Why it exists
Cyber security controls assume the attacker is remote. A great many are not. Someone who walks into the building, sits in the reception area within line of sight of a screen, photographs a document left on a desk, plugs into an unattended port, or leaves a device in a meeting room, defeats the entire perimeter without touching it. There was no framework that treated that surface as a surface — enumerable, scoreable, and reducible over time — so I wrote one.
The domains
PASM enumerates the proximity surface across six domains. Each is assessed separately, because organisations are rarely uniformly weak or uniformly strong across them.
- Physical credential management
- Passes, keys, visitor issuance, tailgating, contractor and cleaner access, and the lifecycle of a credential after someone leaves.
- Hard-copy exposure
- Printed material at rest and in transit: desks, printers, bins, whiteboards, and the documents that leave the building in a bag.
- Edge-device hardening
- Unattended ports, conferencing hardware, smart displays, printers with storage, and anything with a radio in it that nobody owns.
- Line-of-sight spillage
- What is readable through glass, over a shoulder, or from an adjacent tenancy, and what is audible through a wall or a door. Speech privacy sits at this boundary.
- Technical surveillance vulnerability
- Covert devices and the conditions that make a room worth targeting. TSCM is the detection layer inside this domain, not a synonym for the whole framework.
- Insider threat governance
- Who is trusted with proximity, how that trust is granted and revoked, and whether anomalies in physical behaviour are visible to anyone.
How it is meant to be used
PASM is an operational discipline, not a one-off audit. The intended cycle is: enumerate the surface, score it with PRMS, remediate in priority order, then re-measure. A single audit tells you where you are. Only the loop tells you whether you are getting better, and only the loop survives contact with a board that wants to know what its money bought.
Relationship to TSCM
This causes the most confusion, so plainly: TSCM is a subset of PASM. TSCM finds covert electronic surveillance — audio devices, hidden cameras, transmitters, implants. PASM covers that alongside the five other domains above. A TSCM sweep on a building with unattended ports, readable screens and no visitor discipline is an expensive way to feel better.