Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 22

IT Security Management

Physical Security
What to Learn

Design Concepts of
Physical Security

Physical Threats

Source: https://www.pexels.com/photo/royal-guard-standing-near-lamp-post-1427581/
Site and Facility Design

Secure Facility Plan


Site Selection
Visibility
Natural Disasters
Facility Design
Physical Security Implementation

Deterrence (boundary)
Denial (locked doors)
Detection (motion
sensors)
Delay (asset locks)

Source: https://www.pexels.com/photo/door-green-closed-lock-4291/
Wiring Closets
Refrain from using the wiring closet as storage
Ample amount of locks
Tidy area
No flammable items nearby
CCTV
Physical inspections
Server Rooms
Must be located at the core of the building
Server rooms should be designed to support optimal
operations
Block unauthorized human access
Evidence Storage

Records of digital events


Retain image copies of drives
Snapshots of virtual machines
No Internet access
Encrypt all datasets stored
Restricted & Work Area Security

Non-equal access to all locations


Allocate access based on requirements
Confidential assets at the centre of the facility
Assign classifications to areas similar to IT
assets.
Data Center Security

Smartcards
Proximity Readers
Intrusion Alarms
CCTV
Emanation Security

Faraday cage
White noise
Control zone
HVAC

Use of UPS
Surge Protectors
Electric generators
Noise

Electromagnetic Interference

Radio Frequency Interference


Temperature, Humidity and Static

Ideal temperature: 15-23 degree Celsius


Humidity: 40-60%
Water Issues

Water can damage IT equipment


Be familiar with the drainage systems
Consider to design:
‒ Facility location
‒ Drainage
‒ Flooding history
‒ Basement
Fire Prevention, Detection & Suppression

Extinguisher

Detection systems
Physical Access Control
Perimeter
Fence, Gates, Mantraps
Lighting
Guards & Dogs
Keys and Locks
Badges
Motion Detectors
Intrusion Alarms
Secondary Verifications
Taxonomy of Security Control

Administrative

Technical

Physical
Administrative Controls

Facility construction and selection


Site management
Personnel controls
Awareness training
Emergency response and procedures
Technical Controls
Access controls
Intrusion detection
Alarms
CCTV
Monitoring
HVAC
Power supplies
Fire detection and suppression
Physical Control

Fencing
Lighting
Locks
Construction materials
Mantraps
Dogs
Guards
Summary

Cyber security is meaningless without


physical security!

Design of IT infrastructure is crucial

Last but not least, personnel safety should be


the first priority.
References

Physical Security

CISSP : Certified Information systems Security Professional ; study gui


de by James Michael Stewart, Ed
Tittel, Mike Chappleand Why It Is Important by David Hutter, 2016

Fire Triangle: https://en.wikipedia.org/wiki/Fire_triangle

You might also like