Discussion and Replies

profileCyberSter
Information_Security_Design_Implementation_Measure..._----_Chapter_11_Physical_and_Environmental_Security.pdf

11

Physical and Environmental

Security Physical and environmental controls are some of the most critical safeguards an organization can

implement based on results. Physical controls are historically among the most breached controls.

Secure areas and equipment security concepts have been around for a long time and are some of

the most widely accepted methods for security. If this last statement is generally true, why are

there so many physical breaches of information security controls?

So much attention is focused on high-tech controls, and the bulk of the budget dollars are

typically spent in this area as well, that some of the most basic, yet effective, controls can be

overlooked.

The thirteen controls and two control objectives should be reviewed very closely by every

organization, and management should ensure that they are implemented and operating at a high

level of effectiveness. They are some of the most straightforward and simple controls to

implement and will continue to prove to be some of the most effective for controlling common

threats.

SECURE AREAS

This control objective is designed to help organizations prevent security breaches and damages to

the organization’s facilities and ultimately their information, data, and systems.

9.1.1 — P S PHYSICAL ECURITY ERIMETER

Scope: The organization’s information processing facilities perimeter should be adequately

protected by physical controls such as walls, fences, manned and guarded entry, barriers, access

cards, closed circuit television, etc.

Key Risk Indicator: Yes

Control Class: (O) Operations

Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.

Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 1 of 9

Key Questions:

Has the organization clearly defined security perimeters?

Describe the physical security controls and safeguards in place today to protect the

information processing facility.

Is the information processing facility monitored for fire, smoke, water, and unauthorized

entry?

· Is the building that houses information processing facilities protected by a manned

reception area?

Are visitors to the information processing facilities building(s) required to sign in and be

escorted by an employee at all times when visiting?

Additional Information: In smaller companies, the more elaborate controls and safeguards

might not be available or appropriate. At a minimum, the information processing systems should

be contained in a safe environment with controlled access; preferably this access is auditable and

can be monitored.

9.1.2 — P E CHYSICAL NTRY ONTROLS

Scope: Physical entry controls should be developed and implemented to properly protect secured

areas.

Key Risk Indicator: No

Control Class: (O) Operations

Key Questions:

How does management control access to secured information processing facilities?

Is there an audit trail maintained for secured information processing facilities?

Does management review access rights to secured information processing facilities on a

regular basis?

9.1.3 — S O , R , FECURING FFICES OOMS AND ACILITIES

Scope: Offices and organizational facilities should be secured with appropriate physical controls

as required.

Key Risk Indicator: No

Control Class: (O) Operations

Key Questions:

Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.

Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 2 of 9

How does management identify areas within the organization requiring physical controls?

Are vacant areas within the facilities secured with physical controls and routinely checked to

ensure the integrity of the implemented controls?

What controls are currently in place to control the use of video and audio recording

equipment?

9.1.4 — P A E E TROTECTING GAINST XTERNAL AND NVIRONMENTAL HREATS

Scope: Management of an organization must protect itself and employees from disasters such as

fire, flooding, and explosions, including both natural and man-made events. Physical controls

should be assessed, designed, implemented, and monitored to ensure adequacy and effectiveness

of these controls.

Key Risk Indicator: Yes

Control Class: (M) Management, (O) Operations

Key Questions:

How do employees and users know they are operating in a secure area within the

organization?

How does management remain current with new threats, internal and external, and how they

relate to your organization?

Describe the actions taken by your organization to protect itself from neighboring buildings

or infrastructures.

Does your organization store information or data near materials that could be considered

hazardous or prone to fire or other similar events?

Additional Information: If disaster recovery equipment is housed too close to the main facility,

this may be an issue for concern. Recovery equipment, systems, backup media, and other similar

items should be stored as far away as reasonably possible to be protected from the event that

disrupted operations at the main facility.

9.1.5 — W S AORKING IN ECURE REAS

Scope: Secure areas within an organization should be designed and implemented as a result of

business or organizational requirements. These areas should possess strong physical controls, and

management should develop and publish requirements for working in secure areas.

Key Risk Indicator: No

Control Class: (M) Management, (O) Operations

Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.

Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 3 of 9

Key Questions:

If your organization has secure areas, currently what controls are in place to maintain the

security and integrity of such areas?

