top of page

Course Title

Security Skills

Security Skills training aligned with ASIS PSC.1 and ISO/IEC 27001:2022, covering physical security, access control, cybersecurity awareness, threat response, and incident reporting.

Security Skills Training Service in Saudi Arabia

ACCREDITATIONS

Clients

750+

Satisfied Clients

Our Clients

2025

Training Ratings Report

4.89 ★★★★★

Based on 2400+ Reviews

View Ratings Report

4.8 ★★★★★

Based on 1000+ Reviews

Check Reviews

SUCCESS PROOF IN NUMBERS

RESULTS-ORITNTED Training Description

Course Duration

1 Day

Training Delivery Method

Classroom (Instructor-Led) or Online (Instructor-Led)

Instructors Languages

English / Arabic / Urdu / Hindi / Pashto

Certification Provider

Tamkene Saudi Training Center - Approved by TVTC (Technical and Vocational Training Corporation)

Certificate Validity

2 Years (Extendable with additional training hours)

Course Average Passing Rate

97%

Competency Assessment Criteria

Practical Assessment and Knowledge Assessment

Post Training Reporting

Post Training Report + Candidate(s) Training Evaluation Forms

Training Design Methodology

ADDIE Training Design Methodology

Certificate of Successful Completion

Certification is provided upon successful completion. The certificate can be verified through a QR-Code system.

Course Overview

Security threats in today's professional environment are no longer confined to a single domain. Physical breaches, social engineering, unauthorized access, cyber intrusions, and insider threats operate in an increasingly interconnected landscape — where a tailgating incident at a building entrance can be the first step in a data breach, and a phishing email can result in physical asset compromise. Organizations that address physical and cybersecurity in isolation leave the gaps between them exposed.


This training course develops a unified security skills competency covering both physical security operations and cybersecurity awareness within a single integrated program. The course is aligned with ASIS PSC.1: Management System for Quality of Private Security Company Operations for physical security standards and ISO/IEC 27001:2022: Information Security Management Systems — specifically Annex A.6.3 on information security awareness, education, and training, and Annex A physical and environmental security controls — for cybersecurity and information security requirements. Participants develop competency across access control, patrol and threat detection, visitor management, social engineering recognition, phishing defense, data handling, and security incident reporting — reinforced through practical scenario exercises and case studies grounded in Middle East operational security environments. The course applies Hazard Identification, Risk Assessment, and Risk Control (HIRARC) methodology to security threat assessment throughout.

Key Learning Objectives

  • Understand the integrated relationship between physical security and cybersecurity in organizational risk management

  • Apply physical security principles including access control, perimeter protection, and patrol procedures in accordance with ASIS PSC.1

  • Conduct visitor management, identity verification, and controlled access operations professionally and consistently

  • Identify and respond to physical security threats including unauthorized access, tailgating, suspicious behavior, and workplace violence indicators

  • Apply cybersecurity awareness principles in accordance with ISO/IEC 27001:2022 Annex A.6.3 including phishing recognition, password security, and data classification

  • Recognize and respond to social engineering attacks including pretexting, impersonation, and manipulation tactics

  • Report security incidents correctly and maintain security documentation in accordance with organizational and regulatory requirements

  • Apply HIRARC to security threat assessment and integrate security responsibilities within the organizational HSE and quality management framework

Course Outline

1. Introduction to Integrated Security

  • The converged security threat landscape including (physical breaches, cyber intrusions, insider threats, and social engineering — and how they interconnect)

  • Applicable standards including (ASIS PSC.1: Management System for Quality of Private Security Company Operations and ISO/IEC 27001:2022 Annex A.6.3 and physical security controls)

  • Security roles and responsibilities including (dedicated security personnel, all-staff security awareness obligations, and management accountability under ISO/IEC 27001:2022)

  • The cost of security failures including (data breach consequences, reputational damage, regulatory penalties, and physical asset loss in Middle East organizational contexts)

  • Overview of the HIRARC methodology applied to security threat assessment throughout the course

