ACCREDITATIONS
Clients
RESULTS-ORITNTED Training Description
Course Duration
1 Day
Training Delivery Method
Classroom (Instructor-Led) or Online (Instructor-Led)
Instructors Languages
English / Arabic / Urdu / Hindi / Pashto
Certification Provider
Tamkene Saudi Training Center - Approved by TVTC (Technical and Vocational Training Corporation)
Certificate Validity
2 Years (Extendable with additional training hours)
Course Average Passing Rate
97%
Competency Assessment Criteria
Practical Assessment and Knowledge Assessment
Post Training Reporting
Post Training Report + Candidate(s) Training Evaluation Forms
Training Design Methodology
ADDIE Training Design Methodology
Certificate of Successful Completion
Certification is provided upon successful completion. The certificate can be verified through a QR-Code system.
Course Overview
Security threats in today's professional environment are no longer confined to a single domain. Physical breaches, social engineering, unauthorized access, cyber intrusions, and insider threats operate in an increasingly interconnected landscape — where a tailgating incident at a building entrance can be the first step in a data breach, and a phishing email can result in physical asset compromise. Organizations that address physical and cybersecurity in isolation leave the gaps between them exposed.
This training course develops a unified security skills competency covering both physical security operations and cybersecurity awareness within a single integrated program. The course is aligned with ASIS PSC.1: Management System for Quality of Private Security Company Operations for physical security standards and ISO/IEC 27001:2022: Information Security Management Systems — specifically Annex A.6.3 on information security awareness, education, and training, and Annex A physical and environmental security controls — for cybersecurity and information security requirements. Participants develop competency across access control, patrol and threat detection, visitor management, social engineering recognition, phishing defense, data handling, and security incident reporting — reinforced through practical scenario exercises and case studies grounded in Middle East operational security environments. The course applies Hazard Identification, Risk Assessment, and Risk Control (HIRARC) methodology to security threat assessment throughout.
Key Learning Objectives
Understand the integrated relationship between physical security and cybersecurity in organizational risk management
Apply physical security principles including access control, perimeter protection, and patrol procedures in accordance with ASIS PSC.1
Conduct visitor management, identity verification, and controlled access operations professionally and consistently
Identify and respond to physical security threats including unauthorized access, tailgating, suspicious behavior, and workplace violence indicators
Apply cybersecurity awareness principles in accordance with ISO/IEC 27001:2022 Annex A.6.3 including phishing recognition, password security, and data classification
Recognize and respond to social engineering attacks including pretexting, impersonation, and manipulation tactics
Report security incidents correctly and maintain security documentation in accordance with organizational and regulatory requirements
Apply HIRARC to security threat assessment and integrate security responsibilities within the organizational HSE and quality management framework
Course Outline
1. Introduction to Integrated Security
The converged security threat landscape including (physical breaches, cyber intrusions, insider threats, and social engineering — and how they interconnect)
Applicable standards including (ASIS PSC.1: Management System for Quality of Private Security Company Operations and ISO/IEC 27001:2022 Annex A.6.3 and physical security controls)
Security roles and responsibilities including (dedicated security personnel, all-staff security awareness obligations, and management accountability under ISO/IEC 27001:2022)
The cost of security failures including (data breach consequences, reputational damage, regulatory penalties, and physical asset loss in Middle East organizational contexts)
Overview of the HIRARC methodology applied to security threat assessment throughout the course
2. Physical Security — Access Control and Perimeter Protection
Physical security perimeter principles in accordance with ASIS PSC.1 and ISO/IEC 27001:2022 Annex A including (layered perimeter design, controlled entry points, and security zone classification)
Access control systems and their operation including (card readers, biometric systems, PIN-code entry, and manual key management procedures)
Tailgating and piggybacking prevention including (recognition techniques, challenge procedures, and physical barrier enforcement at entry points)
Visitor management procedures including (identity verification, visitor registration, escort requirements, and temporary access badge issuance and retrieval)
Secure area management including (clear desk and clear screen policies, restricted zone enforcement, and document and asset handling in sensitive areas)
CCTV and surveillance system awareness including (operator responsibilities, footage retention obligations, and privacy considerations in Middle East regulatory contexts)
3. Threat Detection, Patrol, and Incident Response
Security patrol techniques and patrol planning including (fixed and mobile patrol patterns, patrol documentation, and checkpoint reporting procedures)
Threat recognition and suspicious behavior identification including (behavioral indicators of unauthorized access, theft, workplace violence precursors, and suspicious package identification)
