UNCLASSIFIED
7.5
Equipment Security
In accordance with US ISO/IEC 27001, organisations must protect equipment
against physical and environmental threats. The security measures help reduce
the risk of unauthorised access to information and loss or damage to equipment.
The measures have strong importance to equipment used offsite. Organisations
must also protect supporting facilities such as electrical supply and cabling
infrastructure. Equipment security aims to achieve the security outcomes below.
PH4 – Organisations must implement appropriate measures to prevent the
physical loss, damage, theft or compromise of equipment and infrastructure
supporting critical infrastructure. As a minimum requirement, organisations
must: (a) locate all production equipment within the access-controlled
boundaries of the data centre; (b) protect power and telecom cabling against
interception or damage; (c) use reliable electrical power supply; and, (d)
manage risks to off-site equipment, information or software.
To achieve the security outcomes mandated above, organisations must:
Host all production computer systems such as servers, desktops, firewalls,
etc in the secure areas of the data centre to prevent unauthorised access;
Position devices processing sensitive data such as displays in a way that
reduces the viewing opportunities of unauthorised persons during their use;
Protect power lines supporting IT services and telecommunications wiring
against unauthorised access, damage or disruption through tapping. Where
possible, locate cabling underground and use protective shielding;
Have in place controls to minimise the risk of potential physical threats, e.g.
theft, fire, explosives, smoke, water (or water supply failure), dust, vibration,
chemical effects, electrical supply interference, communications interference,
electromagnetic radiation, and vandalism;
Establish and enforce guidelines for eating, drinking, and smoking in
proximity to information processing facilities;
Monitor environmental conditions, such as temperature and humidity for
conditions, which could adversely affect information processing facilities;
Have in place measures to protect power and telecom cabling against
interception or damage by installing lightning protection to all buildings and
fitting lightning filters to incoming power and communications lines; and
Address risk of off-site equipment, information and software in accordance
with the guidelines outlined in section 6.10 – Remote Access Security.
50