What you need to know
A screening point cannot be consistent when the prohibited list, lawful exceptions, notification, secondary screening, refusal options, evidence handling, and emergency escalation exist only in an officer’s memory.
Potentially affected
Public entrances, employee and visitor screening, security officers, reception, event access, mail and delivery checkpoints, metal detectors and X-ray stations, posted notices, exception approvals, and incident reporting.
DSE recommendation
Approve a facility-specific prohibited and controlled-items policy, align it with applicable law, communicate it before arrival, train screeners on one response sequence, document exceptions, and test both the equipment and human decisions.
Source facts: a prohibited-items program exists beyond the checkpoint
The Interagency Security Committee’s May 2022 standard Items Prohibited in Federal Facilities establishes a federal baseline for dangerous, unlawful, or otherwise restricted items and procedures for controlling them. It is intended to increase consistency and reduce confusion at screening locations. The document applies its federal prohibitions whether or not a facility operates a screening checkpoint.
The standard distinguishes prohibited items from controlled items that may have a legitimate, lawful facility purpose but require advance notification and approval. It assigns the responsible authority a role in customizing and implementing the baseline for mission needs, exceptions, and exemptions while following applicable law. This is important operationally: discovering an item and deciding whether it is authorized are separate actions.
The related ISC Facility Access Control best practice describes electronic, visual, and manual screening of people, vehicles, packages, and containers. It says screening personnel need established initial and follow-up procedures, documented training, and regular testing. Its federal scope and legal authorities do not automatically govern a private facility; organizations must obtain their own legal, labor, contractual, and policy review.
DSE recommendation: decide policy before an object reaches the tray
Create an owner-approved operating standard that answers what a screener must do without forcing an improvised legal or safety decision at a crowded entrance.
- Define the authority and scope. Identify the facility owner, policy approver, security operator, legal reviewer, and emergency authority. State which entrances, populations, events, vehicles, bags, deliveries, and non-screened doors are covered. Do not borrow federal authority or terminology without confirming it applies.
- Publish usable categories. Separate prohibited, controlled, exempt, and ordinary items. For controlled items, document who can approve them, required advance notice, identity and purpose checks, movement restrictions, storage, escort, and end-of-visit reconciliation.
- Give notice before screening. Place clear, accessible notices where a person can choose not to enter and provide the same information in invitations, visitor instructions, event pages, and contractor onboarding. Include whom to contact about medical, religious, accessibility, law-enforcement, or business-purpose exceptions without forcing disclosure in public.
- Design one decision path. Define initial indication, respectful rescreening, supervisor review, approved exception lookup, voluntary withdrawal or return-to-vehicle option where permitted, denial of entry, emergency notification, and incident documentation. Specify when staff should stop handling an item and create distance.
- Protect people at the station. Plan queue capacity, escape and duress options, responder access, safe placement of discovered property, communications, privacy during secondary screening, and a method for summoning a supervisor without escalating the interaction.
- Control records and property. Decide what screeners document, who may take custody, whether the organization has lawful authority to retain an item, how evidence is preserved for law enforcement, and how ordinary surrendered property is identified and disposed of. Never let an improvised “confiscation box” become an untracked hazard.
Train with scenarios, not only equipment buttons: an employee with a newly prohibited item, a contractor carrying a controlled tool, a visitor requesting an accommodation, an off-duty officer, a credible dangerous object, a refusal to screen, a false equipment alarm, and an overwhelmed queue. Test detection equipment according to its instructions, but separately observe whether the human response follows policy.
Audit exceptions and denials for consistency, not quotas. Review recurring items, unclear notices, abandoned property, equipment downtime, unauthorized bypass doors, supervisor response time, complaints, and emergency escalations. After a policy change, brief every entrance and shift before enforcement begins. A high-quality screening program is predictable: people receive notice, screeners know their limits, legitimate exceptions are controlled, and dangerous uncertainty moves quickly to the right authority.
Official references
- Cybersecurity and Infrastructure Security Agency, Interagency Security Committee, Items Prohibited in Federal Facilities: An ISC Standard, May 26, 2022.
- CISA Interagency Security Committee, Facility Access Control: An ISC Best Practice.
Review the official source
CISA Interagency Security Committee: Items Prohibited in Federal Facilities · Published May 26, 2022
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE