Discussion and Replies
11
Physical and Environmental
Security Physical and environmental controls are some of the most critical safeguards an organization can
implement based on results. Physical controls are historically among the most breached controls.
Secure areas and equipment security concepts have been around for a long time and are some of
the most widely accepted methods for security. If this last statement is generally true, why are
there so many physical breaches of information security controls?
So much attention is focused on high-tech controls, and the bulk of the budget dollars are
typically spent in this area as well, that some of the most basic, yet effective, controls can be
overlooked.
The thirteen controls and two control objectives should be reviewed very closely by every
organization, and management should ensure that they are implemented and operating at a high
level of effectiveness. They are some of the most straightforward and simple controls to
implement and will continue to prove to be some of the most effective for controlling common
threats.
SECURE AREAS
This control objective is designed to help organizations prevent security breaches and damages to
the organization’s facilities and ultimately their information, data, and systems.
9.1.1 — P S PHYSICAL ECURITY ERIMETER
Scope: The organization’s information processing facilities perimeter should be adequately
protected by physical controls such as walls, fences, manned and guarded entry, barriers, access
cards, closed circuit television, etc.
Key Risk Indicator: Yes
Control Class: (O) Operations
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.
Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 1 of 9
Key Questions:
Has the organization clearly defined security perimeters?
Describe the physical security controls and safeguards in place today to protect the
information processing facility.
Is the information processing facility monitored for fire, smoke, water, and unauthorized
entry?
· Is the building that houses information processing facilities protected by a manned
reception area?
Are visitors to the information processing facilities building(s) required to sign in and be
escorted by an employee at all times when visiting?
Additional Information: In smaller companies, the more elaborate controls and safeguards
might not be available or appropriate. At a minimum, the information processing systems should
be contained in a safe environment with controlled access; preferably this access is auditable and
can be monitored.
9.1.2 — P E CHYSICAL NTRY ONTROLS
Scope: Physical entry controls should be developed and implemented to properly protect secured
areas.
Key Risk Indicator: No
Control Class: (O) Operations
Key Questions:
How does management control access to secured information processing facilities?
Is there an audit trail maintained for secured information processing facilities?
Does management review access rights to secured information processing facilities on a
regular basis?
9.1.3 — S O , R , FECURING FFICES OOMS AND ACILITIES
Scope: Offices and organizational facilities should be secured with appropriate physical controls
as required.
Key Risk Indicator: No
Control Class: (O) Operations
Key Questions:
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.
Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 2 of 9
How does management identify areas within the organization requiring physical controls?
Are vacant areas within the facilities secured with physical controls and routinely checked to
ensure the integrity of the implemented controls?
What controls are currently in place to control the use of video and audio recording
equipment?
9.1.4 — P A E E TROTECTING GAINST XTERNAL AND NVIRONMENTAL HREATS
Scope: Management of an organization must protect itself and employees from disasters such as
fire, flooding, and explosions, including both natural and man-made events. Physical controls
should be assessed, designed, implemented, and monitored to ensure adequacy and effectiveness
of these controls.
Key Risk Indicator: Yes
Control Class: (M) Management, (O) Operations
Key Questions:
How do employees and users know they are operating in a secure area within the
organization?
How does management remain current with new threats, internal and external, and how they
relate to your organization?
Describe the actions taken by your organization to protect itself from neighboring buildings
or infrastructures.
Does your organization store information or data near materials that could be considered
hazardous or prone to fire or other similar events?
Additional Information: If disaster recovery equipment is housed too close to the main facility,
this may be an issue for concern. Recovery equipment, systems, backup media, and other similar
items should be stored as far away as reasonably possible to be protected from the event that
disrupted operations at the main facility.
9.1.5 — W S AORKING IN ECURE REAS
Scope: Secure areas within an organization should be designed and implemented as a result of
business or organizational requirements. These areas should possess strong physical controls, and
management should develop and publish requirements for working in secure areas.
Key Risk Indicator: No
Control Class: (M) Management, (O) Operations
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.
Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 3 of 9
Key Questions:
If your organization has secure areas, currently what controls are in place to maintain the
security and integrity of such areas?
