7
Physical Security
Physical security is about stopping unauthorised physical access, damage, and
interference to information, premises and resources by a range of physical
security threats including crime, espionage, natural disasters and acts of
terrorism. It also protects personnel against violence and other sorts of harm.
7.1.1
Physical Security, Governance and Risk Management
The themes contained in “Part I – Security Governance” apply to the physical
security functional area. For example, physical security also adopts the PDCA
continuous improvement model to structure all its governance processes.
Indeed, physical security measures are more effective when considered at all
phases of the broader organisational security programme. Physical security is
harder and more expensive to ‘bolt-on’ after the event. Physical security also
complies with mandated minimum security requirements on risk management
contained in the Governance section of this policy. Thus, good physical security
measures match business and security needs.
7.1.2
Physical Security in Context
Physical security measures work alongside and indeed are the bedrock of other
areas of security such as information and personnel security. Physical security
represented the bulk of security measures in the mainframe era. Organisations
invested substantial sums of money to restrict personnel access, used locks and
alarms and implemented environmental controls to cool the giant machines. It all
changed when computers became cheaper and smaller. For example, section
6.10 shows that remote access increases the risks of equipment and data theft
because it occurs in exposed environments such as homes or when travelling.
7.2
Physical Security Perimeter
This policy requires organisations to put in place an adequate physical perimeter
around sensitive information processing facilities to stop unauthorised physical
access. A perimeter is the whole area surrounding the building hosting protected
computer assets including roads, footpaths and any other areas just outside the
building. The physical security perimeter is the first layer of a ‘layered’ or
‘defence-in-depth’ approach to security that progressively increases the difficulty
of security controls the closer one gets to areas containing sensitive information
assets. As noted earlier, the physical security controls that the perimeter
enforces must align with business needs and be cost-effective. The costs of the
controls must not substantially outstrip the impact of loss. If the costs outstrip the
impact of loss, organisations should consider avoiding the risk, for example by
moving the assets to data centres that are easier to secure. By minimising the
risk of theft, destruction and unauthorised access, the security perimeter can
help achieve the following mandated minimum security outcomes.