top of page
Self Defense Training NJ

Home  About  Contact  Industries  Programs  Our Impact  Join  Subscribe  Resources

Access Our Free Online Training Learn More. Brought to you by generous supporters

Home > Resources

Active Assailant Policy: A Practical Implementation Guide


Decorative title card illustration of security tools

An organization’s active assailant policy is its written set of prevention, response, and recovery procedures, delivered with training, so every staff member knows exactly what to do before, during, and after an incident. Your single next step: authorize a cross-functional planning team and schedule an initial hazard and threat assessment this week. CISA and the Interagency Security Committee identify four core components every effective policy must address:

 

  • Pre-incident planning (risk assessment, threat reporting, access controls)

  • Incident response procedures (evacuation, shelter-in-place, limited engagement)

  • Training programs and exercises (awareness, tabletop, functional drills)

  • Post-incident recovery (trauma-informed support, continuity, after-action review)

 

Key Takeaways

 

An effective active assailant policy requires all four federally recommended components, practiced through regular exercises, and reviewed at least annually to remain current and compliant.

 

Point

Details

Four components are mandatory

Every policy must address pre-incident planning, incident response, training, and post-incident recovery per CISA/ISC guidance.

Annual review is the minimum

Plans must be updated at least annually, and sooner after any incident, facility change, or AAR finding.

Training converts policy to behavior

ASSP recommends tabletop and functional drills to expose gaps that written documents cannot reveal.

Healthcare requires unit-level procedures

Duty-to-care obligations mean standard Run/Hide/Fight must be adapted per unit, per the FBI healthcare planning guide.

CVPSD provides end-to-end support

CVPSD offers policy workshops, tabletop facilitation, functional drills, and compliance consulting for organizations across sectors.

Table of Contents

 

 

What does an active assailant policy need to cover?

 

CISA and the Interagency Security Committee (ISC) frame these four components as the non-negotiable foundation. Pre-incident planning means identifying vulnerabilities before an attacker exploits them. Incident response procedures give staff a clear decision path when seconds count. Training and exercises convert written procedures into practiced behavior. Post-incident recovery addresses the human and operational toll that follows.

 

Plans should be reviewed and updated at least annually, or sooner when your facility changes, a threat assessment reveals new risks, or a local incident exposes gaps. OSHA’s General Duty Clause creates a parallel obligation: employers must provide a workplace free from recognized hazards, and inspectors look for documented programs, training records, and incident logs. Healthcare organizations face an additional layer through IAHSS guidelines and duty-to-care obligations that shape how each component is applied.

 

How to draft the written policy: scope, roles, and compliance

 

A well-drafted policy is clear enough that a new employee on day one can follow it under stress. Structure it as an annex to your Emergency Action Plan (EAP) rather than a standalone document, so it inherits your EAP’s distribution and review cycle. Plain language is not optional; use short sentences, active verbs, and a reading level accessible to all staff. Publish ADA-compliant formats (large print, screen-reader-compatible PDF, translated versions for non-English-speaking staff).

 

Core drafting checklist:

 

  • Define scope: which facilities, shifts, and populations the policy covers

  • Assign an executive sponsor with authority to approve and fund updates

  • Name a safety officer or threat assessment team lead as day-to-day owner

  • Identify roles: behavioral threat assessment team, facilities, communications, legal liaison, HR/union representative

  • State the review cadence (annual minimum) and who signs off on changes

  • Include a recordkeeping section: training logs, incident reports, hazard assessments

 

Legal and compliance checkpoints:

 

  1. Confirm OSHA General Duty compliance: site-specific program, documented training, incident investigation records

  2. Verify state-specific requirements (several states mandate active shooter drills for schools and healthcare)

  3. Coordinate with legal counsel on liability language and union notification obligations

  4. Cross-reference your policy with CISA’s Active Shooter EAP template to confirm coverage

 

Pro Tip: Draft a one-paragraph mission statement, a scope statement, and a review-cadence clause first. These three elements anchor every other section and prevent scope creep during committee review.

