can reach the most sensitive area of a site is usually longer than anyone expects and older than anyone realises.
They are on site, frequently unescorted, and outside the induction and access systems that cover employees. In yards, delivery drivers are alone with vehicles and product for extended periods. Any assessment omitting them has left out the population with the most access and the least oversight.
Where a workplace violence prevention plan or a food defense plan is required, this assessment should feed them and reference them, not attempt to be them. Both have specified components and retention requirements that a general security assessment does not satisfy.
Audit findings
Common audit findings
Security findings concentrate on the inside of the fence.
| Finding | Clause | What fixes it |
|---|---|---|
| Assessment addresses perimeter only, with no aggression exposure assessed. | ISO 45001 cl.6.1.2 | Assess people first; the perimeter does not constrain someone already inside. |
| California location without a written workplace violence prevention plan. | Cal Labor Code 6401.9 | Required since July 2024; there is no exemption for out-of-state headquarters. |
| Violent incident log absent or missing required fields. | Cal Labor Code 6401.9 | Maintain with the prescribed content, retained five years and viewable by employees on request. |
| Access lists not reviewed, with former employees or completed projects still holding access. | ISO 27001 A.7 | Review on a cycle and on role change; access accumulates and is never removed by default. |
| Contractors and delivery drivers outside the assessment scope. | ISO 45001 cl.8.1.4 | Include them; they have the most access and the least oversight. |
| General security assessment presented as a food defense plan. | 21 CFR Part 121 | They are different regimes; the IA rule requires specific components a security assessment does not contain. |
| No de-escalation training for roles exposed to aggression. | Cal Labor Code 6401.9 | Train the exposed roles; where a plan is required, training is a specified element. |
| Incidents not recorded because no injury resulted. | Cal Labor Code 6401.9 | Log every violent incident regardless of injury; that is the requirement and the trend data. |
| Assessment not reviewed after a change to hours, layout or occupancy. | ISO 45001 cl.6.1.2 | Extended hours and layout changes alter exposure; treat both as triggers. |
| Staff not consulted on which situations feel unsafe. | ISO 45001 cl.5.4 | Ask; the people at the counter know which interactions escalate. |
Worked case
Case in point: the regime that arrived without being noticed
California's SB 553 took effect on 1 July 2024, adding Labor Code section 6401.9. It requires nearly all California employers to establish, implement and maintain a written workplace violence prevention plan, keep a violent incident log with prescribed fields, provide initial and annual training, investigate incidents, and retain hazard and incident records for five years and training records for one year.
The exemptions are narrow: worksites with fewer than ten employees not open to the public, employees teleworking from a location of their own choosing, healthcare settings covered by a separate Cal/OSHA standard, and certain law enforcement and corrections facilities. There is no exemption based on where the organisation is headquartered.
Cal/OSHA was directed to propose a general industry standard by December 2025, with the standards board due to adopt one by the end of 2026. Federal OSHA convened a small business panel in 2023 but had not published a proposed rule as of early 2026.
Definitions
Definitions and key terms
- Workplace violence
- Any act or threat of physical violence, harassment, intimidation or other threatening behaviour at the worksite.
- Violent incident log
- A record of every workplace violence incident with prescribed fields, retained five years in California, with identifying details omitted.
- Insider threat
- Risk from someone with legitimate access, which perimeter controls do not address.
- Actionable process step
- Under the food defense regime, a point where a significant vulnerability exists and mitigation can be applied.
- Escorted access
- A control requiring a visitor or contractor to be accompanied within defined areas, only effective where the escort is available.
- Access review
- Periodic confirmation that each person holding access still requires it, without which access accumulates indefinitely.
- De-escalation
- Technique for reducing the intensity of a confrontation, a specified training element where a violence prevention plan is required.
- Post-incident investigation
- Review following a violent incident, required as a plan element and distinct from a general incident investigation.
FAQ
Frequently asked questions
Does a security assessment satisfy food defense requirements?+
No. The Intentional Adulteration rule at 21 CFR Part 121 requires a specific set of components: a vulnerability assessment identifying actionable process steps with reasoning recorded either way, mitigation strategies, monitoring, corrective action and verification. A general security assessment contains none of those in the required form, though it should feed and reference the food defense plan.
Who does California's SB 553 apply to?+
Nearly all California employers, with narrow exemptions: worksites with fewer than ten employees not open to the public, employees teleworking from a location of their own choosing, healthcare settings under the separate Cal/OSHA standard, and certain law enforcement and corrections facilities. There is no exemption based on headquarters location, so any California site brings the obligation.
What must be in the violent incident log?+
The date, time and location, a description of the incident, its classification, the type of violence, the consequences and actions taken, and who completed the log, with personal identifying information omitted. It is retained five years and employees may view and copy it within fifteen calendar days of a request.
Why start with people rather than premises?+
Because the threats that most often materialise involve someone already inside: aggression at a counter, a contractor with unescorted access, a driver alone in a yard. Perimeter controls do not address any of them. Assessments that begin with the building reliably conclude with cameras and leave the exposed roles unaddressed.
Should incidents without injury be recorded?+
Yes. Where a violence prevention plan is required the log covers every incident regardless of whether injury resulted, and even where it is not required, threats and near misses are the leading data. Recording only injuries produces a log that describes outcomes rather than exposure.
The agents
What the agents do with it
The assessment covers four domains. What fails is the access list nobody reviewed and the aggression exposure nobody assessed.
Holds the assessment across people, premises and product, and links exposed roles to training and to the incident log where one is required.
Brings contractors, drivers and visitors into scope, with access tied to the work and expiring when it completes.
Reviews access lists on a cycle and on role change, since access accumulates through project work and is rarely removed.
Connects site security to the food defense plan where the Intentional Adulteration rule applies, keeping the two distinct but linked.
This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.
Meet KnowSafe→Sources
Sources
- California Labor Code section 6401.9 and Cal/OSHA workplace violence guidance
- 21 CFR Part 121, mitigation strategies to protect food against intentional adulteration, FDA
- ISO 45001:2018 clauses 6.1.2 and 8.1.4
- ISO/IEC 27001 Annex A.7, physical and environmental security
- OSHA guidelines for preventing workplace violence