It is important to note that physical controls do not provide any protection against malicious software or other malicious entities that may be residing on or have access to the system. In order to prevent tampering with patch panels, fiber distribution panels and structured wiring, any such enclosures need to be placed within at least lockable commercial cabinets. Furthermore, keys for such cabinets should not be remain in locks as this defeats the purpose of using lockable commercial cabinets in the first place. 11.4. IT Equipment Objective: Mandatory Control 1: T equipment is secured outside of normal working hours, is non‐ operational or when work areas are unoccupied Agencies must account for all IT equipment containing media IT equipment containing medias includes but is not limited to workstations, printers, photocopiers, scanners and multi‐function devices (MFDs). Additional information relating to IT equipment and media can be found in the following chapters and sections of this manual: Section 14.1 ‐ Fax Machines, Multifunction Devices and Network Printers Chapter 15 ‐ Product Security Chapter 16 – Decommissioning and Disposal Ensuring that IT equipment containing media is accounted for by using asset registers, equipment registers, operational & configuration records and regular audits will assist in preventing loss or theft, or in the cases of loss or theft, alerting appropriate authorities to its loss or theft. Asset registers may not provide a complete record as financial limits may result in smaller value items not being recorded. In such cases other registers and operational information can be utilized to assist in building a more complete record. 11.5. Tamper Evident Seals Objective: Recommended Control 1: Tamper evident seals and associated auditing processes identify attempts to bypass the physical security of systems and their infrastructure Agencies should record the usage of seals in a register that is appropriately secured 49

Select target paragraph3