UNCLASSIFIED
PH1 – All organisations must have appropriate security perimeters to shield
facilities hosting critical infrastructure against a range of physical security
threats including crime, natural disasters and acts of terrorism. As a minimum
requirement, organisations must: (a) allocate physical security roles and
responsibilities in particular designate a security controller; (b) conduct physical
security risk assessments before site selection; (c) design into or require
changes to a site’s security; (d) have effective access controls; (e) log and
review access; (f) prepare for, detect and respond to physical incidents.
To achieve the security outcomes mandated above, organisations must:
7.3
Allocate physical security roles to facilities hosting critical infrastructure. In
common with information and personnel security, the Information Risk Owner
shall have overall responsibility for physical security risk management at
Board-level. The Information Risk Owner should appoint a Security
Controller to oversee day-to-day security aspects of a facility or group of
facilities. The Controller shall be Ugandan and either full-time or part-time
depending on business needs, costs and risks including national security;
Have in place a physical security policy that describes in appropriate detail
how the organisation would define, apply and evidence physical security
controls in all its locations in accordance with US ISO/IEC 27001:2005;
Ensure that no classified GoU data is processed, stored or transmitted to and
from any facility without a full risk assessment and formal approval from the
GoU client and relevant GoU national security agencies;
Choose the data centre site carefully taking into consideration issues such as
its visibility; proximity to hazards and crime; natural disasters; transportation;
access to environmental controls and emergency services;
Ensure that the site is designed securely with careful consideration for wall
height and fire rating; ceiling fire and weight bearing ratings; door and
window design and strength; electricity and environmental controls;
Clearly define the perimeter and ensure that its location and strength
corresponds with the security requirements of the assets within the boundary
and the results of a risk assessment;
Ensure that the perimeters are physically sound with no gaps to enable easy
break-in. In addition, external walls of the site must be of solid construction
with all external doors suitably protected against unauthorised access with
control mechanisms, e.g. bars, alarms, locks etc; and
Ensure that Security Standard No. 5 – Physical Security (SS5) and
referenced material therein are the main source of guidance on physical
security matters.
Physical Entry Controls
Secure areas within information processing facilities must have appropriate entry
controls to stop unauthorised personnel from gaining access. In keeping with the
47