2. Physical Security — Access Control and Perimeter Protection

  • Physical security perimeter principles in accordance with ASIS PSC.1 and ISO/IEC 27001:2022 Annex A including (layered perimeter design, controlled entry points, and security zone classification)

  • Access control systems and their operation including (card readers, biometric systems, PIN-code entry, and manual key management procedures)

  • Tailgating and piggybacking prevention including (recognition techniques, challenge procedures, and physical barrier enforcement at entry points)

  • Visitor management procedures including (identity verification, visitor registration, escort requirements, and temporary access badge issuance and retrieval)

  • Secure area management including (clear desk and clear screen policies, restricted zone enforcement, and document and asset handling in sensitive areas)

  • CCTV and surveillance system awareness including (operator responsibilities, footage retention obligations, and privacy considerations in Middle East regulatory contexts)

3. Threat Detection, Patrol, and Incident Response

  • Security patrol techniques and patrol planning including (fixed and mobile patrol patterns, patrol documentation, and checkpoint reporting procedures)

  • Threat recognition and suspicious behavior identification including (behavioral indicators of unauthorized access, theft, workplace violence precursors, and suspicious package identification)

  • Applying HIRARC to physical security threat assessment including (identifying credible threat scenarios, rating likelihood and consequence, and selecting proportionate response controls)

  • De-escalation techniques for security personnel including (managing aggressive or non-compliant individuals, verbal communication control, and when to escalate to law enforcement)

  • Emergency response procedures including (lockdown activation, evacuation support, bomb threat response, and coordination with civil defense and law enforcement authorities)

  • Security incident documentation including (incident report writing, evidence preservation, chain of custody, and regulatory notification requirements)

4. Cybersecurity Awareness and Information Security

  • Information security principles under ISO/IEC 27001:2022 including (Confidentiality, Integrity, and Availability — the CIA triad — and their practical meaning for all personnel)

  • Data classification and handling including (classification levels — public, internal, confidential, and restricted — and correct handling, storage, and disposal procedures for each)

  • Password security and access management including (strong password construction, multi-factor authentication, prohibition on password sharing, and correct response to suspected account compromise)

  • Phishing and email-based attacks including (identifying phishing indicators — suspicious sender, urgency, link mismatches — and correct response — do not click, report to IT security)

  • Safe internet and device use including (acceptable use policy compliance, public Wi-Fi risks, removable media restrictions, and screen lock requirements for unattended devices)

  • Data breach and cybersecurity incident reporting in accordance with ISO/IEC 27001:2022 Annex A.6.3 including (what to report, to whom, and within what timeframe)

5. Social Engineering Recognition and Defense

  • Social engineering attack types and their mechanics including (phishing, vishing — voice phishing, smishing — SMS phishing, pretexting, impersonation, and baiting)

  • Psychological manipulation tactics used in social engineering including (urgency creation, authority impersonation, reciprocity exploitation, and fear-based pressure)

  • Recognizing social engineering in physical environments including (impersonation of maintenance workers, delivery personnel, or authority figures to gain unauthorized site access)

  • Defense behaviors against social engineering including (verify before acting, confirm identity through official channels, never disclose credentials or sensitive information under pressure, and report all suspected attempts)

  • Insider threat awareness including (recognizing behavioral indicators of malicious insider activity, the role of access control in limiting insider threat impact, and reporting obligations)

6. HSE, Quality, and Security Management Integration

  • Integration of security within the organizational Health, Safety, and Environment (HSE) management system including (security threats in the risk register, security incident reporting within HSE frameworks, and security-HSE interface during emergency response)

  • Quality management in security operations in accordance with ISO/IEC 27001:2022 including (security policy documentation, training records, incident log maintenance, and access control audit trails)

  • Security KPIs and performance monitoring including (incident frequency, access control compliance rate, phishing simulation results, and patrol completion rates)

  • Continuous improvement in security programs including (Plan-Do-Check-Act — PDCA applied to security threat assessment updates, policy revision, and lessons learned integration from incidents)

