3.8 Secure Site & Facility Design Principles

CISSP Domain 3 Β· Security Architecture and Engineering

3.8 Secure Site & Facility Design Principles

Physical security begins long before locks, cameras and access-control systems are installed.

Secure facility design considers where a site is located, what surrounds it, how people and vehicles approach it, where sensitive activities are placed inside it and how the design reduces opportunities for intrusion, disruption and environmental damage.

πŸ“

Choose Carefully

Understand threats surrounding the location before selecting the site.

SITE SELECTION
🏰

Layer Protection

Move from public areas toward progressively more restricted zones.

DEFENCE IN DEPTH
πŸ‘οΈ

Design Out Risk

Use layout, visibility and controlled movement to discourage and detect unwanted activity.

SECURE BY DESIGN

The Big Idea

A secure building should not rely on a single door, guard or security technology.

The entire site should be designed so an attacker encounters multiple boundaries while legitimate users can move safely and efficiently.

🌍 Location β†’ What threats surround the site?
🏞️ Property β†’ How can people and vehicles approach?
🏒 Building β†’ Where are the entry points?
πŸšͺ Internal Zones β†’ Which areas require stronger protection?
πŸ’Ž Critical Assets β†’ How far are they from public access?
πŸ†˜ Emergency β†’ Can people leave safely when necessary?

Facility Design Flow

LOCATION Choose the site
PERIMETER Define the boundary
BUILDING Control entry
ZONE Separate activities
ASSET Protect what matters most

Outside β†’ Inside β†’ More Restricted

Foundation

Design Before Controls

Physical security is strongest when it is incorporated into the original site and building design.

Weak Approach

Select a building based only on price and convenience.

Discover security problems afterwards.

Attempt to compensate with additional cameras, guards and barriers.

Secure Design Approach

Identify threats before selecting or designing the site.

Position critical assets appropriately.

Build security boundaries into the layout.

Architecture can remove risk that technology would otherwise have to manage

A data centre designed away from flood-prone areas is preferable to deliberately building in a high-risk location and relying entirely on pumps and emergency procedures.

πŸ“ Site Selection Security begins with choosing the right location

Before selecting a site, the organisation should understand threats associated with both the property and the surrounding area.

Environmental Considerations

Flooding

Rivers, coastlines, drainage and local flood history may affect availability.

Earthquake

Seismic risk can influence building design and equipment protection.

Wildfire

Vegetation, climate and access routes can affect fire exposure.

Severe Weather

Storms, extreme temperatures, snow or wind may affect the facility and its utilities.

Ground Conditions

Stability, drainage and geological characteristics can influence physical risk.

Water Exposure

The site should consider both external flooding and nearby water infrastructure.

Human & Infrastructure Considerations

Crime

Local crime patterns influence the threat environment.

Civil Disturbance

Some locations may face greater protest, disorder or unrest risk.

High-Profile Neighbours

Nearby organisations may attract threats unrelated to your own organisation.

Industrial Hazards

Chemical plants, fuel storage and other hazardous facilities can introduce external risk.

Transport Infrastructure

Airports, railways and major roads can provide convenience while also introducing additional hazards.

Emergency Services

Access to fire, police and medical services can influence response capability.

Ask not only: "Is this building secure?"

Also ask:

"Is this a sensible place to put the building?"

🌍 Understand the Surrounding Environment The organisation does not control everything beyond its property line

The security architecture should consider nearby buildings, infrastructure and activities.

Example

A highly resilient data centre has excellent internal security.

It is located immediately beside a large chemical-processing facility.

A serious incident at the neighbouring facility could still make the data centre inaccessible or unsafe.

Risk can originate outside organisational control

Site assessment therefore considers both direct attacks and indirect hazards created by neighbouring infrastructure.

⚑ Utility Dependencies A secure building still depends on external services

Facilities depend on external infrastructure that may fail even when the building itself remains undamaged.

Electricity Water Telecommunications Internet Connectivity Fuel Drainage Transport Access
Example

A data centre receives two network connections.

They appear redundant.

Investigation reveals that both cables travel through the same underground duct before reaching the building.

One construction accident could cut both connections.

Logical redundancy does not necessarily mean physical diversity.
Look for common dependencies

Two systems that appear independent may still share the same power substation, telecommunications path, fuel source or physical access route.

🏰 Physical Defence in Depth Use multiple boundaries between the public and critical assets

Defence in depth applies to physical environments just as it does to networks and information systems.

🌍 Public Space β†’ Anyone may approach
🚧 Property Boundary β†’ First security layer
🏒 Building Entrance β†’ Controlled access
πŸ‘” Work Area β†’ Authorised personnel
πŸ” Restricted Area β†’ Limited authorised personnel
πŸ’Ž Critical Asset β†’ Strongest protection
The most sensitive asset should not usually sit at the first boundary

Placing critical infrastructure deeper inside a facility forces an attacker to cross additional controlled zones before reaching it.

Physical Defence in Depth

OUTSIDE Low trust
ENTER Authenticate
MOVE INWARD Increase restriction
CORE Critical assets

More sensitive β†’ Deeper inside

πŸ—ΊοΈ Security Zones Not every part of a building requires the same level of trust

Facility layouts can divide space according to security requirements.

Public Area

Reception, customer-facing or other areas accessible without significant authorisation.

Controlled Area

Access limited to employees or otherwise authorised people.

Restricted Area

Access requires a specific business requirement.

