Physical Security Controls for IT Facilities
Learn about physical security controls for data centers and IT facilities that IS auditors evaluate on the CISA exam.
Physical Security Fundamentals
Physical security protects an organization's IT assets, personnel, and facilities from physical threats including unauthorized access, theft, vandalism, and environmental hazards. While cybersecurity often receives more attention, physical security is equally important because physical access to systems can bypass many logical security controls.
Physical Access Controls
Multiple layers of physical access controls protect IT facilities:
- Perimeter Security: Fencing, gates, barriers, lighting, and security cameras control access to the facility grounds and deter unauthorized entry.
- Building Access: Card readers, biometric scanners, security guards, and visitor management systems control who enters the building.
- Data Center Access: The most sensitive areas require additional controls such as mantrap entrances (interlocking doors), multi-factor authentication, and video surveillance with recording.
- Equipment Access: Server cabinets and network equipment should be locked, with access restricted to authorized personnel. Key management procedures should track who has physical keys or access cards.
Environmental Controls
IT equipment requires specific environmental conditions to operate reliably:
- HVAC Systems: Heating, ventilation, and air conditioning systems maintain appropriate temperature and humidity levels. Data centers typically require temperatures between 64 and 80 degrees Fahrenheit with humidity between 40 and 60 percent.
- Fire Detection and Suppression: Smoke detectors, heat sensors, and fire suppression systems protect against fire damage. Clean agent suppression systems (such as FM-200) are preferred for data centers because they do not damage electronic equipment.
- Water Detection: Water sensors under raised floors and near plumbing detect leaks before they damage equipment.
- Power Protection: Uninterruptible power supplies (UPS) protect against power fluctuations, and backup generators provide extended power during outages. Power distribution should include surge protection and proper grounding.
Monitoring and Surveillance
Physical security monitoring includes:
- CCTV Systems: Video surveillance cameras at entry points, sensitive areas, and perimeter locations. Recordings should be retained for a defined period to support incident investigation.
- Alarm Systems: Intrusion detection alarms that alert security personnel to unauthorized entry attempts.
- Security Guards: Trained personnel who monitor access points, patrol facilities, and respond to security events.
- Access Logs: Electronic records of who accessed controlled areas and when. These logs support investigations and compliance requirements.
Audit Considerations
IS auditors should physically inspect facilities to verify that controls are in place and operating effectively. Key areas to evaluate include access control mechanisms, environmental monitoring systems, fire suppression equipment, power protection, and CCTV coverage. Auditors should also review visitor logs, access records, and maintenance schedules.
CISA Exam Tips
For the CISA exam, understand that physical security follows the defense-in-depth principle with multiple layers from perimeter to equipment. Know the types of fire suppression systems and which are appropriate for data centers. Remember that water-based sprinkler systems, while common in office areas, can damage electronic equipment. Questions may ask about the most appropriate physical control for a specific scenario or the proper environmental conditions for a data center.