top of page
All Posts


SBA Mentor-Protégé: Teaming Without Losing Your VOSB Status
The SBA's All Small Mentor-Protégé Program is one of the best growth tools available to a veteran-owned small business: development assistance, past performance borrowing, and the ability to pursue set-aside contracts through joint ventures with an established partner. It also has rules with teeth, because every benefit the program offers could otherwise be used by a large business to wear a small business as a costume. If you're an SBA-certified Veteran-Owned Small Business
kate frese
4 days ago2 min read


PACS Log Retention: What to Keep, How Long, and Why It Matters
Facilities usually have a defensible answer to "how long do you keep video." Ask the same question about PACS logs and the answer is often a shrug: the logs live wherever the server's default settings put them. That is a problem, because access control event data is frequently the deciding evidence in an insider investigation, a loss investigation, or an assessment, and its retention deserves the same deliberate policy as surveillance. Blue Violet Security, LLC (BVS) designs
kate frese
4 days ago2 min read


Visitor Badging and Vetting: Where Visitor Management Meets HSPD-12
HSPD-12 gave the federal government a common credential: the PIV card. It standardized identity proofing, issuance, and use for employees and contractors. Visitors, though, still arrive through a patchwork of sign-in sheets, printed stickers, and local judgment. That patchwork is becoming the next compliance surface, because the same PACS infrastructure that reads PIV cards can, and increasingly must, account for everyone else inside the perimeter. The Integration Point A mod
kate frese
4 days ago2 min read


After-Action Reviews: Feeding Security Incidents Back into Your RMF Package
A door held open, a credential misused, a camera outage during an alarm event: every security incident is a live test of the assumptions in your risk assessment. Most organizations close the incident and file it. The mature ones run a structured after-action review (AAR) and feed the results directly back into their Risk Management Framework (RMF) artifacts. Blue Violet Security, LLC (BVS) helps facilities turn incident response into continuous improvement, so the authorizati
kate frese
4 days ago2 min read


Securing CUI Workspaces: Display and Storage Controls Auditors Actually Check
CUI protection failures rarely involve exotic attacks. They involve documents face-up on a desk, a printer in an open corridor, and a locking container whose key lives in the nearest unlocked drawer. The rules that prevent this are among the oldest in NIST SP 800-53: PE-4 governs the display of information where unauthorized observers could view it, and PE-5 governs physical access to output devices and the control of storage media. Auditors do not need forensics to assess th
kate frese
4 days ago2 min read


Shift-Change Handoffs: Access Control at the Seams
Security programs are usually judged by how they perform at steady state. Incidents, though, cluster at the seams: the moments when one crew goes home and another takes over. Shift change is the single most reliable gap in facility security, because for a short window, accountability is in transit between people who are both half-attending. Why Handoffs Fail At handoff, the outgoing officer is thinking about the drive home. The incoming officer is still booting up mentally. K
kate frese
4 days ago2 min read


FICAM Alignment: What the Federal Identity Roadmap Means for Your PACS
Federal Identity, Credential, and Access Management (FICAM) is usually discussed as an IT topic, which is exactly why physical access programs get surprised by it. FICAM is the government's enterprise approach to how identities are established, credentials are issued, and access is granted, and it does not stop at the network boundary. It stops at your front door, where HSPD-12 credentials meet FIPS 201-2 compliant readers. Blue Violet Security, LLC (BVS) aligns PACS deployme
kate frese
4 days ago3 min read


Two-Person Integrity: When Dual Custody Applies to Keys and Credentials
Every high-consequence loss shares one feature: a single person, acting alone, had enough access to cause it. Two-person integrity (TPI), sometimes called dual custody, is the discipline designed to break that pattern. In federal physical security, it shows up in classified key control, weapons storage, and nuclear materials programs, but the underlying principle applies equally to master keys, PACS administrative credentials, and credential stock. Blue Violet Security, LLC (
kate frese
4 days ago2 min read


Escort Duty Is a Control, Not a Chore: NIST 800-53 PE-3 in Practice
Ask most facility staff what escort duty means and you'll hear "walk them to the conference room." Ask an assessor and you'll hear something different: an access control safeguard under NIST SP 800-53 PE-3 that either has evidence or doesn't. The gap between those two answers is where findings come from. Escorting Is Physical Access Control When a visitor without a standing credential crosses a controlled boundary, the escort temporarily assumes the authorization the visitor
kate frese
4 days ago2 min read


