11.
Physical Security
11.1.
Facilities
Objective:
Mandatory Control 1:
Physical security measures are applied to facilities protect
systems and their infrastructure
Agencies must ensure that any facility containing a system or its
associated infrastructure, including deployable systems, are
certified and accredited in accordance with the Physical Security
Requirements
The certification of an agency’s physical security measures is an essential part of the certification
and accreditation process. High Level information relating to physical security is contained in
ISO/IEC 27002:2013.
The application of defense‐in‐depth to the protection of systems and infrastructure is enhanced
through the use of successive layers of physical security. Typically the layers of security are:
site
building
room
racks
approved containers
operational hours.
All layers are designed to control and limit access to those with the appropriate authorization for
the site, infrastructure and system. Deployable platforms need to meet physical security
certification requirements as with any other system. Physical security certification authorities
dealing with deployable platforms may have specific requirements that supersede the requirements
of this manual and as such security personnel should contact their appropriate physical security
certification authority to seek guidance.
11.2.
Servers and Network Devices
Objective:
Mandatory Control 1:
Mandatory Control 2:
Secured server and communications rooms provide appropriate
physical security for servers and network devices
Agencies must ensure that servers and network devices are
secured within cabinets as outlined by GOB
Agencies must ensure that keys or equivalent access mechanisms
to server rooms, communications rooms and security containers
47