Applying HIRARC to physical security threat assessment including (identifying credible threat scenarios, rating likelihood and consequence, and selecting proportionate response controls)
De-escalation techniques for security personnel including (managing aggressive or non-compliant individuals, verbal communication control, and when to escalate to law enforcement)
Emergency response procedures including (lockdown activation, evacuation support, bomb threat response, and coordination with civil defense and law enforcement authorities)
Security incident documentation including (incident report writing, evidence preservation, chain of custody, and regulatory notification requirements)
4. Cybersecurity Awareness and Information Security
Information security principles under ISO/IEC 27001:2022 including (Confidentiality, Integrity, and Availability — the CIA triad — and their practical meaning for all personnel)
Data classification and handling including (classification levels — public, internal, confidential, and restricted — and correct handling, storage, and disposal procedures for each)
Password security and access management including (strong password construction, multi-factor authentication, prohibition on password sharing, and correct response to suspected account compromise)
Phishing and email-based attacks including (identifying phishing indicators — suspicious sender, urgency, link mismatches — and correct response — do not click, report to IT security)
Safe internet and device use including (acceptable use policy compliance, public Wi-Fi risks, removable media restrictions, and screen lock requirements for unattended devices)
Data breach and cybersecurity incident reporting in accordance with ISO/IEC 27001:2022 Annex A.6.3 including (what to report, to whom, and within what timeframe)
5. Social Engineering Recognition and Defense
Social engineering attack types and their mechanics including (phishing, vishing — voice phishing, smishing — SMS phishing, pretexting, impersonation, and baiting)
Psychological manipulation tactics used in social engineering including (urgency creation, authority impersonation, reciprocity exploitation, and fear-based pressure)
Recognizing social engineering in physical environments including (impersonation of maintenance workers, delivery personnel, or authority figures to gain unauthorized site access)
Defense behaviors against social engineering including (verify before acting, confirm identity through official channels, never disclose credentials or sensitive information under pressure, and report all suspected attempts)
Insider threat awareness including (recognizing behavioral indicators of malicious insider activity, the role of access control in limiting insider threat impact, and reporting obligations)
6. HSE, Quality, and Security Management Integration
Integration of security within the organizational Health, Safety, and Environment (HSE) management system including (security threats in the risk register, security incident reporting within HSE frameworks, and security-HSE interface during emergency response)
Quality management in security operations in accordance with ISO/IEC 27001:2022 including (security policy documentation, training records, incident log maintenance, and access control audit trails)
Security KPIs and performance monitoring including (incident frequency, access control compliance rate, phishing simulation results, and patrol completion rates)
Continuous improvement in security programs including (Plan-Do-Check-Act — PDCA applied to security threat assessment updates, policy revision, and lessons learned integration from incidents)
Regulatory and legal compliance in Middle East security environments including (local law enforcement coordination obligations, data protection regulatory requirements, and civil defense notification procedures)
7. Case Studies and Group Discussions
Case studies from physical and cybersecurity incidents in Middle East organizational environments including (tailgating-enabled data center breaches, phishing attacks that compromised financial systems, social engineering impersonation incidents at corporate facilities, and insider threat events in high-security environments) and the importance of proper integrated security training in protecting organizational assets, data, and personnel
Group discussion on security challenges in regional professional contexts including (managing access control in large multi-tenant facilities, security culture development in high-turnover workforces, and balancing hospitality norms with visitor security protocols in the Middle East)
Security scenario exercise including (participants assess a presented combined physical and cyber threat scenario, apply HIRARC to identify risks, and develop an integrated security response plan for peer and facilitator review)
1. Introduction to Integrated Security
The converged security threat landscape including (physical breaches, cyber intrusions, insider threats, and social engineering — and how they interconnect)
Applicable standards including (ASIS PSC.1: Management System for Quality of Private Security Company Operations and ISO/IEC 27001:2022 Annex A.6.3 and physical security controls)
Security roles and responsibilities including (dedicated security personnel, all-staff security awareness obligations, and management accountability under ISO/IEC 27001:2022)
The cost of security failures including (data breach consequences, reputational damage, regulatory penalties, and physical asset loss in Middle East organizational contexts)
Overview of the HIRARC methodology applied to security threat assessment throughout the course
2. Physical Security — Access Control and Perimeter Protection
Physical security perimeter principles in accordance with ASIS PSC.1 and ISO/IEC 27001:2022 Annex A including (layered perimeter design, controlled entry points, and security zone classification)
