Active Assailant Policy: A Practical Implementation Guide
- William DeMuth

- Jul 20
- 10 min read

An organization’s active assailant policy is its written set of prevention, response, and recovery procedures, delivered with training, so every staff member knows exactly what to do before, during, and after an incident. Your single next step: authorize a cross-functional planning team and schedule an initial hazard and threat assessment this week. CISA and the Interagency Security Committee identify four core components every effective policy must address:
Pre-incident planning (risk assessment, threat reporting, access controls)
Incident response procedures (evacuation, shelter-in-place, limited engagement)
Training programs and exercises (awareness, tabletop, functional drills)
Post-incident recovery (trauma-informed support, continuity, after-action review)
Key Takeaways
An effective active assailant policy requires all four federally recommended components, practiced through regular exercises, and reviewed at least annually to remain current and compliant.
Point | Details |
Four components are mandatory | Every policy must address pre-incident planning, incident response, training, and post-incident recovery per CISA/ISC guidance. |
Annual review is the minimum | Plans must be updated at least annually, and sooner after any incident, facility change, or AAR finding. |
Training converts policy to behavior | ASSP recommends tabletop and functional drills to expose gaps that written documents cannot reveal. |
Healthcare requires unit-level procedures | Duty-to-care obligations mean standard Run/Hide/Fight must be adapted per unit, per the FBI healthcare planning guide. |
CVPSD provides end-to-end support | CVPSD offers policy workshops, tabletop facilitation, functional drills, and compliance consulting for organizations across sectors. |
Table of Contents
How to draft the written policy: scope, roles, and compliance
Designing training and exercises that actually build readiness
How do you prevent an active assailant incident before it starts?
Post-incident recovery: supporting people and restoring operations
Healthcare and behavioral health: adapting for duty-to-care environments
Why policy without practiced training leaves organizations exposed
What does an active assailant policy need to cover?
CISA and the Interagency Security Committee (ISC) frame these four components as the non-negotiable foundation. Pre-incident planning means identifying vulnerabilities before an attacker exploits them. Incident response procedures give staff a clear decision path when seconds count. Training and exercises convert written procedures into practiced behavior. Post-incident recovery addresses the human and operational toll that follows.
Plans should be reviewed and updated at least annually, or sooner when your facility changes, a threat assessment reveals new risks, or a local incident exposes gaps. OSHA’s General Duty Clause creates a parallel obligation: employers must provide a workplace free from recognized hazards, and inspectors look for documented programs, training records, and incident logs. Healthcare organizations face an additional layer through IAHSS guidelines and duty-to-care obligations that shape how each component is applied.
How to draft the written policy: scope, roles, and compliance
A well-drafted policy is clear enough that a new employee on day one can follow it under stress. Structure it as an annex to your Emergency Action Plan (EAP) rather than a standalone document, so it inherits your EAP’s distribution and review cycle. Plain language is not optional; use short sentences, active verbs, and a reading level accessible to all staff. Publish ADA-compliant formats (large print, screen-reader-compatible PDF, translated versions for non-English-speaking staff).
Core drafting checklist:
Define scope: which facilities, shifts, and populations the policy covers
Assign an executive sponsor with authority to approve and fund updates
Name a safety officer or threat assessment team lead as day-to-day owner
Identify roles: behavioral threat assessment team, facilities, communications, legal liaison, HR/union representative
State the review cadence (annual minimum) and who signs off on changes
Include a recordkeeping section: training logs, incident reports, hazard assessments
Legal and compliance checkpoints:
Confirm OSHA General Duty compliance: site-specific program, documented training, incident investigation records
Verify state-specific requirements (several states mandate active shooter drills for schools and healthcare)
Coordinate with legal counsel on liability language and union notification obligations
Cross-reference your policy with CISA’s Active Shooter EAP template to confirm coverage
Pro Tip: Draft a one-paragraph mission statement, a scope statement, and a review-cadence clause first. These three elements anchor every other section and prevent scope creep during committee review.
Designing training and exercises that actually build readiness

