Why it exists
A TSCM engagement is largely unobservable to the person buying it. You cannot tell from the outside whether someone spent four hours doing systematic work or forty minutes walking around with a handheld detector, and the invoice looks the same either way. Publishing the method is the only way a buyer can ask a specific question and recognise a non-answer.
The six stages
- 1. Threat and scope definition
- Start with the information, not the equipment: what is discussed, where, and who plausibly wants it. This fixes the spaces in scope, the threat model, the discretion requirements and the cover story for on-site work. Output is an agreed scope at a fixed price.
- 2. Physical search
- Systematic, fingertip-level inspection: furniture, fittings, ceiling and floor voids, power and data outlets, conferencing hardware, gifts and ornaments. Most finds in this industry are physical finds. Method and trained hands beat any single instrument.
- 3. Radio-frequency spectrum analysis
- Wideband capture and analysis across the ranges used by commercial and improvised devices, compared against a baseline of the local RF environment, out of hours where the environment allows. Burst, frequency-hopping and standby transmitters are specifically hunted.
- 4. Electronic and infrastructure inspection
- Non-linear junction detection to find semiconductor electronics whether powered or dormant; thermal imaging for powered devices in fabric and fittings; inspection of telephony, network points, conferencing systems and cabling for taps, implants and misconfiguration.
- 5. Findings, risk and report
- Every anomaly is resolved: identified, cleared or escalated. The report records scope, method, equipment classes, findings in risk language a committee can use, and recommendations in priority order. A clean report is itself an asset — it bounds your exposure window with a date.
- 6. Remediation and re-inspection
- Where findings require change, remediation is verified by re-inspection and the record is closed. On a find, the protocol in your TSCM policy governs evidence preservation, legal escalation and notification analysis.
Where this aligns to published standards
The staged approach aligns with the expectations behind NIST SP 800-53 RA-6, which calls for technical surveillance countermeasures surveys by qualified personnel; the physical control families of ISO/IEC 27001:2022 Annex A section 7; and the all-hazards physical environment language of NIS2 Article 21. None of those standards prescribe a method, which is precisely the gap this fills.