Visit Requests and Escorted Access: Controlling Temporary Access at Federal Facilities
Most federal facilities do a disciplined job controlling who holds a badge. Where discipline breaks down is temporary access: contractors on a punch list, vendor technicians, escorting officials, and visiting personnel who need to be inside the fence today and gone tomorrow. Every one of those individuals touches your perimeter without holding a standing credential, which makes visit and escort processes a genuine access control function, not an administrative courtesy. As a
kate frese
4 days ago2 min read
Risk Assessment Methodology for Physical Security Integrators
Structuring Physical Security Risk Assessments Federal physical security integration requires a repeatable, structured risk assessment methodology. Rather than relying on informal site walks, integrators and facility security officers must evaluate physical assets, threat vectors, and technical vulnerabilities systematically. Conducting structured assessments ensures that physical security countermeasures directly address documented operational risks across hardened facilitie
kate frese
Sep 211 min read
Converged Security Operations Centers: The Federal GSOC Playbook
Federal agencies face sophisticated threat vectors that span both physical infrastructure and digital networks. Managing physical security systems (PACS, CCTV, intrusion detection) independently from IT security operations creates dangerous operational silos. Establishing a converged Global Security Operations Center (GSOC) unifies physical security monitoring and cyber threat intelligence into a single pane of glass. Designing a converged GSOC architecture enhances real-time
kate frese
Sep 212 min read
Counterfeit and Cloned Credentials: Catching Fake PIV Cards at the Reader
How Credential Fraud Threatens Federal Access Control Physical credential counterfeiting and cloning pose persistent risks to federal facility perimeter security. Attackers utilize inexpensive handheld radio frequency identification (RFID) copiers to clone physical access badges in seconds. When unauthenticated card data is presented to a door reader, legacy physical access control systems (PACS) grant entry based solely on static card identification numbers. Protecting secur
kate frese
Sep 212 min read
Access Reviews and Recertification: NIST 800-53 AC-2 for Physical Access
Federal cybersecurity audits increasingly focus on the intersection of personnel security and physical access control. NIST SP 800-53 control AC-2 (Account Management) requires federal agencies to manage, review, and recertify access entitlements systematically. While organizations maintain strict AC-2 compliance for logical IT accounts, physical access entitlements stored within Physical Access Control Systems (PACS) are frequently overlooked. Establishing periodic physical
kate frese
Sep 212 min read
CMMC Audit Findings: Common PACS Gaps and How to Fix Them
Addressing Physical Access Control Gaps in CMMC Audits During Cybersecurity Maturity Model Certification (CMMC) assessments, physical access control systems (PACS) often introduce unexpected findings. Assessors evaluate physical security controls under NIST SP 800-171 Requirement 3.10 to ensure physical perimeter integrity. While defense contractors frequently focus on network firewalls and endpoint security, misconfigured physical security infrastructure can delay certificat
kate frese
Sep 211 min read
RMF Step 1: Preparation for Physical Security Systems
Integrating physical security systems into federal IP networks requires authorization under the NIST Risk Management Framework (RMF). Electronic Security Systems (ESS), Physical Access Control Systems (PACS), and IP Closed-Circuit Television (CCTV) networks process sensitive operational data and connect directly to agency backbones. Skipping or rushing RMF Step 1 (Prepare) creates severe delays during later assessment and authorization phases. Thorough preparation aligns your
kate frese
Sep 212 min read
Fail-Secure vs Fail-Safe: Lockdown Decisions Are Compliance Decisions
Distinguishing Fail-Secure from Fail-Safe Hardware Selecting door locking mechanisms for federal facilities involves a fundamental operational choice between fail-secure and fail-safe hardware. Fail-secure locking devices remain locked when electrical power is removed, requiring mechanical keys, battery backups, or physical force to open from the exterior. Fail-safe locking devices unlock automatically when power drops, granting unhindered physical access. Selecting the wrong
kate frese
Sep 212 min read
OSDP vs Wiegand: Why Federal PACS Are Moving to Open Supervised Device Protocol
Legacy physical access control systems (PACS) across federal facilities frequently rely on legacy Wiegand card reader interfaces developed decades ago. While Wiegand served as an industry baseline for years, its inherent technical limitations present severe security risks to modern federal networks. Transitioning your facility to Open Supervised Device Protocol (OSDP) eliminates structural vulnerabilities and aligns your access control architecture with modern federal securit
kate frese
Sep 212 min read
Video Analytics in Federal Security: Compliance Considerations
Capabilities and Limitations of Automated Analytics Deploying video analytics such as object detection, loitering monitoring, and tailgating detection enhances situational awareness across federal facilities. These algorithms excel at processing high-volume visual feeds to flag motion patterns or unauthorized personnel trailing valid cardholders through access points. However, analytics engines are not autonomous security officers. Environmental variables, lighting changes, w
kate frese
Sep 212 min read
UL 2050: The Standard Behind Certified Federal Intrusion Detection
Federal facility protection depends on rigorous physical security controls to safeguard sensitive compartments and classified assets. When your agency deploys an Intrusion Detection System (IDS), meeting high-security operational goals requires adhering to recognized technical benchmarks. Standard UL 2050 defines the operational and physical security baseline for National Industrial Security Program facilities and federal Sensitive Compartmented Information Facilities (SCIFs)
kate frese
Sep 212 min read
bottom of page