Objective:
Mandatory Control 3:
Mandatory Control 4:
Recommended Control 1:
Secured server and communications rooms provide appropriate
physical security for servers and network devices
are appropriately controlled
Agencies must notleave server rooms, communications rooms or
security containers in an unsecured state unless the server room is
occupied by authorised personnel
Agencies must develop a Site Security Plan (SitePlan) for each
server and communications room. Information to be covered
includes, but is not limited to:
a summary of the security risk review for the facility the
server or communications room is located in
roles and responsibilities of facility and security personnel
the administration, operation and maintenance of the
electronic access control system or security alarm system
key management, the enrolment and removal of system
users and issuing of personal identification number codes
and passwords
regular inspection of the generated audit trails and logs
end of day checks and lockup
reporting of information security incidents
what activities to undertake in response to security alarms
Agencies should use a secured server or communications room
within a secured facility
Site security plans (SitePlan), the physical security equivalent of the SecPlan and SOPs for systems,
are used to document all aspects of physical security for systems. Formally documenting this
information ensures that standards, controls and procedures can easily be reviewed by security
personnel.
11.3.
Network Infrastructure
Objective:
Recommended Control 1:
Network infrastructure is protected by secure facilities
Agencies should locate patch panels, fiber distribution panels and
structured wiring enclosures within at least lockable commercial
cabinets
Network infrastructure is considered to process information being communicated across it.
48