Static documents do not save lives. ASSP’s technical report TR-Z590.5-2019 recommends moving beyond policy documents to interactive exercises that expose gaps in response, communication, and evacuation before an incident occurs.
Structure training in three tiers:
Awareness (all staff): Recognize warning signs, know the alert system, understand Run/Hide/Fight options. Deliver annually via FEMA IS-906 or IS-907 online courses.
Role-based (managers, security, clinical leads): Decision-making under pressure, notification protocols, accountability procedures.
Operations-based (security, clinical teams, facilities): Timed walk-throughs, functional drills with realistic constraints.
Exercise Type | Purpose | Frequency | Resource Need |
Tabletop | Test decision-making and communication | Annually (minimum) | Low: conference room, facilitator |
Functional drill | Test physical response and evacuation | Annually or after major changes | Moderate: coordination, staff time |
Full-scale exercise | Validate integrated response with LE | Every 2–3 years | High: multi-agency coordination |
Evaluate every exercise using FEMA’s HSEEP framework: document strengths, areas for improvement, and corrective actions with assigned owners and deadlines. Findings feed directly back into the written policy.
How do you prevent an active assailant incident before it starts?
Prevention has the highest return on investment. ASSP’s guidance emphasizes that the pre-incident phase, specifically risk identification and securing entry points, has greater life-safety impact than response protocols alone.
Behavioral threat programs:
Train staff to recognize Pathway to Violence indicators: grievance escalation, research into weapons or past attacks, final-act behaviors
Establish a confidential reporting mechanism (tip line, online portal)
Convene a multidisciplinary threat assessment team: HR, security, behavioral health, legal, and management
Physical security priorities:
Priority | Action | Timeline |
Short-term | Audit entry points, enforce visitor sign-in, add door locks | Days 1–30 |
Medium-term | Install or upgrade CCTV, add panic/duress buttons, improve lighting | 30–90 days |
Long-term | Access control systems, mass notification upgrade, engineering controls | 90–180 days |

CISA’s resources for businesses and critical infrastructure partners provide Pathway to Violence training materials and reporting system templates at no cost.
Pro Tip: Tailgating, not forced entry, is the most common access failure in workplace violence incidents. A simple policy requiring staff to challenge unfamiliar individuals at controlled entry points costs nothing and closes a real gap.
Operational response: what happens when an incident begins
Clear response options reduce hesitation. Present staff with a stepwise decision flow rather than a rigid script:
Evacuate if a safe exit route exists and the threat location is known.
Shelter in place / lockdown if evacuation is not safe: lock and barricade doors, silence phones, stay low, await law enforcement clearance.
Engage as a last resort only when no other option exists and life is in immediate danger.
Internal communication checklist:
Pre-load plain-language alert messages in your mass notification system (text, PA, email, digital signage)
Designate a primary and backup notification authority
Assign a family liaison and a media spokesperson before an incident occurs
Coordinate with law enforcement on a shared site map, staging areas, and command post location
Integration with first responders requires more than a phone number. The DOJ/COPS interagency guide recommends ICS/NIMS-aligned unified command, pre-incident site walkthroughs with local law enforcement, and joint tabletop exercises at least annually. Share updated floor plans, utility shutoff locations, and access codes with your local precinct and fire department each year.
Post-incident recovery: supporting people and restoring operations

