Western Australia operates one of Australia’s most geographically dispersed aviation networks. Perth Airport serves as the state’s major international and domestic hub, while a network of regional and remote aerodromes supports the mining, resources, pastoral, and community services that define WA’s economy and population distribution.
Every one of these facilities – from Perth Airport to the most remote Category 5 aerodrome – has physical security obligations under the Aviation Transport Security Act 2004 (ATSA). Those obligations have become more demanding following recent amendments that introduced mandatory security assessments, all-hazards risk frameworks, and annual compliance statements approved at board level.
Smartsec Security Solutions delivers independent physical security assessments for WA airports, aerodromes, and aviation industry participants. Our work focuses exclusively on the physical security dimension of aviation security compliance – perimeter, access control, surveillance, landside and airside physical arrangements – without the cyber, screening operations, or ICAO-specialist advisory that national firms typically bundle into large aviation security programs.
This article explains what physical security assessment under the ATSA involves, which WA aviation industry participants are affected, and what an independent assessment provides that internal review cannot.
The Aviation Transport Security Framework in Australia
The Aviation Transport Security Act 2004 establishes the regulatory framework for civil aviation security in Australia. It imposes obligations on a range of aviation industry participants – airport operators, aircraft operators, air cargo agents, and regulated air cargo agents – requiring them to develop and comply with Transport Security Programs (TSPs) that address security risk across their operations.
The ATSA is administered by the Cyber and Infrastructure Security Centre (CISC) within the Department of Home Affairs. CISC assigns categories to security controlled airports based on the volume and type of air services they support, and monitors compliance with TSP obligations across the national aviation network.
Recent amendments to the ATSA have significantly strengthened the physical security requirements placed on aviation industry participants. Key changes include:
Mandatory security assessments. Comprehensive, risk-based security assessments are now compulsory for all Transport Security Programs. The “all-hazards” approach requires participants to address physical security threats alongside other risk categories – moving beyond a compliance checklist to a structured, evidence-based assessment of actual risk exposure.
Annual compliance statements. Board-approved declarations confirming that security programs remain current and compliant are now required annually. This governance requirement means physical security arrangements must be reviewed and evidenced on a regular cycle, not just at TSP renewal.
Expanded security scope. New requirements address both unlawful and operational interference, taking an all-hazards approach that explicitly includes physical security threats to aviation assets and infrastructure.
These changes mean that WA airports and aviation industry participants who previously treated their TSP as a static compliance document now need to demonstrate active, ongoing physical security risk management – including documented assessments, regular review, and board-level accountability.
What a Transport Security Program Must Include for Physical Security
The Aviation Transport Security Regulations 2005 set out the content requirements for TSPs across different categories of aviation industry participant. For airport operators, the physical security requirements are explicit and detailed.
Access control. The TSP must set out security measures and procedures to control access at the airport and maintain the integrity of access control systems. This includes measures to deter and detect unauthorised access into the airside area, airside security zone, and landside security zone by people, aircraft, vehicles, and things.
Perimeter security. Physical perimeter arrangements – fencing, barriers, gates, vehicle access controls, and the integrity of the boundary between public landside areas and restricted airside zones – must be addressed. For WA’s regional aerodromes, perimeter integrity is often the most significant physical security challenge, particularly where facilities are remotely located and after-hours monitoring is limited.
Surveillance and monitoring. CCTV coverage of critical areas – airside access points, restricted zones, terminal entries and exits, cargo areas, and perimeter interfaces – must be documented in the TSP. The assessment evaluates whether existing coverage is adequate against the actual threat environment, not just whether cameras are present.
Unattended aircraft. Measures to be applied to unattended aircraft must be documented. This is particularly relevant for regional aerodromes where aircraft may be left overnight with minimal supervision.
Suspicious items and substances. Procedures to assess, identify, and respond to unknown substances and unattended or suspect vehicles, aircraft, or items must be in place and documented.
For the physical security elements of a TSP to be compliant under the amended ATSA requirements, they need to be grounded in a current, evidence-based security risk assessment – not a generic template or a self-assessment by the airport operator.
