Objective: Mandatory Control 3: Mandatory Control 4: Recommended Control 1: Secured server and communications rooms provide appropriate physical security for servers and network devices are appropriately controlled Agencies must notleave server rooms, communications rooms or security containers in an unsecured state unless the server room is occupied by authorised personnel Agencies must develop a Site Security Plan (SitePlan) for each server and communications room. Information to be covered includes, but is not limited to: a summary of the security risk review for the facility the server or communications room is located in roles and responsibilities of facility and security personnel the administration, operation and maintenance of the electronic access control system or security alarm system key management, the enrolment and removal of system users and issuing of personal identification number codes and passwords regular inspection of the generated audit trails and logs end of day checks and lockup reporting of information security incidents what activities to undertake in response to security alarms Agencies should use a secured server or communications room within a secured facility Site security plans (SitePlan), the physical security equivalent of the SecPlan and SOPs for systems, are used to document all aspects of physical security for systems. Formally documenting this information ensures that standards, controls and procedures can easily be reviewed by security personnel. 11.3. Network Infrastructure Objective: Recommended Control 1: Network infrastructure is protected by secure facilities Agencies should locate patch panels, fiber distribution panels and structured wiring enclosures within at least lockable commercial cabinets Network infrastructure is considered to process information being communicated across it. 48

Select target paragraph3