Recovery begins the moment law enforcement clears the scene. Trauma-informed support is not a courtesy; it is a legal and ethical obligation. The Department of Justice Office for Victims of Crime (OVC) provides no-cost toolkits and training to help organizations support victims and communities after mass violence events. Activate your Employee Assistance Program immediately and arrange on-site mental health counselors for the first 72 hours. Staff who respond to the incident, not just direct victims, often experience vicarious trauma and need the same referral pathways.
Operational continuity steps:
Identify critical functions and alternate sites in advance
Establish a communication protocol for clients, families, and the public
Preserve the crime scene: do not move evidence, and coordinate with law enforcement before any cleanup
After-action review (AAR) template:
What was planned vs. what happened
What worked and why
What failed and the root cause
Corrective actions with owners and deadlines
Policy update required: yes/no, with specific section references
Document the AAR and file it with your training records. OSHA inspectors treat AAR documentation as evidence of a functioning workplace violence prevention program.
Healthcare and behavioral health: adapting for duty-to-care environments
Standard Run/Hide/Fight guidance does not translate directly to a hospital floor or a behavioral health unit. The FBI’s healthcare planning guide explains that duty-to-care obligations require staff to balance patient safety with their own survival, demanding unit-level procedures rather than facility-wide scripts.
Key adaptations:
Write separate procedures for the ED, ICU, pediatrics, behavioral health units, and outpatient clinics
Identify patients who cannot be evacuated quickly and assign a staff member to shelter and protect them
Coordinate visitor restriction protocols with security before an incident, not during one
Build clinical, security, and administrative teams into a single planning group
The ASPR TRACIE hospital checklist organizes planning across mitigation, preparedness, response, and recovery phases and is scalable for clinics and behavioral health facilities, not just large hospitals.
For staff and patients with disabilities, publish evacuation procedures in accessible formats, assign on-shift evacuation monitors, and conduct at least one drill that tests mobility-assistance protocols. CVPSD’s training for at-risk groups addresses these accommodations directly.
Pro Tip: Run your first healthcare drill in a simulation room or unoccupied unit. A live-patient floor drill without careful staging can cause real harm. Build up to occupied-unit exercises only after the simulation phase confirms staff competency.
A 90-day implementation timeline for getting started
Days 1–30:
Convene your cross-functional planning team (executive sponsor, safety officer, HR, legal, facilities, behavioral health)
Conduct an initial hazard and threat assessment using CISA’s EAP template
Identify a training provider or designate an internal lead
Audit current notification systems and access controls
Days 31–90:
Draft and approve the written policy; circulate for legal and union review
Run a tabletop exercise with the planning team
Launch staff awareness training (FEMA IS-906 or equivalent)
Establish a training log and incident reporting system
Days 91–180+:
Conduct a functional drill; evaluate using HSEEP principles
Complete an AAR and update the written policy
Schedule the annual review date and assign the owner
Formalize recordkeeping: training logs, incident reports, hazard assessments, AAR files
Budget line items to plan for: training delivery fees, exercise facilitation, mass notification system subscription, modest engineering controls (locks, signage, lighting), and staff time for drills. CVPSD’s nationwide training network can reduce per-engagement costs for multi-site organizations.
Your copy-ready policy toolkit
One-page policy checklist (print and sign off):
[ ] Mission statement drafted and approved
[ ] Scope defined (facilities, populations, shifts)
[ ] Roles and responsibilities assigned
[ ] Four core components addressed in writing
[ ] ADA-accessible formats published
[ ] Training schedule established
[ ] Notification system tested
[ ] Law enforcement site walkthrough completed
[ ] AAR process documented
[ ] Annual review date set and owner named
Copy-ready policy snippets:
Mission statement: “[Organization] is committed to providing a safe environment for all staff, patients/clients, and visitors. This policy establishes prevention, response, and recovery procedures for active assailant incidents.”
Scope: “This policy applies to all employees, contractors, and volunteers at all [Organization] facilities during all operating hours.”
Review cadence: “This policy will be reviewed annually by [Safety Officer/Title] and updated following any incident, significant facility change, or after-action review finding.”
Tabletop exercise agenda (90 minutes):
Welcome and ground rules (5 min)
Scenario inject: assailant enters building (10 min)
Team discussion: notification, evacuation, shelter decisions (30 min)
Second inject: communications failure (15 min)
Team discussion: backup protocols (20 min)
Debrief and improvement capture (10 min)
Federal resources to download and keep in your policy annex:
Resource | Best Used For |
Template, accessibility guidance, business continuity | |
FEMA IS-906 / IS-907 / HSEEP | Staff awareness training, exercise design and evaluation |
Exercise standards, pre-incident risk guidance | |
Compliance, recordkeeping, General Duty obligations | |
Healthcare adaptations, multidisciplinary design | |
Hospital and clinic phased planning | |
DOJ OVC Mass Violence Resources | Post-incident victim support and trauma-informed care |
Why policy without practiced training leaves organizations exposed
Most organizations that experience a gap during an incident had a written policy. The document existed; the practice did not. A tabletop exercise run by an experienced facilitator routinely surfaces the same failure modes: staff who do not know which door to use, notification systems that reach only half the building, and clinical teams who have never discussed what happens to a patient in the ICU when the lockdown alarm sounds.
Written policy is the foundation, but it is the training that converts intention into behavior. Organizations that treat the policy as the finish line, rather than the starting point, are the ones that discover their gaps during an actual event rather than a drill.
CVPSD supports your policy development and training program
CVPSD is a 501©(3) non-profit that works directly with healthcare systems, schools, corporations, government agencies, and nonprofits to build active assailant preparedness programs that go beyond paperwork. Where many organizations struggle to move from a written policy to a practiced one, CVPSD provides the facilitation, expertise, and structured exercises to close that gap.