 

Designing training and exercises that actually build readiness


Hands practicing self-defense drill

Static documents do not save lives. ASSP’s technical report TR-Z590.5-2019 recommends moving beyond policy documents to interactive exercises that expose gaps in response, communication, and evacuation before an incident occurs.

 

Structure training in three tiers:

 

  1. Awareness (all staff): Recognize warning signs, know the alert system, understand Run/Hide/Fight options. Deliver annually via FEMA IS-906 or IS-907 online courses.

  2. Role-based (managers, security, clinical leads): Decision-making under pressure, notification protocols, accountability procedures.

  3. Operations-based (security, clinical teams, facilities): Timed walk-throughs, functional drills with realistic constraints.

 

Exercise Type

Purpose

Frequency

Resource Need

Tabletop

Test decision-making and communication

Annually (minimum)

Low: conference room, facilitator

Functional drill

Test physical response and evacuation

Annually or after major changes

Moderate: coordination, staff time

Full-scale exercise

Validate integrated response with LE

Every 2–3 years

High: multi-agency coordination

Evaluate every exercise using FEMA’s HSEEP framework: document strengths, areas for improvement, and corrective actions with assigned owners and deadlines. Findings feed directly back into the written policy.

 

How do you prevent an active assailant incident before it starts?

 

Prevention has the highest return on investment. ASSP’s guidance emphasizes that the pre-incident phase, specifically risk identification and securing entry points, has greater life-safety impact than response protocols alone.

 

Behavioral threat programs:

 

  • Train staff to recognize Pathway to Violence indicators: grievance escalation, research into weapons or past attacks, final-act behaviors

  • Establish a confidential reporting mechanism (tip line, online portal)

  • Convene a multidisciplinary threat assessment team: HR, security, behavioral health, legal, and management

 

Physical security priorities:

 

Priority

Action

Timeline

Short-term

Audit entry points, enforce visitor sign-in, add door locks

Days 1–30

Medium-term

Install or upgrade CCTV, add panic/duress buttons, improve lighting

30–90 days

Long-term

Access control systems, mass notification upgrade, engineering controls

90–180 days


Timeline of prevention actions with priorities and timelines

CISA’s resources for businesses and critical infrastructure partners provide Pathway to Violence training materials and reporting system templates at no cost.

 

Pro Tip: Tailgating, not forced entry, is the most common access failure in workplace violence incidents. A simple policy requiring staff to challenge unfamiliar individuals at controlled entry points costs nothing and closes a real gap.

 

Operational response: what happens when an incident begins

 

Clear response options reduce hesitation. Present staff with a stepwise decision flow rather than a rigid script:

 

  1. Evacuate if a safe exit route exists and the threat location is known.

  2. Shelter in place / lockdown if evacuation is not safe: lock and barricade doors, silence phones, stay low, await law enforcement clearance.

  3. Engage as a last resort only when no other option exists and life is in immediate danger.

 

Internal communication checklist:

 

  • Pre-load plain-language alert messages in your mass notification system (text, PA, email, digital signage)

  • Designate a primary and backup notification authority

  • Assign a family liaison and a media spokesperson before an incident occurs

  • Coordinate with law enforcement on a shared site map, staging areas, and command post location

 

Integration with first responders requires more than a phone number. The DOJ/COPS interagency guide recommends ICS/NIMS-aligned unified command, pre-incident site walkthroughs with local law enforcement, and joint tabletop exercises at least annually. Share updated floor plans, utility shutoff locations, and access codes with your local precinct and fire department each year.

 

Post-incident recovery: supporting people and restoring operations


Hands offering tea for support after incident

Recovery begins the moment law enforcement clears the scene. Trauma-informed support is not a courtesy; it is a legal and ethical obligation. The Department of Justice Office for Victims of Crime (OVC) provides no-cost toolkits and training to help organizations support victims and communities after mass violence events. Activate your Employee Assistance Program immediately and arrange on-site mental health counselors for the first 72 hours. Staff who respond to the incident, not just direct victims, often experience vicarious trauma and need the same referral pathways.