The WA Aviation Network: Who Needs Physical Security Assessment
Western Australia’s aviation network is extensive and geographically diverse. The physical security challenges facing Perth Airport differ fundamentally from those facing a regional aerodrome in the Pilbara or Kimberley – and both differ from the security environment facing a metropolitan air cargo facility or a charter operator serving remote mine sites.
Perth Airport is a designated, categorised security controlled airport under the ATSA, with obligations that reflect its status as WA’s major international and domestic hub. Physical security arrangements at Perth Airport are subject to ongoing CISC oversight, and the recent ATSA amendments increase the governance and documentation requirements for its TSP.
Regional and remote aerodromes – including Karratha, Port Hedland, Broome, Newman, Kalgoorlie-Boulder, Learmonth, Albany, Geraldton, and Esperance – serve the resources sector, regional communities, and critical services including Royal Flying Doctor Service operations. These facilities have physical security obligations under the ATSA that are frequently under-resourced and under-documented compared to their metropolitan counterparts.
The specific physical security challenges of regional WA aerodromes include:
- Extended perimeters with limited fencing infrastructure in remote locations
- After-hours operations with minimal staffing and extended emergency response times
- Shared-use environments where public and commercial aviation access intersect
- Limited CCTV infrastructure relative to the area requiring coverage
- Vehicle access arrangements that reflect operational convenience rather than security design
- Seasonal staffing and contractor access management challenges
An independent physical security assessment that understands the WA regional aviation operating environment produces different and more relevant findings than one conducted by a consultant unfamiliar with the practical constraints of remote Australian airports.
Air cargo agents and regulated air cargo agents operating in WA have their own TSP obligations, including physical security measures for cargo handling areas, restricted access zones, and the interface between public and secure areas at cargo facilities. Perth’s air cargo infrastructure serves the resources, pharmaceutical, and perishable goods sectors and has physical security requirements that a generic commercial property assessment does not adequately address.
Charter and regional aircraft operators serving WA mine sites under FIFO arrangements operate in a specific security environment where personnel access management, vehicle access at remote aerodromes, and the security of aircraft parked at remote locations all create physical security exposure. The TSP for these operators must address physical security arrangements at the aerodromes they use, which may be Category 5 or unclassified facilities with minimal existing security infrastructure.
What an Independent Physical Security Assessment Involves for Aviation
A physical security assessment for an aviation industry participant is a structured, site-specific evaluation aligned with ISO 31000:2018 and the physical security requirements of the ATSA and associated regulations. It is not a screening operations audit, a cyber security assessment, or an ICAO compliance review – it focuses exclusively on the physical security elements of the TSP.
Site inspection and context review. Understanding the facility, its layout, its operational model, its passenger and cargo volumes, its hours of operation, and its specific geographic and environmental context. For WA regional aerodromes, this includes understanding the practical realities of remote operations – extended response times, seasonal variation, contractor access patterns, and the infrastructure constraints that shape what physical security measures are actually achievable.
Threat identification. Identifying the realistic physical security threats relevant to the specific facility. Aviation threat environments include not only the unlawful interference threats addressed by ICAO Annex 17 but also the broader physical threat picture – theft, vandalism, unauthorised access, vehicle-borne threats, and insider risk. The threat picture for a Pilbara regional aerodrome is different to that for Perth Airport’s international terminal, and the assessment reflects this.
Perimeter and access control assessment. Evaluating the physical integrity of the perimeter – fencing, gates, barriers, and vehicle access points – and the adequacy of access control arrangements for airside, airside security zone, and landside security zone access. This includes credential management, after-hours access controls, visitor management, and the integration of access control with monitoring and alarm arrangements.
Surveillance and monitoring assessment. Evaluating CCTV coverage of critical areas against the threat environment and the TSP requirements. This includes camera positioning, field of view, image quality and resolution, lighting adequacy, recording and retention settings, and system health. Aviation environments present specific challenges for CCTV – large open apron areas, variable lighting conditions, and the need for coverage across multiple access points and zones simultaneously.
After-hours arrangements. Aviation facilities often operate across extended hours or around the clock. The physical security arrangements that are adequate during peak operational periods may be significantly inadequate after hours – when staffing is reduced, monitoring is intermittent, and response times are extended. The assessment specifically examines after-hours physical security conditions.
Risk rating and prioritisation. All findings are rated using a likelihood-consequence matrix aligned with ISO 31000:2018, producing a prioritised risk register. For aviation industry participants who need to demonstrate to CISC that their TSP is based on a current security risk profile, this risk register is the evidentiary foundation.
Report suitable for TSP documentation and CISC review. A written assessment report that documents methodology, findings, risk ratings, and prioritised recommendations – structured to support TSP compliance and capable of withstanding CISC audit scrutiny. The report addresses each physical security element required by the ATSA regulations and demonstrates that the assessment has been conducted by an independent, credentialed consultant.
Why Independent Assessment Matters for Aviation Physical Security
Aviation industry participants frequently rely on their own security teams, airport operators, or bundled consulting services for physical security assessment. Each of these approaches has limitations that independent assessment avoids.
Internal assessment is conducted by people embedded in the organisation who may have designed or approved the existing arrangements. The incentive to identify significant gaps is limited when those gaps reflect decisions the assessor was involved in. Independent assessment removes this bias.
Airport operator-led assessment creates a similar dynamic for tenants and airline operators whose physical security arrangements are assessed by the airport operator they depend on for access and services. An independent assessment provides a genuinely objective view.
Bundled consulting services from national firms that combine cyber, personnel, and physical security advisory often treat physical security as a secondary element within a larger program. The physical security assessment receives less specialist attention than cyber and governance, and may be conducted by a consultant whose primary expertise is not physical security.
Smartsec works exclusively in physical security. Every engagement is a physical security assessment – conducted on site, by an experienced consultant, against a structured methodology aligned with ISO 31000:2018. We do not supply or install security systems, and we have no commercial relationships with security product suppliers.
The Amended ATSA and the Case for Acting Now
The recent amendments to the Aviation Transport Security Act 2004 have created a compliance environment with stronger physical security documentation requirements, mandatory risk-based assessments, and annual board-level attestation. The trajectory is clear – physical security in aviation is moving toward the same structured, evidenced compliance framework that critical infrastructure under SOCI now requires.
Aviation industry participants who have not conducted an independent physical security assessment of their TSP arrangements are increasingly exposed – not just to CISC audit finding, but to the governance and liability consequences of operating a TSP that cannot demonstrate the mandatory all-hazards risk assessment the amended legislation requires.
The right time to commission an independent assessment is before a CISC audit, not after one. An assessment conducted proactively provides the evidentiary foundation for TSP compliance, identifies gaps before they become findings, and demonstrates to the regulator that the operator is actively managing its physical security obligations.
WA Airports and Aerodromes Smartsec Works With
Smartsec Security Solutions is available to conduct independent physical security assessments for aviation industry participants across Western Australia, including:
- Perth Airport and associated terminals, cargo facilities, and aviation precincts
- Regional airports across the Pilbara, Kimberley, Gascoyne, Goldfields, Great Southern, and South West regions
- Remote aerodromes serving the resources sector under FIFO arrangements
- Air cargo facilities and regulated air cargo agents operating in WA
- Charter and regional aircraft operators with WA-based TSP obligations
- Ground handling and aviation services operators at WA security controlled airports
Engaging Smartsec as Your Aviation Security Consultant in Perth
Smartsec Security Solutions is a Perth-based independent physical security consultancy delivering assessments and advisory for aviation industry participants, critical infrastructure operators, local government, commercial operators, and government agencies across Western Australia.
Our aviation physical security assessments are aligned with ISO 31000:2018, the ATSA and associated regulations, and the all-hazards risk framework required under the amended legislation. We are a licensed WA Security Risk Consultant and Security Agent, holding the Security Risk Management Certified Professional (SRMCP) credential. We are vendor-neutral – we do not supply or install security systems.
For WA aviation industry participants who need an independent physical security assessment to support their TSP compliance, the right starting point is a brief scoping conversation. We will confirm the scope of your ATSA obligations, identify what physical security documentation currently exists, and outline what an independent assessment and report would involve for your facility.
Contact Smartsec Security Solutions to arrange a confidential scoping conversation.


