KB-007
FM-01
5 min read
Garrit Hunt
Security Readiness
FULL-READING VSG INFOGRAPHIC
VSG-KB007-COVER-01
Opening thesis
Security readiness is the ability to demonstrate that the current operation can meet a real demand. Required controls must function. Responsible people must understand their roles. Records must be available. Exceptions must reach someone with authority, and corrective actions must be verified. An approved plan or installed system is only a starting point. For Oregon cannabis operators, the legal baseline comes from current OLCC rules and the conditions attached to the licensed premises. The review practices described here as VSG recommendations are operational guidance, not additional law or legal advice.
Convert requirements into owned controls
Readiness begins by translating applicable requirements into clear control statements. OAR 845-025-1400 addresses the approved security plan and requires approval before a proposed plan change is implemented. OAR 845-025-1410 addresses safeguards, locks, secured conditions, and record protection. OAR 845-025-1420 establishes alarm-system requirements. OAR 845-025-1430 through 845-025-1460 address surveillance equipment, camera coverage and placement, recording and retention, equipment location, authorized access, and maintenance records.
VSG recommends a readiness register that assigns each applicable control an owner, evidence source, review frequency, last test, unresolved exception, and approval dependency. The register should point to the current rule and approved plan rather than rewriting them. This prevents a convenient checklist from becoming a substitute for the authoritative requirement.
The distinction matters. A rule may require a condition. VSG may recommend how often to check it or how to route a failure. The first is law; the second is management practice.
Test the outcome, not the component
A readiness test should confirm the result the organization depends on. For access, sample whether current authorization matches job need and whether terminated or changed roles were removed. For alarms, test that the applicable condition produces the intended notification and reaches a current authorized contact. For surveillance, retrieve representative video, confirm usable coverage and timestamps, and check whether required records can be reproduced and made available.
The legal details remain controlling. OAR 845-025-1430 requires, among other provisions, failure notification within one hour for a prolonged surveillance interruption or failure and at least one hour of recording support from battery backup. OAR 845-025-1450 requires at least 90 calendar days of surveillance recordings, at least 30 days for the off-site backup described in that rule, and Commission notice within 48 hours for an equipment failure or system outage lasting 30 minutes or more. OAR 845-025-1460 requires a current access list and a maintenance activity log for the surveillance system.
VSG does not recommend waiting for a failure to discover whether those paths work. A proportional sample can expose stale contacts, inaccessible recordings, coverage drift, or incomplete service records while corrective options remain available.
Treat exceptions as decisions
An exception should state what failed, what operation is affected, what immediate safeguard exists, who owns the response, and when a decision is required. Urgency should reflect safety, diversion exposure, evidence loss, compliance impact, and the time remaining before a reporting or approval deadline.
OAR 845-025-1450’s motion-detection method, effective January 1, 2026, should be governed as a conditional compliance path. It requires the specified analytics, stored video, auditable logs, detection-zone coverage, and uninterrupted recording whenever a person remains in view. Retention and applicable backup requirements continue. It is not a general reduction of the continuous-recording obligation. CE2025-07 supplies OLCC context but does not replace the rule.
VSG recommends recording system configuration, authorized changes, test evidence, and any exception to the expected result. Human owners should determine the response and confirm that the final condition meets the rule and approved plan.
Govern change before testing the aftermath
Many readiness gaps begin as operational improvements. A doorway moves. A room changes use. A camera is added. Detection zones are adjusted. Storage architecture is replaced. OAR 845-025-1175 requires prior written approval for the material or substantial premises changes described by that rule, including covered physical changes that require additional cameras or a security-system change. OAR 845-025-1400 separately requires approval before implementing a proposed change to the security plan.
VSG recommends a pre-change gate that records applicable approvals, expected control effects, responsible contractors, acceptance tests, and documentation updates. The change is not closed when installation ends. It is closed when the authorized owner verifies the approved operating result.
FIELD OBSERVATION
An organization may have more security data than readiness evidence. It can show live camera views, alarm histories, service tickets, and access reports, yet still struggle to answer four executive questions: Which control is affected? Who owns it? What decision is pending? What evidence proves closure? A readiness program reduces that gap by connecting technical activity to accountable management instead of adding another disconnected report.
NEXUS INSIGHT
A readiness view in a client-authorized Nexus deployment is intended to connect controls, owners, tests, exceptions, approvals, and closure evidence for human review. Nexus does not certify compliance, approve a security-plan change, alter surveillance settings, or decide that an exception is acceptable. Those decisions remain with the licensee’s authorized people and advisers. The platform’s role is to help them see what is current, what is overdue, and what evidence supports the next decision.

