UNCLASSIFIED 7.4 Internal Data Centre Physical Access Controls Internal areas of information processing facilities require additional physical security controls because this is where sensitive information is processed or stored. The internal areas include the data centre, communication and switching centres and end-user areas. The areas require more stringent personnel security controls to safeguard the information processed therein. Organisations must develop a general access control policy for use in the data centre to achieve the following mandated minimum security outcomes. PH3 – Organisations must implement appropriate internal physical security controls to defend critical infrastructure against physical attacks. As a minimum requirement, organisations must match the value, sensitivity and criticality of assets with: (a) data centre classifications; (b) data centre location requirements; (c) infrastructure and perimeter security measures; (d) access controls; (e) access control logging levels; (f) package handling mechanisms; (g) visitor management systems; and, (h) tape handling approach. To achieve the security outcomes mandated above, organisations must:  Classify data centres according to their criticality to the continued operation of one or major business activities. The categories may be as simple as A (TOP SECRET); B (SECRET); and C (RESTRICTED);  Use the data centre classifications to guide location decisions. For example, due to their criticality, class A data centres may be located in a separate building with a fenced perimeter etc. Based on business needs an organisation may specify the minimum distance, for example a Class C data centre may be in the same building or city as the production site;  Use the data centre classifications to determine data centre infrastructure, access control and access logging, package, visitor and tape handling requirements. For example, class A data centre may require security staff to monitor activity via CCTV, limited interior and external visibility from the computer and motion detection;  Ensure that sites processing, storing or handling classified information have secure rooms with an Intruder Detection System (IDS) installed. Security must respond to IDS alerts in a timely manner;  Ensure that personnel only know of the existence of, or activities within, a secure area on a Need-to-Know basis;  Avoid unsupervised working in secure areas both for safety reasons and to reduce opportunities for malicious activities;  Physically lock and periodically check vacant secure areas; and  Unless authorised for a business purpose, ban the use of photographic, video, audio or other recording equipment, such as cameras on mobile devices in sensitive secure rooms. Based on security needs, users may have to surrender such devices at the security desk when visiting secure areas. 49

Select target paragraph3