Physical security policy
Published: 10 July 2026Freedom of information class: How we manage our resources
The Physical Security Policy sets out Registers of Scotland's (RoS) commitment to the security and safety of it's colleagues, persons working on behalf of RoS, and third-party organisations accessing RoS premises, as well as it's physical and electronic assets.
Table of contents
1. Purpose and scope
1.1 This policy outlines Registers of Scotland’s (RoS) commitment to safeguarding people, physical assets, and information by maintaining a secure physical environment across all RoS managed premises.
1.2 The policy applies to all employees, contingent workers, tenants, contractors, and other 3rd parties who access RoS buildings or use associated facilities.
1.3 The policy covers the physical protection of:
- building access points and perimeters
- offices, workspaces, secure rooms, and plant areas
- physical records, hardware, and sensitive materials
- security systems such as access control, alarms, and CCTV
- the safety and wellbeing of all building users.
2. Guiding principles
2.1 RoS will adopt a risk-based, proportionate approach to physical security, ensuring controls are appropriate to the threats, vulnerabilities, and operational requirements of each site.
2.2 Physical security controls will align with the wider leadership-driven security culture and the reinforcement of cyber security, information security, resilience, and business continuity frameworks.
2.3 RoS will maintain a safe, secure environment that supports the protection of people, assets, and information in line with legal, regulatory, and organisational obligations.
3. The policy
3.1 Physical security controls will be implemented to prevent unauthorised access, damage, interference, loss, or disclosure relating to RoS premises, people, and assets.
3.2 RoS will design, implement, and maintain physical security measures including, where appropriate:
- controlled entry systems and identification checks
- visitor management processes
- CCTV and alarm systems compliant with data protection
- secure storage for sensitive information and equipment
- segregation of restricted or controlled areas.
3.3 Security measures will aim to deter, delay, detect, and respond to attempted or actual:
- unauthorised access
- acts of vandalism
- theft
- disorder
- violence.
3.4 Decisions on physical security controls will be based on:
- site specific threat and vulnerability assessments
- legal, regulatory, and data protection requirements
- operational needs, including public access requirements
- cost effectiveness and proportionality
- whether the premises are solely or jointly occupied.
3.5 All employees and contingent workers must clearly display their RoS identification passes while on RoS premises. Passes must not be shared or loaned. All passes must be removed or covered immediately after leaving our premises.
3.6 All tenants, contractors and other third parties working in or on behalf of RoS must clearly display their own identification passes whilst on RoS premises.
3.7 Passes should not be photographed, and images of passes must not be shared on any social media platforms.
3.8 Lost, stolen, or damaged passes must be reported immediately to RoS Estates or Security.
3.9 Access to restricted, or controlled areas will be granted only where there is a clear business need and must be regularly reviewed.
3.10 All physical security incidents, suspicious activity, or breaches must be reported promptly in line with RoS incident management procedures.
3.11 RoS will ensure that security measures are reviewed periodically and enhanced when changes in threat, incidents, or operational requirements warrant it.
4. Roles and responsibilities
4.1 RoS Estates:
- owns this policy, ensuring its development, maintenance, and review
- ensures appropriate physical security measures are implemented and monitored and owns the building-level risk registers
- maintains supporting procedures, standards, and documentation
- communicates relevant updates to colleagues, tenants, and contractors.
4.2 Security:
- operate access control systems
- CCTV monitoring
- patrols
- front of house security activities in line with contractual and legal requirements.
4.3 All employees, contingent workers, tenants, contractors and other third parties:
- must comply with this policy and all supporting procedures
- must report security concerns, breaches, or incidents immediately.
4.4 Visitor hosts:
- are responsible for arranging visitor access
- must ensure visitors are booked in via Management Visitor Portal, photo ID must be shown on arrival, briefed where necessary, and escorted at all times while on site.
4.5 Employees with managerial responsibilities:
- must ensure their teams are aware of and comply with this policy.
4.6 Tenants:
- will receive relevant security documentation from RoS Estates
- must adhere to RoS security requirements and communicate changes in their operations that may impact physical security.
5. Approval and review
5.1 This policy will be reviewed annually by RoS Estates and approved by ISAG. Earlier review may take place following significant changes in risk, legislation, organisational structure, or after relevant incidents.
5.2 All updates will be version controlled and communicated to affected stakeholders in a timely manner.
| Author | Estates |
|---|---|
| Reviewed | Estates |
| Cleared | Head of Procurement and Estates |
| Approval | Information Security Assurance Group (ISAG) |
| Approval date | May 2026 |
| Policy version | V 1.6 |
| Review responsibility | Head of Procurement and Estates |
| Review date | April 2027 |
| Suitable for publication | Y |
| Contact | estatesservicedesk@ros.gov.uk |
