National Information Security Policy and Guidelines | Ministry of Home Affairs 14. Physical and environmental security 14.1. Background 14.1.1. Organizations generally have multiple touch points, which may be spread across different geographic regions, from where information can be accessed physically. Thus geographies, locations and facilities play an important role in the security posture of information and information systems 14.1.2. Physical aspects have a role in determining how information and information systems are housed in a facility, who can possibly reach physical systems, which way one can enter or exit from the facility, what can human elements physically do with the system housed in a facility and what will be impact of regional physical events on the particular facilities 14.1.3. Physical security in an important component of information security and requires a careful attention in planning, selecting countermeasures, deploying controls, ensuring secure operations and respond in case of an event 14.1.4. Physical security is not only restricted to barriers or locks but have evolved with the use of access control measures, risk based or multifactor authentications, monitoring cameras, alarms, intrusion detectors, etc. 14.2. Relevance of domain to information security 14.2.1. Lack of due consideration to the area and to the choice of the building may expose information and IT systems to threats. Choice of the area, building architecture and plan have a significant impact on security posture of information and information systems 14.2.2. Insufficient entry controls may give access to unintended persons. It may allow entry of unauthorized assets or easy passage of sensitive assets from premises 14.2.3. Without adequate interior physical control, unauthorized personnel may gain access to sensitive areas. Instances such as theft of information may remain undetected 14.2.4. Without processes for physical access provisioning and deprovisioning, governing access to the sensitive physical locations will remain a challenging task. This will have serious impact on security of information and information during their life cycle in a particular physical facility 14.3. Physical and environmental security guidelines 14.3.1. Map and characteristics of physical facilities: The organization must create an map of access point and information assets and systems housed within G 19 14.3.2. Protection from hazard: The organization must ensure that all facilities housing information systems and assets are provided with adequate physical security measures, which include protection from natural and man-made hazard G 20 14.3.3. Physical boundary protection: The organization must deploy an adequate level of perimeter security measures such as barriers, fencing, protective lighting, etc. G 21 14.3.4. Restricting entry: The organization must deploy an adequate level of countermeasures for restricting the entry to the facilities only to authorized persons G 22 NISPG - Version 5.0 Restricted Page 55

Select target paragraph3