A 14-step checklist for bringing cyber, physical, personnel and supplier security under one governance structure, one risk register and one incident process.
Most organisations run three security programmes that barely speak: IT owns cyber, facilities owns doors and cameras, HR owns vetting and terminations. Incidents do not respect that structure. A tailgater who reaches a server room is a physical event with a cyber blast radius. An insider threat is a personnel, cyber and physical problem at once. The camera network watching your doors is a fleet of computers on your LAN that nobody patches.
The industry name for fixing this is security convergence: not necessarily merging teams into one org chart, but running one management system over all of it. The failures live in the handoffs between domains, and a framework that stops at a domain boundary cannot see a handoff.
One accountable owner, one risk appetite covering all hazards, one risk register with a shared severity scale, and one incident process, applied across cyber, physical, personnel and supplier security. Each domain keeps its specialists and its controls; what unifies is the governance above them, so a risk can never fall between two half-owners and every incident escalates the same way whatever triggered it.
Tick items as you complete them. Progress is stored in your own browser and never leaves it, so nothing here is submitted to us or to anyone else.
If you have not yet built the management-system basics (sponsorship, risk appetite, policy hierarchy), start with our cybersecurity governance framework checklist and return here: this framework extends that one sideways, across domains, rather than replacing it.
CSO or CISO with a cross-domain mandate
Cyber · Physical · Personnel · Suppliers
ISO 27001 / ACSC ISM / SOCI CIRMP
Name a single executive accountable for cyber, physical and personnel security, and stand up a steering group drawing IT, facilities, HR, operations and procurement. While accountability is split, every cross-domain risk has two half-owners and therefore none.
One set of appetite statements, in measurable terms, spanning data loss, physical intrusion, personnel failure and supplier failure. Separate appetites per domain is how an exposure facilities considers acceptable stays intolerable to IT without anyone noticing the contradiction.
One likelihood and impact scale, one incident severity ladder, used by every domain, so a physical severity 2 means the same thing as a cyber severity 2. Every later step that compares, escalates or reports across domains is arithmetic on these units.
Systems, sites, critical roles and suppliers in one inventory with the relationships between them, because a server room is simultaneously a site, an asset and an access-control scope. Domain inventories that cannot reference each other are how the camera VLAN ends up in nobody's patch cycle.
Migrate the domain registers into one, restated in the shared taxonomy from Phase 0. Keep per-domain views as filters on the one register, never as separate documents that can drift apart again.
Pick one spine (ISO 27001 Annex A or the ISM, both of which already span physical and personnel controls) and map every existing control to it, then cross-walk to whatever else regulators ask for. One control set with many mappings beats one control set per framework.
Walk the scenarios that cross domains: who revokes building access when IT disables an account, who owns a stolen-laptop event end to end, who is paged when the CCTV network is scanned from inside the LAN. The dangerous gaps are in the handoffs, not inside any single domain.
Make the joiner-mover-leaver process drive badges and credentials together, so one leaver event revokes the building pass and the accounts in the same hour. The gap between HR termination and badge deactivation is a standing invitation.
One intake, the shared severity ladder, one escalation path, whether the trigger is a phishing email, a forced door or an insider tip-off. Write joint playbooks for the scenarios that cross, because those are the ones where two teams each assume the other has it.
Bring building management, access control, cameras and any industrial control into the same register and monitoring. The devices that guard your doors are computers on your network, and they are usually the oldest ones on it.
Assess critical suppliers across cyber, physical and personnel dimensions in one assessment. A cleaning contractor with after-hours site access is a supply-chain risk in exactly the way a SaaS vendor is, and only an integrated view prices them on the same scale.
Run scenarios that force the domains to work together: a break-in that becomes data theft, an insider event, a cyber incident during a physical evacuation. A single-domain exercise validates exactly the silo this framework exists to dismantle.
One report on the shared scale, covering all domains, replacing the three competing narratives the board used to arbitrate between. This is the deliverable that makes the whole programme visible, and defensible, above the security function.
Map the framework to the SOCI risk management program rules if you are critical infrastructure, CPS 230 if you are APRA-regulated, and the ISM if you supply government. Review annually so the framework tracks the estate rather than the version of it that existed at launch.
This framework extends sideways what the governance checklist builds upward, and the anchors below carry the detail.