Skip to content

policy

Workplace Security Policy: A Practical Template for SMBs

A seven-section skeleton for the security policy a 20-to-300-person office actually needs, plus the honest answer on how much of it is really about the front desk.

By InstaCheckin Team Updated August 25, 2026

Most small offices have a locked server closet, a fire drill, a sign-in iPad, and no workplace security policy tying any of it together. The controls exist. What doesn’t exist is the document that says who decides, who enforces, and what the receptionist is supposed to do at 6pm when a contractor nobody expected walks in behind someone holding the door.

That gap is what this post fills. Below is a seven-section skeleton you can paste into your own document, the decision each section has to make, and an honest account of where visitor sign-in actually fits — which is one section, not the whole thing.

One position up front, because it’s the thing most templates get wrong. A workplace security policy is not a wish list of controls you’d buy with an unlimited budget. It’s a written record of the rules you will actually enforce on a busy Tuesday with one person on the desk. Write that version.

This post describes general practice and product capabilities. It is not legal advice — your obligations depend on your industry, jurisdiction, lease, and insurance contracts. Verify with counsel before relying on any of it for a compliance decision.

”We’re too small for this” doesn’t survive the numbers

The scale argument is the usual reason a 40-person office never writes one. It doesn’t hold up well against either the injury data or the regulations.

Violence at work is not a big-company problem. The Bureau of Labor Statistics Census of Fatal Occupational Injuries for 2024 counted 5,070 fatal work injuries in the United States, of which 470 were homicides — up from 458 the year before, in a year when total workplace fatalities fell 4.0 percent. The trend line for everything else went down. That one didn’t.

The regulatory floor moved too. OSHA’s emergency action plan standard, 29 CFR 1910.38, requires a written plan kept in the workplace — including procedures to account for every person after an evacuation — for any employer with more than 10 employees. And under Cal/OSHA’s workplace violence prevention requirements for general industry, most California employers have had to establish, implement and maintain a written workplace violence prevention plan, with a violent incident log and defined emergency response, since July 1, 2024. If you employ anyone in California, part of your security policy is already mandatory.

What a workplace security policy has to answer that your controls don’t

A badge reader records a door opening. A camera records a hallway. A sign-in kiosk records a name. None of them decide anything.

Federal security frameworks split those two jobs deliberately. NIST SP 800-53 Rev. 5 puts the authorisation rules (PE-2, PE-3) in different controls from the evidence they generate (PE-6 monitoring, PE-8 visitor access records). You can have flawless records and no policy, which is the state most offices are in — a year of sign-in data and no written answer to “was that person supposed to be here?”

CISA’s Interagency Security Committee best practice on facility access control makes the sequencing explicit for federal buildings: entry requirements get defined in advance, published to the people who’ll be subject to them, then applied consistently. Define, communicate, apply. That’s the shape you’re copying, scaled down to one lobby and one back door.

The seven sections, and the decision each one makes

#SectionThe decision it has to make
1Scope and ownershipWhich sites and which people this covers, and the one named role accountable for it.
2Physical access and keysWho gets a door code or badge, who approves it, and — the one everyone forgets — who revokes it on someone’s last day.
3Visitors and contractorsWho signs in, who escorts, which areas are off-limits, what gets signed at the door.
4Information and devicesClean desk, screen lock, what leaves the building on a laptop, what gets shredded rather than binned.
5Incident reportingHow someone reports a tailgater, a threat, or a missing badge — and the explicit promise of no retaliation for reporting.
6Emergency responseEvacuation, lockdown, headcount, and who talks to police or press. This is where your OSHA plan attaches.
7Review and exceptionsHow often it’s re-read, who signs off on an exception, and where exceptions get logged.

Two notes on using this. Every rule should name a role and an action — “the office manager revokes the door code on the leaver’s last working day,” not “access is managed appropriately.” And keep sections 6 and 7 as short annexes rather than body text, because those change more often than the rules do. Our emergency evacuation plan walkthrough covers what section 6 needs in detail.

Visitors get one section, not the whole policy

Here’s where most vendor-published “security policy templates” quietly become sales collateral: they expand the visitor section until it swallows most of the document, because that’s what the vendor sells. Don’t write it that way. Section 3 is one page.

What belongs on that page is narrow. Who counts as a visitor — contractors, interview candidates, delivery drivers, staff from another site, family. Whether the visit needs a host to pre-register it. What gets captured at sign-in and what happens to it afterwards. Whether the badge must be visible, and how it comes back. Which areas require an escort and which don’t. Any document signed at the door. If you want the long version of just this section, the visitor policy template breaks it into nine parts.

Two adjacent things belong in section 2 rather than section 3, and mixing them up is common. Door credentials are an access-control question; a printed visitor badge is an identification question — where badge access control ends and visitor badges begin sets out the split. And walk-in solicitors aren’t a security incident, they’re a front-desk script; keep them out of the policy and in the solicitor handling guide.

Three sections small offices skip, in order of regret

Offboarding. The policy covers granting access in detail and revoking it in half a sentence. Then somebody leaves, keeps a door code for eight months, and nobody can say when it stopped working. Name the trigger (last working day), the owner (whoever owns section 2), and the artefact (a dated line in a log).

