Physical Access Controls in Information Technology (IT) Security
To help prevent unauthorized access or damage to your network or your sensitive data, management can develop a security program that includes a combination of physical, electronic and management controls. Items to consider include, but are not limited to:
Building security
Entry into your facility by unauthorized persons could result in theft of and compromise to, among other things, your computers and business intelligence and data. Providing physical security to the building exterior can be a first step to protecting against unauthorized entry. Keep doors and windows locked. Have a written program for key control and retrieval. Re-key locks whenever a key is lost.
Security alarms also play an important role in your physical security. Consider installing a building electronic security system that includes a combination of door and window alarms and area motion detection. Alarms should be relayed to a central alarm station where they can be continually monitored. The alarm signaling system should include a trouble alarm in the event the system is interrupted by an electrical or mechanical failure or due to tampering. A written comprehensive program for the testing and maintenance of alarm systems can help you confirm that building security is continually in place.
Access controls
Protect areas such as server rooms, computer rooms or telephone equipment rooms by appropriate security measures such as locked doors or entry controls. The effectiveness of physical access controls for both normal business hours and after business hours should be reviewed and improvements made, as appropriate.
A written access control policy that regulates and monitors access of all persons, including employees, contractors, vendors and visitors can help maintain access controls. Consider requiring visitors, vendors and contractors to sign in and be escorted to the area they are visiting. In tenanted buildings where telephone or electronic equipment rooms are shared, consider a security agreement and access controls that are jointly established by the building owner, you and any other involved tenants.
Only authorized personnel should have access to non-public or restricted areas of your facility. Only authorized employees can have access key(s). Companies should have a written key control program addressing key access and control.
Instruct employees who work in a restricted area to make inquiries of people they do not recognize as to the purpose of their visit and notify management of any unknown persons.
Office area security
In addition to physical security access controls, other security controls for consideration for office areas include:
Devices/equipment
- Providing cabling and locks to secure computer equipment and laptops to workstations.
- Locating/storing easy-to-grab equipment, such as laptops and cell phones that could contain sensitive or personally identifiable information, away from public viewing.
- Reorientation of computer monitors with sensitive information away from public viewing, such as in reception areas, check-in desks and waiting rooms.
- Instruct employees to logoff, or shutdown active sessions, before leaving workstations when working with sensitive information. In addition, program equipment settings to auto-lock when not in use for several minutes.
Data/sensitive information
Have a “clean desk” policy to help keep sensitive and/or confidential documents and information secure.
- Educate employees to understand that leaving sensitive material on a desk in open view could result in data compromise or breach of sensitive information, which could also impact the entire company and your customers.
- Safeguard copies of material containing sensitive information by providing employees with locking file cabinets or safes.
- Make it a standard operating procedure to lock up sensitive information.
Physical protection of electronic/telecommunication equipment
Physical protection features can help provide adequate protection for electronic and telecommunication equipment. Considerations include, but are not limited to:
- Do not locate electronic equipment in basements or below grade, to help minimize the risk of water damage in the event of flooding.
- Segregate the electronic equipment rooms from other areas of the building with noncombustible walls. Consider automatically closing doors normally kept in the locked, closed position.
- Monitor the room temperature if the room requires air conditioning and have an alarm sound if the room temperature exceeds a predetermined level.
Electronic equipment and data disposal
Establish procedures and educate employees on disposal requirements for sensitive information and data. For paper and documents, purchase an adequate number of business grade shredders to make it convenient for employees. Alternatively, subscribe to a trusted recycler/shredding company that will provide locked containers for storage until documents are shredded.
When destroying or recycling electronic equipment, remember, it may be possible to retrieve information even after the computer user believes the information has been deleted. Contract with a recycler that is certified for secure electronic data destruction to help ensure the sensitive information contained within the equipment will be destroyed and irretrievable. If a certified equipment recycler is not available, removing and destroying computer hard drives prior to recycling may help to protect data.