on deploying concentric circles of physical protection. This type of configuration requires
increased levels of authorization to gain access into more sensitive areas inside the facility.
(Stewart et al., 2004)
4. Physical security perimeter
Security perimeters should be defined and used to protect areas that contain either sensitive or
critical information and information processing facilities.
The following guidelines should be considered and implemented where appropriate for physical
security perimeters:
a) security perimeters should be defined, and the siting and strength of each of the
perimeters should depend on the security requirements of the assets within the
perimeter and the results of a risk assessment;
b) perimeters of a building or site containing information processing facilities should be
physically sound; the exterior roof, walls and flooring of the site should be of solid
construction and all external doors should be suitably protected against
unauthorized access with control mechanisms, (e.g. bars, alarms, locks); doors and
windows should be locked when unattended and external protection should be
considered for windows, particularly at ground level;
c) a manned reception area or other means to control physical access to the site or
building should be in place; access to sites and buildings should be restricted to
authorized personnel only;
d) physical barriers should, where applicable, be built to prevent unauthorized physical
access and environmental contamination;
e) all fire doors on a security perimeter should be alarmed, monitored and tested in
conjunction with the walls to establish the required level of resistance in accordance
with suitable regional, national and international standards; they should operate in
accordance with the local fire code in a failsafe manner;
f) suitable intruder detection systems should be installed to national, regional or
international standards and regularly tested to cover all external doors and
accessible windows; unoccupied areas should be alarmed at all times; cover should
also be provided for other areas, e.g. computer room or communications rooms;
g) information processing facilities managed by the organization should be physically
separated from those managed by external parties.
Physical protection can be achieved by creating one or more physical barriers around the
organization’s premises and information processing facilities. The use of multiple barriers gives
additional protection, where the failure of a single barrier does not mean that security is
immediately compromised.
A secure area may be a lockable office or several rooms surrounded by a continuous internal
physical security barrier. Additional barriers and perimeters to control physical access may be
needed between areas with different security requirements inside the security perimeter.
Lebanese National Security Policy Guidelines v1.7
Page
33 |