 

Operational continuity steps:

 

  1. Identify critical functions and alternate sites in advance

  2. Establish a communication protocol for clients, families, and the public

  3. Preserve the crime scene: do not move evidence, and coordinate with law enforcement before any cleanup

 

After-action review (AAR) template:

 

  • What was planned vs. what happened

  • What worked and why

  • What failed and the root cause

  • Corrective actions with owners and deadlines

  • Policy update required: yes/no, with specific section references

 

Document the AAR and file it with your training records. OSHA inspectors treat AAR documentation as evidence of a functioning workplace violence prevention program.

 

Healthcare and behavioral health: adapting for duty-to-care environments

 

Standard Run/Hide/Fight guidance does not translate directly to a hospital floor or a behavioral health unit. The FBI’s healthcare planning guide explains that duty-to-care obligations require staff to balance patient safety with their own survival, demanding unit-level procedures rather than facility-wide scripts.

 

Key adaptations:

 

  • Write separate procedures for the ED, ICU, pediatrics, behavioral health units, and outpatient clinics

  • Identify patients who cannot be evacuated quickly and assign a staff member to shelter and protect them

  • Coordinate visitor restriction protocols with security before an incident, not during one

  • Build clinical, security, and administrative teams into a single planning group

 

The ASPR TRACIE hospital checklist organizes planning across mitigation, preparedness, response, and recovery phases and is scalable for clinics and behavioral health facilities, not just large hospitals.

 

For staff and patients with disabilities, publish evacuation procedures in accessible formats, assign on-shift evacuation monitors, and conduct at least one drill that tests mobility-assistance protocols. CVPSD’s training for at-risk groups addresses these accommodations directly.

 

Pro Tip: Run your first healthcare drill in a simulation room or unoccupied unit. A live-patient floor drill without careful staging can cause real harm. Build up to occupied-unit exercises only after the simulation phase confirms staff competency.

 

A 90-day implementation timeline for getting started

 

Days 1–30:

 

  1. Convene your cross-functional planning team (executive sponsor, safety officer, HR, legal, facilities, behavioral health)

  2. Conduct an initial hazard and threat assessment using CISA’s EAP template

  3. Identify a training provider or designate an internal lead

  4. Audit current notification systems and access controls

 

Days 31–90:

 

  1. Draft and approve the written policy; circulate for legal and union review

  2. Run a tabletop exercise with the planning team

  3. Launch staff awareness training (FEMA IS-906 or equivalent)

  4. Establish a training log and incident reporting system

 

Days 91–180+:

 

  1. Conduct a functional drill; evaluate using HSEEP principles

  2. Complete an AAR and update the written policy

  3. Schedule the annual review date and assign the owner

  4. Formalize recordkeeping: training logs, incident reports, hazard assessments, AAR files

 

Budget line items to plan for: training delivery fees, exercise facilitation, mass notification system subscription, modest engineering controls (locks, signage, lighting), and staff time for drills. CVPSD’s nationwide training network can reduce per-engagement costs for multi-site organizations.

 

Your copy-ready policy toolkit

 

One-page policy checklist (print and sign off):

 

  • [ ] Mission statement drafted and approved

  • [ ] Scope defined (facilities, populations, shifts)

  • [ ] Roles and responsibilities assigned

  • [ ] Four core components addressed in writing

  • [ ] ADA-accessible formats published

  • [ ] Training schedule established

  • [ ] Notification system tested

  • [ ] Law enforcement site walkthrough completed

  • [ ] AAR process documented

  • [ ] Annual review date set and owner named

 

Copy-ready policy snippets:

 

Mission statement: “[Organization] is committed to providing a safe environment for all staff, patients/clients, and visitors. This policy establishes prevention, response, and recovery procedures for active assailant incidents.”

 

Scope: “This policy applies to all employees, contractors, and volunteers at all [Organization] facilities during all operating hours.”

 

Review cadence: “This policy will be reviewed annually by [Safety Officer/Title] and updated following any incident, significant facility change, or after-action review finding.”