What type of access or authorization requirements does management require for secure
areas?
Is access to secure areas monitored? If so, how?
Is access to secure areas auditable via paper or electronic logs?
Additional Information: An organization can have secure areas for reasons unrelated to
information security (e.g., personnel safety reasons, storing new equipment or purchases). No
matter the reason, secure areas should have strong physical controls that are routinely monitored
and have the ability to be audited.
9.1.6 — P A , D , L AUBLIC CCESS ELIVERY AND OADING REAS
Scope: Public areas such as reception, delivery, and loading or other similar areas should be
controlled with physical controls and monitored.
Key Risk Indicator: No
Control Class: (O) Operations
Key Questions:
How does your organization keep unauthorized people from entering the main facility from
public areas such as reception, loading, and delivery?
What types of controls are in place to enter the main facilities from public access areas?
Are incoming shipments and materials inspected for threats before they are moved inside the
main facility?
EQUIPMENT SECURITY
Network- and computer-related equipment plays a vital role in the operations and success of
organizations. Controls must be developed and implemented to prevent this type of equipment
from theft or compromise. The seven controls within this subsection help protect networking and
computer equipment from environmental and physical threats, thereby reducing the risk of
unauthorized access or compromise.
9.2.1 — E S PQUIPMENT ITING AND ROTECTION
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.
Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 4 of 9
Scope: This control is designed to protect networking and computer equipment from
environmental and physical threats that may exist within the organization.
Key Risk Indicator: No
Control Class: (O) Operations
Key Questions:
What methods and measures does management take to protect networking assets and
computer systems from unauthorized access and environmental hazards?
What controls exist today to prevent unauthorized removal of computer systems and
networking components from secured areas or facilities?
Is there a written policy preventing eating and drinking in the data center or computer
processing facility?
Are temperature and humidity monitored in the computer processing facility?
Additional Information: Depending on the size and operations of the organization, a computer
processing facility could range from a small locked room to a full-blown data center spanning
thousands of square feet. The depth of controls implemented per this objective will range
depending on the complexity of the computer processing facilities.
9.2.2 — S UUPPORTING TILITIES
Scope: Management should protect information processing systems and facilities from
uninterrupted power and utility failures.
Key Risk Indicator: No
Control Class: (O) Operations
Key Questions:
What methods has management implemented to protect the utilities (electric, gas, water,
heating, ventilation, etc.) supporting core information processing systems and facilities?
Has the organization implemented an uninterruptible power supply (UPS) or backup
generator appropriate for organizational needs?
How frequently is the UPS or generator tested?
Does the organization have a contract with a local firm to supply fuel or other resources in
the event of a sustained outage?
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.
Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 5 of 9
Additional Information: It is always a good idea to have multiple power feeds to the
information processing facilities to help avoid a single point of failure in the power supply to the
facilities.
9.2.3 — C SABLING ECURITY
Scope: Networking and telecommunications cables should be protected from harm as well as
from unauthorized tampering.
Key Risk Indicator: No
Control Class: (O) Operations
Key Questions:
Are the power and telecommunications cabling going into the information processing
facilities underground?
In public areas, is network cabling protected from unauthorized tampering with conduit or
other similar means?
Are wiring closets secured via a manual or electronic lock to keep unauthorized users away
from the cabling?
9.2.4 — E MQUIPMENT AINTENANCE
Scope: Key systems and hosts in the information processing facility should be maintained
according to manufacturer guidelines to ensure their availability for authorized users.
Key Risk Indicator: No
Control Class: (O) Operations
Key Questions:
Does management maintain service contracts on the hardware components of all critical
computing, networking, and telecommunication systems?
How does your organization ensure that only authorized maintenance personnel are allowed
access to equipment in the information processing facility?
· If appropriate, what controls has management implemented for systems and devices that
house confidential information and data when maintenance personnel are repairing or
maintaining this equipment?
9.2.5 — S E -PECURITY OF QUIPMENT OFF REMISES
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.
Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 6 of 9
Scope: If the organization has information processing equipment off site for what-ever reason, its
operation should be authorized by management and properly secured as a result of a risk
assessment.
