Skip to main content

Physical Access Controls in Information Technology (IT) Security

To help prevent unauthorized access or damage to your network or your sensitive data, management can develop a security program that includes a combination of physical, electronic and management controls. Items to consider include, but are not limited to:

Building security

Entry into your facility by unauthorized persons could result in theft of and compromise to, among other things, your computers and business intelligence and data. Providing physical security to the building exterior can be a first step to protecting against unauthorized entry. Keep doors and windows locked. Have a written program for key control and retrieval. Re-key locks whenever a key is lost.

Security alarms also play an important role in your physical security. Consider installing a building electronic security system that includes a combination of door and window alarms and area motion detection. Alarms should be relayed to a central alarm station where they can be continually monitored. The alarm signaling system should include a trouble alarm in the event the system is interrupted by an electrical or mechanical failure or due to tampering. A written comprehensive program for the testing and maintenance of alarm systems can help you confirm that building security is continually in place. 

Access controls

Protect areas such as server rooms, computer rooms or telephone equipment rooms by appropriate security measures such as locked doors or entry controls. The effectiveness of physical access controls for both normal business hours and after business hours should be reviewed and improvements made, as appropriate.  

A written access control policy that regulates and monitors access of all persons, including employees, contractors, vendors and visitors can help maintain access controls. Consider requiring visitors, vendors and contractors to sign in and be escorted to the area they are visiting. In tenanted buildings where telephone or electronic equipment rooms are shared, consider a security agreement and access controls that are jointly established by the building owner, you and any other involved tenants.

Only authorized personnel should have access to non-public or restricted areas of your facility. Only authorized employees can have access key(s). Companies should have a written key control program addressing key access and control.

Instruct employees who work in a restricted area to make inquiries of people they do not recognize as to the purpose of their visit and notify management of any unknown persons. 

Office area security

In addition to physical security access controls, other security controls for consideration for office areas include: 

Devices/equipment

  • Providing cabling and locks to secure computer equipment and laptops to workstations.
  • Locating/storing easy-to-grab equipment, such as laptops and cell phones that could contain sensitive or personally identifiable information, away from public viewing.
  • Reorientation of computer monitors with sensitive information away from public viewing, such as in reception areas, check-in desks and waiting rooms.
  • Instruct employees to logoff, or shutdown active sessions, before leaving workstations when working with sensitive information. In addition, program equipment settings to auto-lock when not in use for several minutes.  

Data/sensitive information

Have a “clean desk” policy to help keep sensitive and/or confidential documents and information secure.

  • Educate employees to understand that leaving sensitive material on a desk in open view could result in data compromise or breach of sensitive information, which could also impact the entire company and your customers.
  • Safeguard copies of material containing sensitive information by providing employees with locking file cabinets or safes.
  • Make it a standard operating procedure to lock up sensitive information.  

Physical protection of electronic/telecommunication equipment

Physical protection features can help provide adequate protection for electronic and telecommunication equipment. Considerations include, but are not limited to:

  • Do not locate electronic equipment in basements or below grade, to help minimize the risk of water damage in the event of flooding.
  • Segregate the electronic equipment rooms from other areas of the building with noncombustible walls. Consider automatically closing doors normally kept in the locked, closed position.
  • Monitor the room temperature if the room requires air conditioning and have an alarm sound if the room temperature exceeds a predetermined level.  

Electronic equipment and data disposal 

Establish procedures and educate employees on disposal requirements for sensitive information and data. For paper and documents, purchase an adequate number of business grade shredders to make it convenient for employees. Alternatively, subscribe to a trusted recycler/shredding company that will provide locked containers for storage until documents are shredded.

When destroying or recycling electronic equipment, remember, it may be possible to retrieve information even after the computer user believes the information has been deleted. Contract with a recycler that is certified for secure electronic data destruction to help ensure the sensitive information contained within the equipment will be destroyed and irretrievable. If a certified equipment recycler is not available, removing and destroying computer hard drives prior to recycling may help to protect data.

Related resources

Cyber Risk Management - Getting Started - Establishing a Security Baseline

This article discusses the importance of management commitment as one strategy in a cyber security program to help prevent unauthorized access or damage to your information, networks or computer systems and equipment.

Related resources

Cyber Security Policies

This article discusses the importance of security policies as one strategy in a cyber security program to help prevent unauthorized access or damage to your information, networks or computer systems and equipment.

Related resources

Administrator Privileges

An important step in providing security for your network is to establish and enforce administrator privileges. Inappropriate use of administrator privileges is often found to be a major contributory factor to data breaches or corruption of data.