 

Tabletop exercise agenda (90 minutes):

 

  1. Welcome and ground rules (5 min)

  2. Scenario inject: assailant enters building (10 min)

  3. Team discussion: notification, evacuation, shelter decisions (30 min)

  4. Second inject: communications failure (15 min)

  5. Team discussion: backup protocols (20 min)

  6. Debrief and improvement capture (10 min)

 

Federal resources to download and keep in your policy annex:

 

Resource

Best Used For

Template, accessibility guidance, business continuity

FEMA IS-906 / IS-907 / HSEEP

Staff awareness training, exercise design and evaluation

Exercise standards, pre-incident risk guidance

Compliance, recordkeeping, General Duty obligations

Healthcare adaptations, multidisciplinary design

Hospital and clinic phased planning

DOJ OVC Mass Violence Resources

Post-incident victim support and trauma-informed care

Why policy without practiced training leaves organizations exposed

 

Most organizations that experience a gap during an incident had a written policy. The document existed; the practice did not. A tabletop exercise run by an experienced facilitator routinely surfaces the same failure modes: staff who do not know which door to use, notification systems that reach only half the building, and clinical teams who have never discussed what happens to a patient in the ICU when the lockdown alarm sounds.

 

Written policy is the foundation, but it is the training that converts intention into behavior. Organizations that treat the policy as the finish line, rather than the starting point, are the ones that discover their gaps during an actual event rather than a drill.

 

CVPSD supports your policy development and training program

 

CVPSD is a 501©(3) non-profit that works directly with healthcare systems, schools, corporations, government agencies, and nonprofits to build active assailant preparedness programs that go beyond paperwork. Where many organizations struggle to move from a written policy to a practiced one, CVPSD provides the facilitation, expertise, and structured exercises to close that gap.


CVPSD

Services include policy development workshops, tabletop facilitation, functional drill design, train-the-trainer certification, and compliance consulting aligned with CISA, OSHA, and FEMA guidance. Programs are customized to your facility type, staff composition, and regulatory environment, and they meet state and local laws. Visit CVPSD’s organization page to schedule an intake consultation or request a starter toolkit for your planning team.

 

Sources

 

Download and keep these in your policy annex:

 

 

Reference these documents during every annual review and cite them in your policy annex to demonstrate good-faith compliance efforts.

 

FAQ

 

What are the four core components of an active assailant policy?

 

CISA and the Interagency Security Committee identify pre-incident planning, incident response procedures, training programs, and post-incident recovery as the four required components of an effective policy.

 

How often should an active assailant policy be reviewed?

 

Policies should be reviewed and updated at least annually, and immediately following any incident, significant facility change, or after-action review finding.

 

Does OSHA require a written active assailant policy?

 

OSHA does not mandate a specific active assailant policy by name, but the General Duty Clause requires employers to address recognized hazards; documented programs, training records, and incident logs are the primary evidence of compliance.

 

How does a healthcare organization adapt Run/Hide/Fight?

 

The FBI’s healthcare planning guide recommends unit-level procedures that account for duty-to-care obligations and patient mobility limitations, replacing a single facility-wide script with tailored protocols for the ED, ICU, behavioral health units, and other clinical areas.

 

What is the difference between a tabletop exercise and a functional drill?

 

A tabletop exercise tests decision-making and communication in a discussion format with low resource requirements; a functional drill tests physical response and evacuation under realistic conditions and requires coordination across staff, facilities, and sometimes external agencies.

 

Recommended

 



About the Author: William DeMuth

About the Author: William DeMuth is the Director of Training at the Center for Violence Prevention and Self Defense (CVPSD) in Freehold, NJ. With over 35 years of research in violence dynamics and personal safety, William specializes in evidence-based training that bridges the gap between compliance and real-world conflict resolution. The architect of the ConflictIQ™ program, he holds advanced certifications and has trained under diverse industry leaders. Today, he actively trains civilians, healthcare workers, and corporate teams in situational awareness, threat assessment, behavior analysis, de-escalation strategies, and physical tactics.

 
 

If you found this content valuable, please consider leaving a review or supporting us with a donation to help keep things running!

Center for Violence Prevention and Self Defense, Freehold NJ 732-598-7811 Registered 501(c)(3) non-profit 2026

  | Privacy Policy | Terms of Service | Terms of Use | Do Not Sell Information

bottom of page