11. Physical Security 11.1. Facilities Objective: Mandatory Control 1: Physical security measures are applied to facilities protect systems and their infrastructure Agencies must ensure that any facility containing a system or its associated infrastructure, including deployable systems, are certified and accredited in accordance with the Physical Security Requirements The certification of an agency’s physical security measures is an essential part of the certification and accreditation process. High Level information relating to physical security is contained in ISO/IEC 27002:2013. The application of defense‐in‐depth to the protection of systems and infrastructure is enhanced through the use of successive layers of physical security. Typically the layers of security are: site building room racks approved containers operational hours. All layers are designed to control and limit access to those with the appropriate authorization for the site, infrastructure and system. Deployable platforms need to meet physical security certification requirements as with any other system. Physical security certification authorities dealing with deployable platforms may have specific requirements that supersede the requirements of this manual and as such security personnel should contact their appropriate physical security certification authority to seek guidance. 11.2. Servers and Network Devices Objective: Mandatory Control 1: Mandatory Control 2: Secured server and communications rooms provide appropriate physical security for servers and network devices Agencies must ensure that servers and network devices are secured within cabinets as outlined by GOB Agencies must ensure that keys or equivalent access mechanisms to server rooms, communications rooms and security containers 47

Select target paragraph3