  • Regulatory and legal compliance in Middle East security environments including (local law enforcement coordination obligations, data protection regulatory requirements, and civil defense notification procedures)

7. Case Studies and Group Discussions

  • Case studies from physical and cybersecurity incidents in Middle East organizational environments including (tailgating-enabled data center breaches, phishing attacks that compromised financial systems, social engineering impersonation incidents at corporate facilities, and insider threat events in high-security environments) and the importance of proper integrated security training in protecting organizational assets, data, and personnel

  • Group discussion on security challenges in regional professional contexts including (managing access control in large multi-tenant facilities, security culture development in high-turnover workforces, and balancing hospitality norms with visitor security protocols in the Middle East)

  • Security scenario exercise including (participants assess a presented combined physical and cyber threat scenario, apply HIRARC to identify risks, and develop an integrated security response plan for peer and facilitator review)

1. Introduction to Integrated Security

  • The converged security threat landscape including (physical breaches, cyber intrusions, insider threats, and social engineering — and how they interconnect)

  • Applicable standards including (ASIS PSC.1: Management System for Quality of Private Security Company Operations and ISO/IEC 27001:2022 Annex A.6.3 and physical security controls)

  • Security roles and responsibilities including (dedicated security personnel, all-staff security awareness obligations, and management accountability under ISO/IEC 27001:2022)

  • The cost of security failures including (data breach consequences, reputational damage, regulatory penalties, and physical asset loss in Middle East organizational contexts)

  • Overview of the HIRARC methodology applied to security threat assessment throughout the course

2. Physical Security — Access Control and Perimeter Protection

  • Physical security perimeter principles in accordance with ASIS PSC.1 and ISO/IEC 27001:2022 Annex A including (layered perimeter design, controlled entry points, and security zone classification)

  • Access control systems and their operation including (card readers, biometric systems, PIN-code entry, and manual key management procedures)

  • Tailgating and piggybacking prevention including (recognition techniques, challenge procedures, and physical barrier enforcement at entry points)

  • Visitor management procedures including (identity verification, visitor registration, escort requirements, and temporary access badge issuance and retrieval)

  • Secure area management including (clear desk and clear screen policies, restricted zone enforcement, and document and asset handling in sensitive areas)

  • CCTV and surveillance system awareness including (operator responsibilities, footage retention obligations, and privacy considerations in Middle East regulatory contexts)

3. Threat Detection, Patrol, and Incident Response

  • Security patrol techniques and patrol planning including (fixed and mobile patrol patterns, patrol documentation, and checkpoint reporting procedures)

  • Threat recognition and suspicious behavior identification including (behavioral indicators of unauthorized access, theft, workplace violence precursors, and suspicious package identification)

  • Applying HIRARC to physical security threat assessment including (identifying credible threat scenarios, rating likelihood and consequence, and selecting proportionate response controls)

  • De-escalation techniques for security personnel including (managing aggressive or non-compliant individuals, verbal communication control, and when to escalate to law enforcement)

  • Emergency response procedures including (lockdown activation, evacuation support, bomb threat response, and coordination with civil defense and law enforcement authorities)

  • Security incident documentation including (incident report writing, evidence preservation, chain of custody, and regulatory notification requirements)

4. Cybersecurity Awareness and Information Security

  • Information security principles under ISO/IEC 27001:2022 including (Confidentiality, Integrity, and Availability — the CIA triad — and their practical meaning for all personnel)

  • Data classification and handling including (classification levels — public, internal, confidential, and restricted — and correct handling, storage, and disposal procedures for each)

  • Password security and access management including (strong password construction, multi-factor authentication, prohibition on password sharing, and correct response to suspected account compromise)

  • Phishing and email-based attacks including (identifying phishing indicators — suspicious sender, urgency, link mismatches — and correct response — do not click, report to IT security)

  • Safe internet and device use including (acceptable use policy compliance, public Wi-Fi risks, removable media restrictions, and screen lock requirements for unattended devices)