What type of access or authorization requirements does management require for secure

areas?

Is access to secure areas monitored? If so, how?

Is access to secure areas auditable via paper or electronic logs?

Additional Information: An organization can have secure areas for reasons unrelated to

information security (e.g., personnel safety reasons, storing new equipment or purchases). No

matter the reason, secure areas should have strong physical controls that are routinely monitored

and have the ability to be audited.

9.1.6 — P A , D , L AUBLIC CCESS ELIVERY AND OADING REAS

Scope: Public areas such as reception, delivery, and loading or other similar areas should be

controlled with physical controls and monitored.

Key Risk Indicator: No

Control Class: (O) Operations

Key Questions:

How does your organization keep unauthorized people from entering the main facility from

public areas such as reception, loading, and delivery?

What types of controls are in place to enter the main facilities from public access areas?

Are incoming shipments and materials inspected for threats before they are moved inside the

main facility?

EQUIPMENT SECURITY

Network- and computer-related equipment plays a vital role in the operations and success of

organizations. Controls must be developed and implemented to prevent this type of equipment

from theft or compromise. The seven controls within this subsection help protect networking and

computer equipment from environmental and physical threats, thereby reducing the risk of

unauthorized access or compromise.

9.2.1 — E S PQUIPMENT ITING AND ROTECTION

Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.

Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 4 of 9

Scope: This control is designed to protect networking and computer equipment from

environmental and physical threats that may exist within the organization.

Key Risk Indicator: No

Control Class: (O) Operations

Key Questions:

What methods and measures does management take to protect networking assets and

computer systems from unauthorized access and environmental hazards?

What controls exist today to prevent unauthorized removal of computer systems and

networking components from secured areas or facilities?

Is there a written policy preventing eating and drinking in the data center or computer

processing facility?

Are temperature and humidity monitored in the computer processing facility?

Additional Information: Depending on the size and operations of the organization, a computer

processing facility could range from a small locked room to a full-blown data center spanning

thousands of square feet. The depth of controls implemented per this objective will range

depending on the complexity of the computer processing facilities.

9.2.2 — S UUPPORTING TILITIES

Scope: Management should protect information processing systems and facilities from

uninterrupted power and utility failures.

Key Risk Indicator: No

Control Class: (O) Operations

Key Questions:

What methods has management implemented to protect the utilities (electric, gas, water,

heating, ventilation, etc.) supporting core information processing systems and facilities?

Has the organization implemented an uninterruptible power supply (UPS) or backup

generator appropriate for organizational needs?

How frequently is the UPS or generator tested?

Does the organization have a contract with a local firm to supply fuel or other resources in

the event of a sustained outage?

Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.

Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 5 of 9

Additional Information: It is always a good idea to have multiple power feeds to the

information processing facilities to help avoid a single point of failure in the power supply to the

facilities.

9.2.3 — C SABLING ECURITY

Scope: Networking and telecommunications cables should be protected from harm as well as

from unauthorized tampering.

Key Risk Indicator: No

Control Class: (O) Operations

Key Questions:

Are the power and telecommunications cabling going into the information processing

facilities underground?

In public areas, is network cabling protected from unauthorized tampering with conduit or

other similar means?

Are wiring closets secured via a manual or electronic lock to keep unauthorized users away

from the cabling?

9.2.4 — E MQUIPMENT AINTENANCE

Scope: Key systems and hosts in the information processing facility should be maintained

according to manufacturer guidelines to ensure their availability for authorized users.

Key Risk Indicator: No

Control Class: (O) Operations

Key Questions:

Does management maintain service contracts on the hardware components of all critical

computing, networking, and telecommunication systems?

How does your organization ensure that only authorized maintenance personnel are allowed

access to equipment in the information processing facility?

· If appropriate, what controls has management implemented for systems and devices that

house confidential information and data when maintenance personnel are repairing or

maintaining this equipment?

9.2.5 — S E -PECURITY OF QUIPMENT OFF REMISES

Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.

Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 6 of 9

Scope: If the organization has information processing equipment off site for what-ever reason, its

operation should be authorized by management and properly secured as a result of a risk

assessment.

