Page
3.10 Physical and Environmental ICT Security
3.10.1
Physical Security Perimeter
3 - 29
3.10.2
Physical Entry Controls
3 - 29
3.10.3
Secure Area
3 - 30
3.10.4
Working in a Secure Area
3 - 30
3.10.5
Site Protection for Data Centre and Computer Room
3 - 31
3.10.6
Equipment Protection
3 - 31
3.10.6.1 Hardware Protection
3 - 31
3.10.6.2 Storage Media Protection
3 - 31
3.10.6.3 Documentation Protection
3 - 32
3.10.6.4 Cabling Protection
3 - 32
Environmental Security
3 - 32
3.10.7.1 Environmental Control
3 - 32
3.10.7.2 Power Supply
3 - 33
3.10.7.3 Emergency Procedures
3 - 33
3.10.7
3.11
3 - 29
Cryptography
3 - 33
3.11.1
Symmetric (or Secret) Key Systems
3 - 34
3.11.2
Asymmetric (or Public) Key Systems
3 - 34
3.11.3
Key Management Issues
3 - 35
3.11.4
Disaster Cryptography and Cryptographic Disasters
3 - 35
3.11.4.1
Disaster Cryptography
3 - 35
3.11.4.2
Cryptographic Disasters
3 - 36
3.11.4.3
What to do in the event of a Cryptographic
Disaster
3 - 36
3.12 Public Key Infrastructure (PKI)
3 - 37
3.13 Trusted Third Parties (TTP)
3 - 38
3.13.1
Assurance
3 - 38
3.13.2
Services of a TTP
3 - 39
3.13.3
Legal Issues
3 - 39
Chapter 4 TECHNICAL OPERATIONS
4 - 1
4.1
Computer Systems
4 - 1
4.1.1
Change Control
4 - 1
4.1.2
Equipment Maintenance
4 - 2
4.1.3
Disposal of Equipment
4 - 2
ix