Orange County NC Website
<br /> <br />P a g e 31 <br /> <br /> <br />Orange County <br />Facilities Security Assessment <br />RFP#: 367-OC 5403 <br />CTCH Security Business Consulting – www.ctchconsulting.com <br /> <br />implemented, based on security risk levels and priority, would be outlined. In another <br />parallel time line, the team will outline all physical security related recommendations <br />that should be implemented within 1 – 36 months which includes: all critical security <br />vulnerabilities that should be addressed within 1 – 6 months; high priority security <br />vulnerabilities that should be addressed within 7 – 18 months; and moderate security <br />priorities that should be addressed within an 18 – 36-month period. A repeated 3- <br />month review event item would be used within the schedule to monitor security <br />mitigation efforts throughout the 36-month period. Recommendations for <br />improvements will be based on the criticality of assets, vulnerabilities, threats and <br />current risk levels identified during on-site assessments and would be based on <br />quantitative incidents that are Low-Frequency – High Impact or High-Frequency – Low <br />Impact events that could cause major security incidents at each site. Below is an <br />example of the final CPTED Security Master Plan – Mitigation Priority Matrix Excel File <br />that would be provided to track security improvement efforts: <br /> <br /> <br />Interview Data: Within this section, the team will also publish interview data that <br />was provided by OC stakeholders during the project. <br /> <br />ESS Functional Test Data: Within this section the team will publish the ESS <br />components that were tested during the Tier II on-site assessments and how these ESS <br />components performed (Pass, Failed and/or Observed Issues). <br /> <br />Official Out-Brief: The official Out-Brief would be hosted in person at the <br />completion of Tier III of Phase I. The out-brief would be used to officially publish the <br />final Security Risk Levels, SRAMF-CPTED Reports, to publish the CPTED-Security Master <br />Plan, to publish a summary of all findings and to obtain feedback from OC stakeholders. <br />The team will provide ‘read ahead’ (draft documents) of the final reports and the master <br />plan so that OC stakeholders can digest the findings and present questions during the <br />DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB