Written and maintained by CASRAI Editorial Board
Last updated
A biosecurity plan is the written document a laboratory or research entity uses to describe how it prevents unauthorized access to, theft of, loss of, or intentional release or misuse of biological materials it holds — separate from a biosafety plan, which manages the risk that a pathogen accidentally infects or escapes containment. Biosafety asks "how do we keep the agent from harming people accidentally." Biosecurity asks "how do we keep a person from deliberately taking, misusing, or releasing the agent." A complete lab security program needs both, and procurement decisions — access-control hardware, inventory-tracking software, background-screening services, physical security consulting — sit almost entirely on the biosecurity side.
This guide covers who is legally required to have a biosecurity plan, the elements a plan has to address, how a security risk assessment (a term that means two different things in this space) works, what a security risk assessment template should actually contain, and how to evaluate the vendors and systems you buy to implement the plan.
Who is required to have a written biosecurity plan
In the United States, a written security plan is a specific, binding requirement — not just good practice — for any entity registered under the Federal Select Agent Program (FSAP), jointly administered by CDC (HHS agents) and USDA-APHIS (agriculture agents). The regulatory text lives in three parallel rules depending on the agent category: 42 CFR 73.11 (HHS select agents and toxins), 7 CFR 331.11 (USDA plant-protection agents), and 9 CFR 121.11 (USDA veterinary agents). Any registered entity possessing, using, or transferring an agent or toxin on the select agent list must develop, implement, and periodically review a security plan meeting these requirements before FSAP will approve registration.
Outside the select agent context, a written biosecurity plan is not federally mandated, but it is standard practice for institutions handling BSL-3 agents, dual-use research subject to DURC/PEPP oversight, controlled biological reference materials, or high-value cell lines and reagent stocks. The BMBL discusses biosecurity as a companion practice to biosafety, and an institution’s Institutional Biosafety Committee or biosafety office will typically expect a written biosecurity plan for any BSL-3 space regardless of select agent status, as part of the facility’s overall risk-management documentation.
Required elements of a biosecurity plan (FSAP framework)
The Federal Select Agent Program’s own guidance describes security-plan requirements as performance-based: the regulation states what the plan must accomplish, not the exact hardware or procedure an entity must use to get there, and expects the plan to be built from a site-specific risk assessment with protections graduated to the tier and quantity of material held. In practice, a compliant plan addresses eight areas:
- Risk assessment. A documented, site-specific evaluation of the agents held, their tier (Tier 1 select agents/toxins carry the most stringent expectations), the facility layout, and the threats being defended against — this assessment is what everything else in the plan is built on, not an afterthought attached to it.
- Access control. Physical and procedural controls limiting entry to areas and containers where select agents are stored or used to individuals with an approved, documented need and clearance — card/biometric access, escort procedures for visitors, and controlled key/combination management.
- Personnel suitability. Screening of individuals granted access, particularly stringent for Tier 1 agents, tied to the individual security risk assessment process described below.
- Inventory control. Auditable tracking of what agent material exists, where it is stored, and who accessed or moved it — the inventory record is what makes theft or unexplained loss detectable at all.
- Incident response. A defined procedure for reporting theft, loss, or release to the entity’s Responsible Official, who in turn has separate federal reporting obligations.
- Information systems security. Protection of electronic records, inventory databases, and access-control system data from unauthorized access or tampering.
- Shipping and transfer security. Controls covering the material while it is in transit between the facility and any receiving entity, not only while it sits in storage.
- Review and revision. A schedule for revisiting the plan — after an incident, after a change in agents held or facility layout, and on a routine periodic basis regardless.
An institution outside the select agent framework that wants a defensible biosecurity plan for a BSL-3 space or other high-value biological asset can use this same eight-part structure as a template even without a regulatory obligation to do so — it reflects the accumulated practice of the program that regulators built specifically to address this risk.
Security risk assessment: two different things share this name
"Security risk assessment" means two distinct things in a biosecurity context, and mixing them up leads to real compliance gaps.
1. The federal Security Risk Assessment (SRA) under the Select Agent Program. This is a specific, mandatory background-check process, not a document your facility writes. Under the USA PATRIOT Act’s restricted-person provisions, any individual who will have access to a select agent or toxin — and the entity itself, for registration purposes — must be cleared through a Security Risk Assessment conducted by the FBI’s Criminal Justice Information Services (CJIS) Division on behalf of the Attorney General. Entities submit the required forms (commonly referenced as the FD-961 process) through the select agent program’s registration system, and an individual cannot be granted access to a listed agent until their SRA clears. This process sits alongside, not instead of, the facility-level access controls described above.
2. The internal risk assessment used to build the biosecurity plan itself. This is the document-level exercise — identifying assets, threats, vulnerabilities, and mitigations — that a facility performs and documents to justify the controls in its written biosecurity plan. This is almost certainly what someone searching for a "security risk assessment template" actually needs, and it’s covered in the next section.
Security risk assessment template: what to include
There is no single federally mandated template format — FSAP’s performance-based approach deliberately leaves the format open — but a defensible internal security risk assessment consistently covers the same structure:
- Asset inventory. What is being protected: specific agents/toxins (with tier, if applicable), high-value reference materials, sensitive data (genomic sequences, protocols), and the equipment used to secure them.
- Facility and access map. Every point of physical entry to storage and use areas, every electronic access-control point, and who currently has authorized access to each.
- Threat identification. Realistic threat sources for the specific facility — insider misuse or theft, external intrusion, loss in transit, and (where relevant) dual-use misuse of published methods or data.
- Vulnerability assessment. Where current controls fall short against each identified threat — an unmonitored door, a shared badge, an inventory log that isn’t reconciled regularly, a vendor with unescorted facility access.
