UNCLASSIFIED 7.5 Equipment Security In accordance with US ISO/IEC 27001, organisations must protect equipment against physical and environmental threats. The security measures help reduce the risk of unauthorised access to information and loss or damage to equipment. The measures have strong importance to equipment used offsite. Organisations must also protect supporting facilities such as electrical supply and cabling infrastructure. Equipment security aims to achieve the security outcomes below. PH4 – Organisations must implement appropriate measures to prevent the physical loss, damage, theft or compromise of equipment and infrastructure supporting critical infrastructure. As a minimum requirement, organisations must: (a) locate all production equipment within the access-controlled boundaries of the data centre; (b) protect power and telecom cabling against interception or damage; (c) use reliable electrical power supply; and, (d) manage risks to off-site equipment, information or software. To achieve the security outcomes mandated above, organisations must:  Host all production computer systems such as servers, desktops, firewalls, etc in the secure areas of the data centre to prevent unauthorised access;  Position devices processing sensitive data such as displays in a way that reduces the viewing opportunities of unauthorised persons during their use;  Protect power lines supporting IT services and telecommunications wiring against unauthorised access, damage or disruption through tapping. Where possible, locate cabling underground and use protective shielding;  Have in place controls to minimise the risk of potential physical threats, e.g. theft, fire, explosives, smoke, water (or water supply failure), dust, vibration, chemical effects, electrical supply interference, communications interference, electromagnetic radiation, and vandalism;  Establish and enforce guidelines for eating, drinking, and smoking in proximity to information processing facilities;  Monitor environmental conditions, such as temperature and humidity for conditions, which could adversely affect information processing facilities;  Have in place measures to protect power and telecom cabling against interception or damage by installing lightning protection to all buildings and fitting lightning filters to incoming power and communications lines; and  Address risk of off-site equipment, information and software in accordance with the guidelines outlined in section 6.10 – Remote Access Security. 50

Select target paragraph3