Page 3.10 Physical and Environmental ICT Security 3.10.1 Physical Security Perimeter 3 - 29 3.10.2 Physical Entry Controls 3 - 29 3.10.3 Secure Area 3 - 30 3.10.4 Working in a Secure Area 3 - 30 3.10.5 Site Protection for Data Centre and Computer Room 3 - 31 3.10.6 Equipment Protection 3 - 31 3.10.6.1 Hardware Protection 3 - 31 3.10.6.2 Storage Media Protection 3 - 31 3.10.6.3 Documentation Protection 3 - 32 3.10.6.4 Cabling Protection 3 - 32 Environmental Security 3 - 32 3.10.7.1 Environmental Control 3 - 32 3.10.7.2 Power Supply 3 - 33 3.10.7.3 Emergency Procedures 3 - 33 3.10.7 3.11 3 - 29 Cryptography 3 - 33 3.11.1 Symmetric (or Secret) Key Systems 3 - 34 3.11.2 Asymmetric (or Public) Key Systems 3 - 34 3.11.3 Key Management Issues 3 - 35 3.11.4 Disaster Cryptography and Cryptographic Disasters 3 - 35 3.11.4.1 Disaster Cryptography 3 - 35 3.11.4.2 Cryptographic Disasters 3 - 36 3.11.4.3 What to do in the event of a Cryptographic Disaster 3 - 36 3.12 Public Key Infrastructure (PKI) 3 - 37 3.13 Trusted Third Parties (TTP) 3 - 38 3.13.1 Assurance 3 - 38 3.13.2 Services of a TTP 3 - 39 3.13.3 Legal Issues 3 - 39 Chapter 4 TECHNICAL OPERATIONS 4 - 1 4.1 Computer Systems 4 - 1 4.1.1 Change Control 4 - 1 4.1.2 Equipment Maintenance 4 - 2 4.1.3 Disposal of Equipment 4 - 2 ix

Select target paragraph3