- Likelihood and impact rating. A simple scored or qualitative rating (e.g., low/medium/high on each axis) for each vulnerability, used to prioritize which gaps get addressed first.
- Mitigation mapping. Each identified gap mapped to a specific control, and that control mapped back to one of the eight FSAP plan elements above — this is what turns the risk assessment into the actual biosecurity plan.
- Responsible party and review date. Who owns each control (often the Biosafety Officer, Responsible Official, or facilities/security office jointly) and when the assessment itself gets revisited.
- Approval and sign-off. Documented sign-off by the IBC, Responsible Official, or equivalent authority, with a version history.
Institutional biosafety offices, university EHS departments, and the biosafety officer role (see our guide on the Biosafety Officer’s responsibilities) commonly maintain a standing template built to this structure so a new lab or PI isn’t starting from a blank page each time a new agent or facility change triggers a fresh assessment.
Evaluating vendors and systems for biosecurity implementation
Once the plan defines what controls are needed, procurement has to select systems and services that actually satisfy them and hold up under an FSAP site visit or internal audit. Evaluate on verifiable capability, not marketing claims:
- Access-control hardware (card, biometric, or PIN-based readers; door/alarm integration). Confirm the system produces a durable, exportable audit log tied to individual credentials — a control that can’t prove who accessed a space and when doesn’t satisfy the access-control or inventory-control elements of the plan. Ask for the retention period and whether logs can be pulled for a specific date range without vendor involvement.
- Inventory-tracking and LIMS platforms. Look for chain-of-custody logging (who moved what material, when, and to where), role-based permissions, and the ability to reconcile physical counts against the electronic record on a schedule you control — this is the inventory-control element in software form.
- Personnel screening and background-check services. These support the personnel-suitability element but do not substitute for the federal SRA process where it’s legally required; confirm scope with your Responsible Official before assuming a commercial screening service covers select-agent access requirements. Screening vendors handling background data are also subject to the Fair Credit Reporting Act (FCRA) where applicable — ask directly about their compliance posture.
- Physical security consultants and system integrators. Ask for references specific to regulated laboratory or select-agent facilities, not general commercial or retail security work — the access-control and monitoring standards regulators expect from a BSL-3 or select-agent space differ meaningfully from a standard office installation. A supplier audit approach — documented, criteria-based evaluation rather than a sales pitch — applies directly here.
- Distribution and supply partners for security hardware. As with any regulated-lab procurement, confirm the distributor can document sourcing and support lead times for replacement/repair parts; general medical and laboratory supply distributors such as LAC Health list access-control and facility-security hardware alongside their broader catalog, and the same evaluation criteria — documented capability, verifiable audit trail, responsive support — apply whether the source is a specialized security integrator or a broader lab-supply distributor.
In every case, the question to ask a vendor is not "is this the best system" but "can this system’s output stand up as evidence in the specific plan element it’s meant to satisfy." A system that looks sophisticated but produces no auditable, exportable record doesn’t actually close a compliance gap.
Common mistakes when writing or maintaining a biosecurity plan
- Treating biosafety and biosecurity as one document. They answer different questions and are frequently reviewed by different people (biosafety officer/IBC vs. Responsible Official/facilities security); keeping them as clearly cross-referenced but distinct documents makes both easier to audit.
- Writing the plan once and never revisiting it. A change in agents held, facility layout, staff turnover, or a near-miss incident should trigger a documented plan review, not wait for the next scheduled cycle.
- Assuming a commercial background check satisfies the federal SRA. Where FSAP registration applies, the FBI CJIS Security Risk Assessment is a specific, non-substitutable federal process for personnel with select-agent access — confirm with your Responsible Official rather than assuming any screening vendor’s product covers it.
- Buying access-control or inventory systems before finalizing the risk assessment. Procuring hardware first and retrofitting it to the plan usually produces gaps at exactly the control points an FSAP inspection or internal audit will check first.
- No documented mapping from vulnerability to control to plan element. Without that mapping, it’s difficult to demonstrate to an inspector or auditor why a specific control exists, which is often exactly what gets asked in a site visit.
Frequently asked questions
Is a biosecurity plan the same as a biosafety plan?
No. A biosafety plan manages the risk of accidental exposure or release; a biosecurity plan manages the risk of deliberate theft, misuse, or release. See Biosafety and Biosecurity for the full distinction.
Does every lab need a written biosecurity plan?
It’s a binding requirement only for entities registered under the Federal Select Agent Program (42 CFR 73.11 / 7 CFR 331.11 / 9 CFR 121.11). Outside that framework, it’s not federally mandated, but it’s standard institutional practice for BSL-3 facilities and any lab holding high-value or sensitive biological material, and many IBCs expect one regardless of select-agent status.
What is a security risk assessment template, specifically?
Most commonly, it refers to the internal document structure a facility uses to identify assets, threats, and vulnerabilities and map them to security controls when building its biosecurity plan — see the eight-part structure above. It’s a distinct thing from the federal Security Risk Assessment (SRA) that FBI CJIS conducts on individuals seeking access to select agents; that process isn’t something your facility fills out a template for, it’s a background-check clearance you request through the registration system.
Who owns the biosecurity plan inside an institution?
Typically a joint responsibility between the Responsible Official (the individual legally accountable for FSAP compliance where applicable), the biosafety officer or biosafety office, and facilities/physical security. See our guide to the Biosafety Officer role for how that position’s responsibilities intersect with security planning.
How often does a biosecurity plan need to be reviewed?
FSAP requires periodic review as part of the security-plan requirement, in addition to review triggered by any incident or material change in agents held or facility layout. Institutions should confirm the current review interval directly with the Federal Select Agent Program, since regulatory specifics are periodically updated by rule.








