Writing a TSCM Policy

A TSCM policy turns occasional bug sweeps into a governed control: defined spaces, defined cadence, defined triggers, and records that stand up to auditors, regulators and courts. Here is the full structure, usable as written.

Last reviewed: 2026-09-03

Why a policy, not just sweeps

An unwritten counter-surveillance practice fails in three predictable ways. It skips the periods of highest risk because no trigger events are defined. It produces no evidence, so it cannot support a compliance declaration, an insurance question, or a trade secret claim. And it dies when its informal owner changes role.

A one-page policy fixes all three. It is also what turns the spend into a control that regulators and auditors recognize: under NIST 800-53 RA-6, ISO 27001 and the SEC's Item 106 disclosure frame alike, the documented, operated control is what counts — not the activity.

Scope: name the spaces, not the building

The most common policy failure is scoping to "the premises". Sweep costs scale with area, so an unscoped policy becomes unaffordable and is quietly abandoned. Scope instead to the rooms where sensitive information is actually spoken or displayed: the board room, executive offices, the M&A or deal room, legal and HR meeting rooms, R&D discussion spaces, and vehicles used for sensitive calls.

For each listed space, record why it is in scope — the information class discussed there — so the list can be defended and revisited. Everything else in the building is covered by ordinary physical security, not by the TSCM programme.

Roles, confidentiality and handling a find

Name a single accountable owner — typically the head of security, the CISO, or in smaller organisations the general counsel or company secretary. Keep the circle of knowledge deliberately small: sweeps announced widely are sweeps defeated, and insider involvement in device placement is common enough that discretion is a design requirement, not paranoia.

The policy must say what happens on a find before a find happens. Typically: do not touch or discuss the device in the room; preserve the scene; notify the owner through an out-of-band channel; engage counsel early because interception is criminal conduct in most jurisdictions; decide deliberately between removal, monitoring, and law-enforcement referral; and assess notification duties — a device that captured personal data can trigger breach obligations, and one that captured material information can trigger disclosure analysis.

The ten sections of a complete TSCM policy

  1. 01Purpose and threat statement — what information loss the policy exists to prevent
  2. 02Scope — named spaces and vehicles, with the information class that justifies each
  3. 03Accountable owner and deputies, with out-of-band contact routes
  4. 04Periodic inspection cadence per space tier (see sweep frequency guidance)
  5. 05Trigger events requiring an unscheduled inspection (see trigger events guidance)
  6. 06Provider requirements — qualifications, equipment class, insurance, NDA
  7. 07Confidentiality rules — who may know schedules, results, and methods
  8. 08Find protocol — preservation, escalation, counsel, notification analysis
  9. 09Records — what is retained, where, and for how long
  10. 10Review — annual policy review and post-incident lessons

Scope an assessment

A short conversation establishes scope and a fixed price. Assessments run across the US, UK and Europe.

Speak to a specialist