Special attention to physical access security should be given in the cas e of buildings holding
assets for multiple organizations.
The application of physical controls, especially for the secure areas, should be adapted to the
technical and economic circumstances of the organization, as set forth in the risk assessment.
(NL ISO/IEC, 2015)
5. Physical Entry Controls
Secure areas should be protected by appropriate entry controls to ensure that only authorized
personnel are allowed access.
The following guidelines should be considered:
a) the date and time of entry and departure of visitors should be recorded, and all
visitors should be supervised unless their access has been previously approved; they
should only be granted access for specific, authorized purposes and should be issued
with instructions on the security requirements of the area and on emergency
procedures;
b) access to areas where confidential information is processed or stored should be
restricted to authorized individuals only by implementing appropriate access
controls, e.g. by implementing a two-factor authentication mechanism such as an
access card and secret PIN;
c) a physical log book or electronic audit trail of all access should be securely
maintained and monitored;
d) all employees, contractors and external parties should be required to wear some
form of visible identification and should immediately notify security personnel if
they encounter unescorted visitors and anyone not wearing visible identification;
e) external party support service personnel should be granted restricted access to
secure areas or confidential information processing facilities only when required;
this access should be authorized and monitored;
f) access rights to secure areas should be regularly reviewed and updated, and revoked
when necessary.
(NL ISO/IEC, 2015)
6. Securing Offices, Rooms and Facilities
Physical security for offices, rooms and facilities should be designed and applied.
The following guidelines should be considered to secure offices, rooms and
facilities:
a) key facilities should be sited to avoid access by the public;
b) where applicable, buildings should be unobtrusive and give minimum
indication of their purpose, with no obvious signs, outside or inside
the building, identifying the presence of information processing activities;
Lebanese National Security Policy Guidelines v1.7
Page
34 |