c) facilities should be configured to prevent confidential information or activities from
being visible and audible from the outside;
d) directories and internal telephone books identifying locations of confidential
information processing facilities should not be readily accessible to anyone
unauthorized.
(NL ISO/IEC, 2015)
7. Server Rooms and Data Center Security
Server rooms, data centers, communications rooms, wiring closets, server vaults, and IT closets
are enclosed, restricted, and protected rooms where your mission-critical servers and network
devices are housed. Centralized server rooms need not be human compatible. In fact, the more
human incompatible a server room is, the more protection it will offer against casual and
determined attacks. Human incompatibility can be accomplished by including Halotron,
PyroGen, or other halon-substitute oxygen-displacement fire detection and extinguishing
systems, low temperatures, little or no lighting, and equipment stacked with little room to
maneuver. Server rooms should be designed to support optimal operation of the IT
infrastructure and to block unauthorized human access or intervention.
Server rooms should be located at the core of the building. Try to avoid locating these rooms on
the ground floor, the top floor, and the basement whenever possible. Additionally, the server
room should be located away from water, gas, and sewage lines. These pose too large a risk of
leakage or flooding, which can cause serious damage and downtime. (Stewart et al., 2004)
8. Protecting Against External and Environmental Threats
Physical protection against natural disasters, malicious attack or accidents should be designed
and applied.
Specialist advice should be obtained on how to avoid damage from fire, flood, earthquake,
explosion, civil unrest and other forms of natural or man-made disaster. (NL ISO/IEC, 2015)
9. Working in Secure Areas
Procedures for working in secure areas should be designed and applied.
The following guidelines should be considered:
a) personnel should only be aware of the existence of, or activities within, a secure
area on a need-to-know basis;
b) unsupervised working in secure areas should be avoided both for safety reasons and
to prevent opportunities for malicious activities;
c) vacant secure areas should be physically locked and periodically reviewed;
d) photographic, video, audio or other recording equipment, such as cameras in mobile
devices, should not be allowed, unless authorized.
Lebanese National Security Policy Guidelines v1.7
Page
35 |