Special attention to physical access security should be given in the cas e of buildings holding assets for multiple organizations. The application of physical controls, especially for the secure areas, should be adapted to the technical and economic circumstances of the organization, as set forth in the risk assessment. (NL ISO/IEC, 2015) 5. Physical Entry Controls Secure areas should be protected by appropriate entry controls to ensure that only authorized personnel are allowed access. The following guidelines should be considered: a) the date and time of entry and departure of visitors should be recorded, and all visitors should be supervised unless their access has been previously approved; they should only be granted access for specific, authorized purposes and should be issued with instructions on the security requirements of the area and on emergency procedures; b) access to areas where confidential information is processed or stored should be restricted to authorized individuals only by implementing appropriate access controls, e.g. by implementing a two-factor authentication mechanism such as an access card and secret PIN; c) a physical log book or electronic audit trail of all access should be securely maintained and monitored; d) all employees, contractors and external parties should be required to wear some form of visible identification and should immediately notify security personnel if they encounter unescorted visitors and anyone not wearing visible identification; e) external party support service personnel should be granted restricted access to secure areas or confidential information processing facilities only when required; this access should be authorized and monitored; f) access rights to secure areas should be regularly reviewed and updated, and revoked when necessary. (NL ISO/IEC, 2015) 6. Securing Offices, Rooms and Facilities Physical security for offices, rooms and facilities should be designed and applied. The following guidelines should be considered to secure offices, rooms and facilities: a) key facilities should be sited to avoid access by the public; b) where applicable, buildings should be unobtrusive and give minimum indication of their purpose, with no obvious signs, outside or inside the building, identifying the presence of information processing activities; Lebanese National Security Policy Guidelines v1.7 Page 34 |

Select target paragraph3