National Information Security Policy and Guidelines | Ministry of Home Affairs
14. Physical and environmental security
14.1. Background
14.1.1. Organizations generally have multiple touch points, which may be spread across different
geographic regions, from where information can be accessed physically. Thus geographies,
locations and facilities play an important role in the security posture of information and
information systems
14.1.2. Physical aspects have a role in determining how information and information systems are
housed in a facility, who can possibly reach physical systems, which way one can enter or
exit from the facility, what can human elements physically do with the system housed in a
facility and what will be impact of regional physical events on the particular facilities
14.1.3. Physical security in an important component of information security and requires a careful
attention in planning, selecting countermeasures, deploying controls, ensuring secure
operations and respond in case of an event
14.1.4. Physical security is not only restricted to barriers or locks but have evolved with the use of
access control measures, risk based or multifactor authentications, monitoring cameras,
alarms, intrusion detectors, etc.
14.2. Relevance of domain to information security
14.2.1. Lack of due consideration to the area and to the choice of the building may expose
information and IT systems to threats. Choice of the area, building architecture and plan have
a significant impact on security posture of information and information systems
14.2.2. Insufficient entry controls may give access to unintended persons. It may allow entry of
unauthorized assets or easy passage of sensitive assets from premises
14.2.3. Without adequate interior physical control, unauthorized personnel may gain access to
sensitive areas. Instances such as theft of information may remain undetected
14.2.4. Without processes for physical access provisioning and deprovisioning, governing access to
the sensitive physical locations will remain a challenging task. This will have serious impact on
security of information and information during their life cycle in a particular physical facility
14.3. Physical and environmental security guidelines
14.3.1.
Map and characteristics of physical facilities: The organization must create an
map of access point and information assets and systems housed within
G 19
14.3.2.
Protection from hazard: The organization must ensure that all facilities
housing information systems and assets are provided with adequate physical
security measures, which include protection from natural and man-made
hazard
G 20
14.3.3.
Physical boundary protection: The organization must deploy an adequate
level of perimeter security measures such as barriers, fencing, protective
lighting, etc.
G 21
14.3.4.
Restricting entry: The organization must deploy an adequate level of
countermeasures for restricting the entry to the facilities only to authorized
persons
G 22
NISPG - Version 5.0
Restricted
Page 55