  • Data breach and cybersecurity incident reporting in accordance with ISO/IEC 27001:2022 Annex A.6.3 including (what to report, to whom, and within what timeframe)

5. Social Engineering Recognition and Defense

  • Social engineering attack types and their mechanics including (phishing, vishing — voice phishing, smishing — SMS phishing, pretexting, impersonation, and baiting)

  • Psychological manipulation tactics used in social engineering including (urgency creation, authority impersonation, reciprocity exploitation, and fear-based pressure)

  • Recognizing social engineering in physical environments including (impersonation of maintenance workers, delivery personnel, or authority figures to gain unauthorized site access)

  • Defense behaviors against social engineering including (verify before acting, confirm identity through official channels, never disclose credentials or sensitive information under pressure, and report all suspected attempts)

  • Insider threat awareness including (recognizing behavioral indicators of malicious insider activity, the role of access control in limiting insider threat impact, and reporting obligations)

6. HSE, Quality, and Security Management Integration

  • Integration of security within the organizational Health, Safety, and Environment (HSE) management system including (security threats in the risk register, security incident reporting within HSE frameworks, and security-HSE interface during emergency response)

  • Quality management in security operations in accordance with ISO/IEC 27001:2022 including (security policy documentation, training records, incident log maintenance, and access control audit trails)

  • Security KPIs and performance monitoring including (incident frequency, access control compliance rate, phishing simulation results, and patrol completion rates)

  • Continuous improvement in security programs including (Plan-Do-Check-Act — PDCA applied to security threat assessment updates, policy revision, and lessons learned integration from incidents)

  • Regulatory and legal compliance in Middle East security environments including (local law enforcement coordination obligations, data protection regulatory requirements, and civil defense notification procedures)

7. Case Studies and Group Discussions

  • Case studies from physical and cybersecurity incidents in Middle East organizational environments including (tailgating-enabled data center breaches, phishing attacks that compromised financial systems, social engineering impersonation incidents at corporate facilities, and insider threat events in high-security environments) and the importance of proper integrated security training in protecting organizational assets, data, and personnel

  • Group discussion on security challenges in regional professional contexts including (managing access control in large multi-tenant facilities, security culture development in high-turnover workforces, and balancing hospitality norms with visitor security protocols in the Middle East)

  • Security scenario exercise including (participants assess a presented combined physical and cyber threat scenario, apply HIRARC to identify risks, and develop an integrated security response plan for peer and facilitator review)

Group Exercises

  • Integrated security threat simulation including (teams respond to a combined physical intrusion and concurrent phishing attack scenario — assigning roles, applying HIRARC, and presenting a coordinated response plan)

  • Security culture workshop including (groups identify security awareness gaps in a presented organizational profile and develop a targeted security improvement plan covering training, policy, and behavioral controls)

Gained Core Technical Skills

  • Ability to apply physical security perimeter principles in accordance with ASIS PSC.1 including layered access control, zone classification, and entry point management

  • Proficiency in visitor management, identity verification, access badge procedures, and tailgating prevention at controlled entry points

  • Competency in security patrol planning, suspicious behavior recognition, threat detection, and de-escalation in physical security environments

  • Skill in applying HIRARC to physical and cyber security threat assessment including risk rating and proportionate control selection

  • Ability to apply ISO/IEC 27001:2022 information security principles including the CIA triad, data classification, password security, and acceptable use compliance

  • Proficiency in identifying phishing, vishing, smishing, and social engineering attacks — and applying correct defense and reporting behaviors

  • Competency in recognizing insider threat behavioral indicators and applying access control measures that limit insider threat impact

  • Skill in documenting and reporting physical and cyber security incidents including evidence preservation, incident report writing, and regulatory notification procedures

  • Ability to integrate security requirements within the organizational HSE and quality management framework including security KPI monitoring and PDCA-driven continuous improvement

Services Geographical Coverage

In Tamkene Training Center or at our client's facility (On-Site), Covering All Saudi Arabia Cities and Locations:


