UNCLASSIFIED PH1 – All organisations must have appropriate security perimeters to shield facilities hosting critical infrastructure against a range of physical security threats including crime, natural disasters and acts of terrorism. As a minimum requirement, organisations must: (a) allocate physical security roles and responsibilities in particular designate a security controller; (b) conduct physical security risk assessments before site selection; (c) design into or require changes to a site’s security; (d) have effective access controls; (e) log and review access; (f) prepare for, detect and respond to physical incidents. To achieve the security outcomes mandated above, organisations must: 7.3  Allocate physical security roles to facilities hosting critical infrastructure. In common with information and personnel security, the Information Risk Owner shall have overall responsibility for physical security risk management at Board-level. The Information Risk Owner should appoint a Security Controller to oversee day-to-day security aspects of a facility or group of facilities. The Controller shall be Ugandan and either full-time or part-time depending on business needs, costs and risks including national security;  Have in place a physical security policy that describes in appropriate detail how the organisation would define, apply and evidence physical security controls in all its locations in accordance with US ISO/IEC 27001:2005;  Ensure that no classified GoU data is processed, stored or transmitted to and from any facility without a full risk assessment and formal approval from the GoU client and relevant GoU national security agencies;  Choose the data centre site carefully taking into consideration issues such as its visibility; proximity to hazards and crime; natural disasters; transportation; access to environmental controls and emergency services;  Ensure that the site is designed securely with careful consideration for wall height and fire rating; ceiling fire and weight bearing ratings; door and window design and strength; electricity and environmental controls;  Clearly define the perimeter and ensure that its location and strength corresponds with the security requirements of the assets within the boundary and the results of a risk assessment;  Ensure that the perimeters are physically sound with no gaps to enable easy break-in. In addition, external walls of the site must be of solid construction with all external doors suitably protected against unauthorised access with control mechanisms, e.g. bars, alarms, locks etc; and  Ensure that Security Standard No. 5 – Physical Security (SS5) and referenced material therein are the main source of guidance on physical security matters. Physical Entry Controls Secure areas within information processing facilities must have appropriate entry controls to stop unauthorised personnel from gaining access. In keeping with the 47

Select target paragraph3