Key Risk Indicator: No
Control Class: (O) Operations
Key Questions:
Does management require a documented information security risk assessment for
information processing systems located outside of organizational facilities?
How does management implement appropriate controls to protect data and information being
processed or stored on these systems?
What controls are in place today to prevent unauthorized access or tampering with these
systems and equipment?
9.2.6 — S D R EECURE ISPOSAL OR EUSE OF QUIPMENT
Scope: Management should require and ensure that licensed software has been properly removed
from all forms of computing devices and systems containing storage media and that any data has
been securely disposed of prior to disposal or reuse of equipment.
Key Risk Indicator: Yes
Control Class: (O) Operations
Key Questions:
Describe how your organization disposes of old or unwanted computing or other devices that
have organizational data and information stored on them.
What procedures are in place today for systems that are reused within your organization?
Additional Information: Many organizations use a third-party organization to dispose of
outdated or unwanted systems. It is normal and customary for these organizations to provide your
firm with a certificate of destruction. These certificates should be maintained for whatever term
management and legal counsel have determined is appropriate for your organization.
9.2.7 — R PEMOVAL OF ROPERTY
Scope: Computing systems, software, or other devices containing organizational information and
data should not be removed from the organization without management authorization.
Key Risk Indicator: No
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.
Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 7 of 9
Control Class: (M) Management, (O) Operations
Key Questions:
Has management published a policy notifying all users that equipment or systems containing
the organization’s software or information/data should not be removed from the facility
without proper management authorization?
How does the organization ensure that users are not improperly removing equipment and
systems?
When equipment has been properly authorized for off-site use, is there a control in place that
ensures the asset will be returned by a particular time?
SUMMARY
The “Physical and Environmental Security” clause has two control objectives focusing on secure
areas (9.1) and equipment security (9.2). Perimeter security controls (9.1.1) are fundamental and
critical to protect an organization and its assets. A layered approach is taken with physical and
environmental security, just as it should be in the logical realm. After establishing strong
perimeter controls, a series of entry controls (9.1.2) should be developed, implemented, and
monitored as appropriate for the organization. As needed, offices, rooms, and other areas housing
sensitive or critical systems (9.1.3) should be protected by physical controls as well.
In many cases, organizations reside in a shared facilities environment or operate in very close
proximity to other organizations. In these cases, it is important to develop and implement controls
protecting against the threats posed by external parties and other environmental elements (9.1.4).
Management should develop and implement secure areas (9.1.5) within the organization as
appropriate. Employees or other authorized users should operate or possess knowledge of these
areas on a need-to-know basis. Any type of public access area (9.1.6), such as reception, loading,
unloading, or other similar areas, should be closely monitored and have strong controls leading
into the secured facilities.
Equipment must be properly identified (9.2.1) to be protected. Information processing facilities
and the associated systems and components rely on several basic utilities (9.2.2) such as air-
conditioning, heating, water, sewer, and others to operate. The systems and hosts within the
information processing facilities rely on cabling (9.2.3) to operate as designed. This cable should
be protected from damage and unauthorized tampering. Computer systems, applications,
networking devices, and telecommunications equipment need to be maintained and repaired like
any other equipment. When the equipment requires repair or maintenance (9.2.4), management
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.
Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 8 of 9
should have implemented the appropriate balance of controls to protect these assets from theft,
interruption of services, and unauthorized tampering. If the organization has any equipment or
systems operating off site (9.2.5), management should ensure that the equipment is secured with
the same level of controls and safeguards as the primary equipment and systems. Eventually,
systems and network devices need to be replaced or updated. When this occurs, management
must have implemented a policy, process, and method to ensure that any data and information is
properly destroyed or removed before the equipment is taken out of commission or repurposed
(9.2.6). From time to time it may be necessary to remove key systems or components from the
organization or from the information processing facility. In these cases, management should have
a written and documented process to allow equipment to be taken off site (9.2.7).
REFERENCES
ISO/IEC 17799:2005 Information Technology — Security Techniques — Code of Practice for Information
Security Management, International Organization for Standardization, 2005.
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.
Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 9 of 9