7 Physical Security Physical security is about stopping unauthorised physical access, damage, and interference to information, premises and resources by a range of physical security threats including crime, espionage, natural disasters and acts of terrorism. It also protects personnel against violence and other sorts of harm. 7.1.1 Physical Security, Governance and Risk Management The themes contained in “Part I – Security Governance” apply to the physical security functional area. For example, physical security also adopts the PDCA continuous improvement model to structure all its governance processes. Indeed, physical security measures are more effective when considered at all phases of the broader organisational security programme. Physical security is harder and more expensive to ‘bolt-on’ after the event. Physical security also complies with mandated minimum security requirements on risk management contained in the Governance section of this policy. Thus, good physical security measures match business and security needs. 7.1.2 Physical Security in Context Physical security measures work alongside and indeed are the bedrock of other areas of security such as information and personnel security. Physical security represented the bulk of security measures in the mainframe era. Organisations invested substantial sums of money to restrict personnel access, used locks and alarms and implemented environmental controls to cool the giant machines. It all changed when computers became cheaper and smaller. For example, section 6.10 shows that remote access increases the risks of equipment and data theft because it occurs in exposed environments such as homes or when travelling. 7.2 Physical Security Perimeter This policy requires organisations to put in place an adequate physical perimeter around sensitive information processing facilities to stop unauthorised physical access. A perimeter is the whole area surrounding the building hosting protected computer assets including roads, footpaths and any other areas just outside the building. The physical security perimeter is the first layer of a ‘layered’ or ‘defence-in-depth’ approach to security that progressively increases the difficulty of security controls the closer one gets to areas containing sensitive information assets. As noted earlier, the physical security controls that the perimeter enforces must align with business needs and be cost-effective. The costs of the controls must not substantially outstrip the impact of loss. If the costs outstrip the impact of loss, organisations should consider avoiding the risk, for example by moving the assets to data centres that are easier to secure. By minimising the risk of theft, destruction and unauthorised access, the security perimeter can help achieve the following mandated minimum security outcomes.

Select target paragraph3