Access control systems and their operation including (card readers, biometric systems, PIN-code entry, and manual key management procedures)
Tailgating and piggybacking prevention including (recognition techniques, challenge procedures, and physical barrier enforcement at entry points)
Visitor management procedures including (identity verification, visitor registration, escort requirements, and temporary access badge issuance and retrieval)
Secure area management including (clear desk and clear screen policies, restricted zone enforcement, and document and asset handling in sensitive areas)
CCTV and surveillance system awareness including (operator responsibilities, footage retention obligations, and privacy considerations in Middle East regulatory contexts)
3. Threat Detection, Patrol, and Incident Response
Security patrol techniques and patrol planning including (fixed and mobile patrol patterns, patrol documentation, and checkpoint reporting procedures)
Threat recognition and suspicious behavior identification including (behavioral indicators of unauthorized access, theft, workplace violence precursors, and suspicious package identification)
Applying HIRARC to physical security threat assessment including (identifying credible threat scenarios, rating likelihood and consequence, and selecting proportionate response controls)
De-escalation techniques for security personnel including (managing aggressive or non-compliant individuals, verbal communication control, and when to escalate to law enforcement)
Emergency response procedures including (lockdown activation, evacuation support, bomb threat response, and coordination with civil defense and law enforcement authorities)
Security incident documentation including (incident report writing, evidence preservation, chain of custody, and regulatory notification requirements)
4. Cybersecurity Awareness and Information Security
Information security principles under ISO/IEC 27001:2022 including (Confidentiality, Integrity, and Availability — the CIA triad — and their practical meaning for all personnel)
Data classification and handling including (classification levels — public, internal, confidential, and restricted — and correct handling, storage, and disposal procedures for each)
Password security and access management including (strong password construction, multi-factor authentication, prohibition on password sharing, and correct response to suspected account compromise)
Phishing and email-based attacks including (identifying phishing indicators — suspicious sender, urgency, link mismatches — and correct response — do not click, report to IT security)
Safe internet and device use including (acceptable use policy compliance, public Wi-Fi risks, removable media restrictions, and screen lock requirements for unattended devices)
Data breach and cybersecurity incident reporting in accordance with ISO/IEC 27001:2022 Annex A.6.3 including (what to report, to whom, and within what timeframe)
5. Social Engineering Recognition and Defense
Social engineering attack types and their mechanics including (phishing, vishing — voice phishing, smishing — SMS phishing, pretexting, impersonation, and baiting)
Psychological manipulation tactics used in social engineering including (urgency creation, authority impersonation, reciprocity exploitation, and fear-based pressure)
Recognizing social engineering in physical environments including (impersonation of maintenance workers, delivery personnel, or authority figures to gain unauthorized site access)
Defense behaviors against social engineering including (verify before acting, confirm identity through official channels, never disclose credentials or sensitive information under pressure, and report all suspected attempts)
Insider threat awareness including (recognizing behavioral indicators of malicious insider activity, the role of access control in limiting insider threat impact, and reporting obligations)
6. HSE, Quality, and Security Management Integration
Integration of security within the organizational Health, Safety, and Environment (HSE) management system including (security threats in the risk register, security incident reporting within HSE frameworks, and security-HSE interface during emergency response)
Quality management in security operations in accordance with ISO/IEC 27001:2022 including (security policy documentation, training records, incident log maintenance, and access control audit trails)
Security KPIs and performance monitoring including (incident frequency, access control compliance rate, phishing simulation results, and patrol completion rates)
Continuous improvement in security programs including (Plan-Do-Check-Act — PDCA applied to security threat assessment updates, policy revision, and lessons learned integration from incidents)
Regulatory and legal compliance in Middle East security environments including (local law enforcement coordination obligations, data protection regulatory requirements, and civil defense notification procedures)
7. Case Studies and Group Discussions
Case studies from physical and cybersecurity incidents in Middle East organizational environments including (tailgating-enabled data center breaches, phishing attacks that compromised financial systems, social engineering impersonation incidents at corporate facilities, and insider threat events in high-security environments) and the importance of proper integrated security training in protecting organizational assets, data, and personnel
Group discussion on security challenges in regional professional contexts including (managing access control in large multi-tenant facilities, security culture development in high-turnover workforces, and balancing hospitality norms with visitor security protocols in the Middle East)