Key Risk Indicator: No

Control Class: (O) Operations

Key Questions:

Does management require a documented information security risk assessment for

information processing systems located outside of organizational facilities?

How does management implement appropriate controls to protect data and information being

processed or stored on these systems?

What controls are in place today to prevent unauthorized access or tampering with these

systems and equipment?

9.2.6 — S D R EECURE ISPOSAL OR EUSE OF QUIPMENT

Scope: Management should require and ensure that licensed software has been properly removed

from all forms of computing devices and systems containing storage media and that any data has

been securely disposed of prior to disposal or reuse of equipment.

Key Risk Indicator: Yes

Control Class: (O) Operations

Key Questions:

Describe how your organization disposes of old or unwanted computing or other devices that

have organizational data and information stored on them.

What procedures are in place today for systems that are reused within your organization?

Additional Information: Many organizations use a third-party organization to dispose of

outdated or unwanted systems. It is normal and customary for these organizations to provide your

firm with a certificate of destruction. These certificates should be maintained for whatever term

management and legal counsel have determined is appropriate for your organization.

9.2.7 — R PEMOVAL OF ROPERTY

Scope: Computing systems, software, or other devices containing organizational information and

data should not be removed from the organization without management authorization.

Key Risk Indicator: No

Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.

Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 7 of 9

Control Class: (M) Management, (O) Operations

Key Questions:

Has management published a policy notifying all users that equipment or systems containing

the organization’s software or information/data should not be removed from the facility

without proper management authorization?

How does the organization ensure that users are not improperly removing equipment and

systems?

When equipment has been properly authorized for off-site use, is there a control in place that

ensures the asset will be returned by a particular time?

SUMMARY

The “Physical and Environmental Security” clause has two control objectives focusing on secure

areas (9.1) and equipment security (9.2). Perimeter security controls (9.1.1) are fundamental and

critical to protect an organization and its assets. A layered approach is taken with physical and

environmental security, just as it should be in the logical realm. After establishing strong

perimeter controls, a series of entry controls (9.1.2) should be developed, implemented, and

monitored as appropriate for the organization. As needed, offices, rooms, and other areas housing

sensitive or critical systems (9.1.3) should be protected by physical controls as well.

In many cases, organizations reside in a shared facilities environment or operate in very close

proximity to other organizations. In these cases, it is important to develop and implement controls

protecting against the threats posed by external parties and other environmental elements (9.1.4).

Management should develop and implement secure areas (9.1.5) within the organization as

appropriate. Employees or other authorized users should operate or possess knowledge of these

areas on a need-to-know basis. Any type of public access area (9.1.6), such as reception, loading,

unloading, or other similar areas, should be closely monitored and have strong controls leading

into the secured facilities.

Equipment must be properly identified (9.2.1) to be protected. Information processing facilities

and the associated systems and components rely on several basic utilities (9.2.2) such as air-

conditioning, heating, water, sewer, and others to operate. The systems and hosts within the

information processing facilities rely on cabling (9.2.3) to operate as designed. This cable should

be protected from damage and unauthorized tampering. Computer systems, applications,

networking devices, and telecommunications equipment need to be maintained and repaired like

any other equipment. When the equipment requires repair or maintenance (9.2.4), management

Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.

Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 8 of 9

should have implemented the appropriate balance of controls to protect these assets from theft,

interruption of services, and unauthorized tampering. If the organization has any equipment or

systems operating off site (9.2.5), management should ensure that the equipment is secured with

the same level of controls and safeguards as the primary equipment and systems. Eventually,

systems and network devices need to be replaced or updated. When this occurs, management

must have implemented a policy, process, and method to ensure that any data and information is

properly destroyed or removed before the equipment is taken out of commission or repurposed

(9.2.6). From time to time it may be necessary to remove key systems or components from the

organization or from the information processing facility. In these cases, management should have

a written and documented process to allow equipment to be taken off site (9.2.7).

REFERENCES

ISO/IEC 17799:2005 Information Technology — Security Techniques — Code of Practice for Information

Security Management, International Organization for Standardization, 2005.

Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-05-15 02:00:48.

Copyright © 2006. Auerbach Publishers, Incorporated. All rights reserved. Ebook pages 153-158 | Printed page 9 of 9