Targeted Audience

  • Security officers and guards responsible for physical site protection, access control, and patrol operations

  • Facility managers and operations personnel responsible for site security standards and visitor management

  • IT and information security personnel responsible for cybersecurity awareness program delivery

  • HSE officers integrating security requirements within the organizational HSE management framework

  • All-staff personnel required to complete mandatory security awareness training under ISO/IEC 27001:2022 compliance obligations

  • Any professional whose role involves protecting organizational assets, data, or personnel from physical or cyber threats

Practical Assessment

  • Physical security scenario exercise including (managing a presented access control breach — identifying the threat, applying HIRARC, and completing an incident report)

  • Phishing and social engineering identification exercise including (reviewing presented email and telephone scenarios and correctly identifying attack type, indicators, and response action)

  • Integrated security risk assessment under supervision including (applying HIRARC to a presented facility scenario covering both physical and cyber threat vectors and producing a prioritized security control plan)

Knowledge Assessment

  • Multiple-choice questions on physical security including (ASIS PSC.1 perimeter principles, access control procedures, tailgating prevention, and visitor management requirements)

  • Cybersecurity awareness questions applying ISO/IEC 27001:2022 including (CIA triad definitions, data classification levels, phishing indicator identification, and breach reporting obligations)

  • Social engineering recognition questions including (attack type identification, manipulation tactic recognition, and correct defense behavior selection)

  • HSE and incident response questions including (security incident documentation steps, HIRARC threat rating application, and PDCA security improvement cycle sequencing)

Why Choose This Course

  • Aligned with ASIS PSC.1 for physical security and ISO/IEC 27001:2022 Annex A.6.3 for cybersecurity awareness — covering both domains in a single regulatory-compliant program

  • Uniquely integrates physical and cyber security into a unified competency — addressing the gap between siloed security programs that leave organizations vulnerable at the intersection of both domains

  • Covers the full security skills spectrum from access control and patrol through to phishing defense, social engineering recognition, and incident reporting

  • Applies HIRARC to security threat assessment — developing personnel who proactively identify and control security risks before incidents occur

  • Grounded in Middle East security contexts including high-density corporate facilities, petrochemical site security requirements, and regional regulatory authority coordination

  • Supports ISO/IEC 27001:2022 Annex A.6.3 mandatory staff security awareness training obligations with documented assessment and completion evidence

Note: This course outline, including specific topics, modules, and duration, can be customized based on the specific needs and requirements of the client.

IPAF - 1a Static Vertical Personnel Platform Operator Training Course
IPAF - 1a Static Vertical Personnel Platform Operator
Learn More
SASO Approved - Motor Grader Operator Training Course
SASO - Motor Graders Operator
Learn More
SASO & LEEA - Forklift Operator Training Course
SASO & LEEA - Forklift Operator
Learn More
Fire Warden Training Course
Fire Warden
Learn More

Recommended Courses

All Courses
FAQ: Is Tamkene Approved by Aramco? Yes
Is Tamkene approved by Aramco? Yes
Learn More
FAQ: Is Tamkene Approved by TVTC? Yes, Read More
Is Tamkene approved locally by TVTC? Yes
Learn More
FAQ: Training Services | Covering all Saudi Arabia cities
Does Tamkene training services covers all Saudi Arabia cities? Yes we do
Learn More
FAQ: How to verify a certificate or a card from Tamkene?
How to verify a certificate or a card from Tamkene?
Learn More

Suggested Questions

All FAQs
Confined Space Entry & Rescue
Dalal AlSaeed

The training I received from Tamkene was truly exceptional.

Dalal AlSaeed

SASO & LEEA - RIGGER 1
Wafi AlZayer

Choosing Tamkene for our professional development was a game-changer.

Wafi AlZayer

Fire Fighting
Saad AlMisehal

Tamkene delivered quality training with a strong focus on standards. The organization and delivery exceeded our expectations.

Saad AlMisehal

Testimonial

Client Testimonials 

bottom of page