UNCLASSIFIED
7.4
Internal Data Centre Physical Access Controls
Internal areas of information processing facilities require additional physical
security controls because this is where sensitive information is processed or
stored. The internal areas include the data centre, communication and switching
centres and end-user areas. The areas require more stringent personnel security
controls to safeguard the information processed therein. Organisations must
develop a general access control policy for use in the data centre to achieve the
following mandated minimum security outcomes.
PH3 – Organisations must implement appropriate internal physical security
controls to defend critical infrastructure against physical attacks. As a minimum
requirement, organisations must match the value, sensitivity and criticality of
assets with: (a) data centre classifications; (b) data centre location
requirements; (c) infrastructure and perimeter security measures; (d) access
controls; (e) access control logging levels; (f) package handling mechanisms;
(g) visitor management systems; and, (h) tape handling approach.
To achieve the security outcomes mandated above, organisations must:
Classify data centres according to their criticality to the continued operation
of one or major business activities. The categories may be as simple as A
(TOP SECRET); B (SECRET); and C (RESTRICTED);
Use the data centre classifications to guide location decisions. For example,
due to their criticality, class A data centres may be located in a separate
building with a fenced perimeter etc. Based on business needs an
organisation may specify the minimum distance, for example a Class C data
centre may be in the same building or city as the production site;
Use the data centre classifications to determine data centre infrastructure,
access control and access logging, package, visitor and tape handling
requirements. For example, class A data centre may require security staff to
monitor activity via CCTV, limited interior and external visibility from the
computer and motion detection;
Ensure that sites processing, storing or handling classified information have
secure rooms with an Intruder Detection System (IDS) installed. Security
must respond to IDS alerts in a timely manner;
Ensure that personnel only know of the existence of, or activities within, a
secure area on a Need-to-Know basis;
Avoid unsupervised working in secure areas both for safety reasons and to
reduce opportunities for malicious activities;
Physically lock and periodically check vacant secure areas; and
Unless authorised for a business purpose, ban the use of photographic,
video, audio or other recording equipment, such as cameras on mobile
devices in sensitive secure rooms. Based on security needs, users may have
to surrender such devices at the security desk when visiting secure areas.
49