Security scenario exercise including (participants assess a presented combined physical and cyber threat scenario, apply HIRARC to identify risks, and develop an integrated security response plan for peer and facilitator review)
Group Exercises
Integrated security threat simulation including (teams respond to a combined physical intrusion and concurrent phishing attack scenario — assigning roles, applying HIRARC, and presenting a coordinated response plan)
Security culture workshop including (groups identify security awareness gaps in a presented organizational profile and develop a targeted security improvement plan covering training, policy, and behavioral controls)
Gained Core Technical Skills
Ability to apply physical security perimeter principles in accordance with ASIS PSC.1 including layered access control, zone classification, and entry point management
Proficiency in visitor management, identity verification, access badge procedures, and tailgating prevention at controlled entry points
Competency in security patrol planning, suspicious behavior recognition, threat detection, and de-escalation in physical security environments
Skill in applying HIRARC to physical and cyber security threat assessment including risk rating and proportionate control selection
Ability to apply ISO/IEC 27001:2022 information security principles including the CIA triad, data classification, password security, and acceptable use compliance
Proficiency in identifying phishing, vishing, smishing, and social engineering attacks — and applying correct defense and reporting behaviors
Competency in recognizing insider threat behavioral indicators and applying access control measures that limit insider threat impact
Skill in documenting and reporting physical and cyber security incidents including evidence preservation, incident report writing, and regulatory notification procedures
Ability to integrate security requirements within the organizational HSE and quality management framework including security KPI monitoring and PDCA-driven continuous improvement
Services Geographical Coverage
In Tamkene Training Center or at our client's facility (On-Site), Covering All Saudi Arabia Cities and Locations:
Targeted Audience
Security officers and guards responsible for physical site protection, access control, and patrol operations
Facility managers and operations personnel responsible for site security standards and visitor management
IT and information security personnel responsible for cybersecurity awareness program delivery
HSE officers integrating security requirements within the organizational HSE management framework
All-staff personnel required to complete mandatory security awareness training under ISO/IEC 27001:2022 compliance obligations
Any professional whose role involves protecting organizational assets, data, or personnel from physical or cyber threats
Practical Assessment
Physical security scenario exercise including (managing a presented access control breach — identifying the threat, applying HIRARC, and completing an incident report)
Phishing and social engineering identification exercise including (reviewing presented email and telephone scenarios and correctly identifying attack type, indicators, and response action)
Integrated security risk assessment under supervision including (applying HIRARC to a presented facility scenario covering both physical and cyber threat vectors and producing a prioritized security control plan)
Knowledge Assessment
Multiple-choice questions on physical security including (ASIS PSC.1 perimeter principles, access control procedures, tailgating prevention, and visitor management requirements)
Cybersecurity awareness questions applying ISO/IEC 27001:2022 including (CIA triad definitions, data classification levels, phishing indicator identification, and breach reporting obligations)
Social engineering recognition questions including (attack type identification, manipulation tactic recognition, and correct defense behavior selection)
HSE and incident response questions including (security incident documentation steps, HIRARC threat rating application, and PDCA security improvement cycle sequencing)
Why Choose This Course
Aligned with ASIS PSC.1 for physical security and ISO/IEC 27001:2022 Annex A.6.3 for cybersecurity awareness — covering both domains in a single regulatory-compliant program
Uniquely integrates physical and cyber security into a unified competency — addressing the gap between siloed security programs that leave organizations vulnerable at the intersection of both domains
Covers the full security skills spectrum from access control and patrol through to phishing defense, social engineering recognition, and incident reporting
Applies HIRARC to security threat assessment — developing personnel who proactively identify and control security risks before incidents occur
Grounded in Middle East security contexts including high-density corporate facilities, petrochemical site security requirements, and regional regulatory authority coordination
Supports ISO/IEC 27001:2022 Annex A.6.3 mandatory staff security awareness training obligations with documented assessment and completion evidence
Note: This course outline, including specific topics, modules, and duration, can be customized based on the specific needs and requirements of the client.
Recommended Courses
Suggested Questions

.webp)
The training I received from Tamkene was truly exceptional.
Dalal AlSaeed

.webp)
Choosing Tamkene for our professional development was a game-changer.
Wafi AlZayer

.webp)
Tamkene delivered quality training with a strong focus on standards. The organization and delivery exceeded our expectations.
Saad AlMisehal
Testimonial




































.webp)
.webp)



.webp)

.webp)