Services include policy development workshops, tabletop facilitation, functional drill design, train-the-trainer certification, and compliance consulting aligned with CISA, OSHA, and FEMA guidance. Programs are customized to your facility type, staff composition, and regulatory environment, and they meet state and local laws. Visit CVPSD’s organization page to schedule an intake consultation or request a starter toolkit for your planning team.
Sources
Download and keep these in your policy annex:
Reference these documents during every annual review and cite them in your policy annex to demonstrate good-faith compliance efforts.
FAQ
What are the four core components of an active assailant policy?
CISA and the Interagency Security Committee identify pre-incident planning, incident response procedures, training programs, and post-incident recovery as the four required components of an effective policy.
How often should an active assailant policy be reviewed?
Policies should be reviewed and updated at least annually, and immediately following any incident, significant facility change, or after-action review finding.
Does OSHA require a written active assailant policy?
OSHA does not mandate a specific active assailant policy by name, but the General Duty Clause requires employers to address recognized hazards; documented programs, training records, and incident logs are the primary evidence of compliance.
How does a healthcare organization adapt Run/Hide/Fight?
The FBI’s healthcare planning guide recommends unit-level procedures that account for duty-to-care obligations and patient mobility limitations, replacing a single facility-wide script with tailored protocols for the ED, ICU, behavioral health units, and other clinical areas.
What is the difference between a tabletop exercise and a functional drill?
A tabletop exercise tests decision-making and communication in a discussion format with low resource requirements; a functional drill tests physical response and evacuation under realistic conditions and requires coordination across staff, facilities, and sometimes external agencies.
Recommended
No Easy Targets- A Complete Self-Defense System for Every Body Type, Personality, and Skill Level
The Prevalence of Ambush Attacks in Crime Statistics- What You Can Do
Home Defense: Why Creating a Hardpoint And Ambush The Home Invaders is Often the Safest Option
Crafting a Counter-Ambush Strategy: A Guide to Preparedness and Response

About the Author: William DeMuth is the Director of Training at the Center for Violence Prevention and Self Defense (CVPSD) in Freehold, NJ. With over 35 years of research in violence dynamics and personal safety, William specializes in evidence-based training that bridges the gap between compliance and real-world conflict resolution. The architect of the ConflictIQ™ program, he holds advanced certifications and has trained under diverse industry leaders. Today, he actively trains civilians, healthcare workers, and corporate teams in situational awareness, threat assessment, behavior analysis, de-escalation strategies, and physical tactics.