Incident reporting with a no-retaliation clause. People don’t report the colleague who props the fire door, or the man who followed them in from the car park, if reporting feels like starting something. Cal/OSHA’s workplace violence prevention requirements for general industry make prohibiting retaliation against a reporting employee an explicit element of a compliant plan, which is a good signal it matters even where it isn’t mandatory. Write the reporting channel and the promise in the same paragraph.

The review date. A policy with no review cadence isn’t a policy, it’s an artefact. Pick a month, put it in the owner’s calendar, and treat “reviewed, no changes” as a valid, recorded outcome.

Rolling it out when nobody’s job title says “security”

Draft it in one sitting. Seven headings, one page each at most, written by the person who actually runs the building rather than by counsel — counsel reviews it afterwards, which is a much cheaper hour.

Then do the part that decides whether it survives: walk the building against your own draft. Try the back door. Ask the receptionist what they’d do with an unannounced contractor. Check whether last quarter’s leaver’s badge still opens anything. Every rule that fails the walk gets rewritten to what you’ll actually do, not deleted and not aspirational.

Publish it somewhere people can find it in ten seconds, brief the front desk in person rather than by email, and set the review date before you close the document.

FAQ

What should a workplace security policy include?

Seven things: scope and ownership, physical access and keys, visitors and contractors, information and device handling, incident reporting, emergency response, and the review cadence. The sections most small offices skip are offboarding and incident reporting. Offboarding is the one that quietly creates risk; incident reporting is the one an insurer or investigator asks for first.

Is a workplace security policy legally required?

No single federal rule requires a document by that name, but several rules require pieces of one. OSHA’s emergency action plan standard, 29 CFR 1910.38, requires a written plan with evacuation and headcount procedures for most employers, and Cal/OSHA’s workplace violence prevention rules for general industry have required a written plan from most California employers since July 1, 2024. This is general information, not legal advice — check your own obligations with counsel.

How long should the policy be?

Shorter than you think. Four to six pages covers all seven sections for a 50-person office if every rule names a role and an action. A 40-page policy nobody at the front desk has read is worse than a four-page one they follow, because it creates a written standard you’re visibly failing to meet.

What’s the difference between a security policy and a security plan?

A policy states the rules and who enforces them. A plan describes what happens in one specific scenario — evacuation, lockdown, a lost badge. NIST SP 800-53 Rev. 5 keeps the two in separate control families. Write one policy, attach the plans as annexes, and let the annexes change more often than the rules.

Do we need a separate visitor policy?

Only if section 3 outgrows a page — which happens at multi-tenant buildings, manufacturing sites with safety inductions, or anywhere visitors sign NDAs by visitor type. Below that, a single section inside the main policy is easier to keep current than two documents that slowly disagree with each other.

Make section 3 something you can actually enforce

Sections 1, 2 and 4 through 7 are paperwork and habit. Section 3 is the one where a written rule turns into a repeatable action at the door — and the one most likely to be ignored if it depends on someone remembering.

That’s the part InstaCheckin handles. Visitors sign in on an iPad instead of a paper book, sign your NDA or safety waiver on the same screen before a badge prints, get a badge with their name, photo, host and date on it, and the host gets an email and SMS the moment they arrive. Every visit lands in a searchable cloud log you can filter by location, host or date range and export to CSV or PDF when someone asks who was in the building on a given day. If your policy also covers a specific office site, the office visitor management system page shows what that looks like end to end.

Write the policy first. Then start a free trial and make the visitor section the one you don’t have to police.

Frequently asked questions

What should a workplace security policy include?
Seven things: scope and ownership, physical access and keys, visitors and contractors, information and device handling, incident reporting, emergency response, and the review cadence. The sections most small offices skip are offboarding — revoking a leaver's door code and badge on their last day — and incident reporting, which is the one an insurer or investigator asks for first.
Is a workplace security policy legally required?
There's no single federal rule requiring a document called a security policy. Several rules require pieces of one. OSHA's emergency action plan standard requires a written plan with evacuation and headcount procedures for most employers, and California's Labor Code section 6401.9 has required a written workplace violence prevention plan from most California employers since July 1, 2024. This is general information, not legal advice — check your own obligations with counsel.
How long should a workplace security policy be?
Shorter than you think. A 50-person office can cover all seven sections in four to six pages if each rule names a role and an action. Length is a bad proxy for quality — a 40-page policy nobody at the front desk has read is worse than a four-page one they follow, because it sets a written standard you're visibly failing to meet.
Who is responsible for the workplace security policy?
One named person, not a committee. In most small and mid-sized offices that's the office manager or head of operations, with IT and HR as reviewers. The owner's real work isn't writing the policy — it's the annual review and the exception log, because a policy with no owner drifts out of date within two reorganisations and nobody notices until an incident.
What's the difference between a security policy and a security plan?
A policy states the rules and who enforces them. A plan describes what happens in a specific scenario — evacuation, an intruder, a lost badge. NIST SP 800-53 keeps the two in separate control families for that reason. In practice you write one policy and attach the plans to it as annexes, so the rules stay stable while the procedures get updated more often.

Related reading

Ready when you are

Try InstaCheckin on your iPad — free