Reference Desk

Standards Library

A practical starting set for teams building security requirements into the built environment. Certanet does not treat any single reference as sufficient. Security design should be risk-based and project-specific.

ReferenceHow Certanet applies it
WBDG Unified Facilities CriteriaPrimary public access point for DoD criteria. Certanet uses it to benchmark whether project language reflects current federal design discipline instead of relying on outdated specifications or informal security preferences.
UFC 4-010-01 DoD Minimum Antiterrorism Standards for BuildingsA baseline model for antiterrorism and force-protection thinking: standoff, envelope behavior, glazing exposure, progressive collapse, and occupancy risk. Certanet uses it as a comparison tool for risk-triggered civilian facilities, not as a blanket civilian code.
UFC 4-021-02 Electronic Security SystemsReference for access control, intrusion detection, video surveillance, duress, communications, and electronic security system integration. Certanet uses it to connect physical protection with the systems that detect, delay, document, and respond.
CISA NSM-22 Critical Infrastructure Security and ResiliencePolicy anchor for critical infrastructure resilience as a shared national responsibility. Certanet uses NSM-22 to frame security as governance, continuity, and risk ownership, not only as a construction or guard-force problem.
ISC Risk Management Process for Federal FacilitiesStructured method for linking threat, vulnerability, consequence, facility security level, and countermeasure selection. Certanet uses it to keep security recommendations documented, proportional, and defensible.
NIST Cybersecurity Framework 2.0Governance and risk framework for cyber and cyber-physical dependencies. Certanet uses it to show why server rooms, controls spaces, communications pathways, and building systems require physical protection as part of enterprise resilience.
NFPA 730 Guide for Premises SecurityCivilian premises-security guide covering security planning, surveys, roles, and facility practices. Certanet uses it as an accessible bridge between everyday facility management and more formal protective-design criteria.