Highly Restricted Area

Critical assets require stronger authentication, monitoring and access restrictions.

Office example
Reception β†’ Public
Office Floor β†’ Controlled
Security Operations Centre β†’ Restricted
Critical Infrastructure Room β†’ Highly Restricted
Zoning supports least privilege physically

An employee may legitimately need access to the office without requiring access to the data centre, evidence store or security operations area.

🏒 Internal Placement & Adjacency Where an asset sits inside the building matters

Secure design considers what surrounds sensitive spaces.

Poor placement

A critical server room shares a wall with:

a public corridor and external loading area.

This creates greater physical exposure than placing the room deeper within the controlled area of the building.

Questions to Ask

What is above it? What is below it? What is beside it? Can the public reach the wall? Are water pipes nearby? Is there an external window? Is it beneath a kitchen or bathroom?
Think three-dimensionally

Security design is not just about the door to the room.

Floors, ceilings, walls, ducts, windows and neighbouring spaces may create alternative access or environmental risks.

πŸ‘οΈ Crime Prevention Through Environmental Design - CPTED Use the physical environment itself to reduce opportunities for crime

Crime Prevention Through Environmental Design uses building and landscape design to discourage unwanted behaviour and make suspicious activity easier to observe.

Natural Surveillance

Design spaces so legitimate occupants can observe entrances, walkways and surrounding areas.

Natural Access Control

Use layout and pathways to guide people toward appropriate entry points.

Territorial Reinforcement

Make boundaries between public, private and restricted space clear.

Maintenance

Well-maintained spaces communicate ownership and make unusual activity more noticeable.

Natural Surveillance

Example

Shrubs surrounding an entrance are kept low enough that they do not create hiding locations.

Interior windows allow reception staff to observe people approaching the entrance.

Natural Access Control

Example

Landscaping and pathways naturally direct visitors toward the reception entrance rather than allowing easy access to employee-only side entrances.

Territorial Reinforcement

Example

Changes in paving, fencing, signs and landscaping make the transition from public space to organisational property obvious.

CPTED

SEE Natural surveillance
GUIDE Natural access control
DEFINE Territory
MAINTAIN The environment

See Β· Guide Β· Define Β· Maintain

🌳 Visibility & Landscaping Landscape design can help or hurt security

Trees, shrubs, walls and decorative structures affect both visibility and physical access.

Good Visibility

Allows occupants and security personnel to observe approaches to the facility.

Poor Visibility

Dense vegetation or structures can provide concealment.

Natural Barrier

Landscaping can guide movement away from sensitive areas.

Maintenance

Vegetation should not gradually undermine security visibility.

Security feature β‰  ugly fortress

Effective design can integrate physical protection into ordinary architectural and landscaping features.

πŸš— Vehicle Approach & Standoff Control how close vehicles can get to sensitive structures

Vehicle access can introduce threats ranging from accidental collision to deliberate attack.

Design Considerations

Parking Location Loading Areas Vehicle Routes Visitor Drop-Off Emergency Access Standoff Distance
Example

Instead of placing unrestricted public parking immediately against a critical building wall, the site design creates distance between normal vehicle areas and sensitive parts of the facility.

Distance can itself be a security control

Site layout can reduce the impact of vehicle-related threats before additional barriers are considered.

πŸšͺ Entry Point Design Every entrance increases the area that must be controlled

Doors are necessary for people and operations, but every entrance represents another potential access path.

More Entrances β†’ More access paths
More Access Paths β†’ More controls and monitoring
More Complexity β†’ Greater chance of weakness
Keep it simple and small applies physically too

The objective is not to remove every entrance.

It is to avoid unnecessary access points while still meeting operational and life-safety requirements.

πŸͺŸ Windows & External Exposure Convenience and natural light can introduce additional exposure

Windows can create several security considerations.

Physical Entry

A vulnerable window may provide another means of entering the building.

Visual Exposure

Sensitive information or activity may be visible from outside.

Environmental Exposure

Windows may influence heat, weather and structural risk.

Critical Area Placement

Highly sensitive rooms may be better positioned away from external walls or easily accessible windows.

🏬 Shared & Multi-Tenant Facilities Other occupants create additional trust relationships

Organisations often occupy shared office buildings, colocation facilities or other multi-tenant environments.

Additional Questions

Who controls the lobby? Who manages building access? Who maintains utilities? Who has master keys? Who can access service areas? Which walls and ceilings are shared? Who manages contractors?
Example

An organisation secures its office door carefully.

However, the suspended ceiling extends over the partition wall into an adjacent tenant's space.

The actual security boundary may therefore be weaker than the visible wall suggests.

Understand the real boundary

A security boundary includes floors, ceilings, shared maintenance spaces and utility routes - not just doors and walls visible to employees.

🚢 People Flow Design how employees, visitors and contractors move through the facility

Secure layout separates different categories of people where their access requirements differ.

πŸ‘€ Visitor β†’ Reception
Reception β†’ Authorised Meeting Area
πŸ‘” Employee β†’ Controlled Work Area
πŸ”§ Contractor β†’ Only Required Service Area
πŸ” Privileged Staff β†’ Restricted Area
Physical least privilege

A contractor repairing an air-conditioning system does not need unrestricted access to unrelated sensitive areas simply because they have legitimate work inside the building.

πŸͺͺ Visitor Considerations Visitors are legitimate outsiders, not trusted employees

Facility design should provide a way for legitimate visitors to conduct business without unnecessarily exposing internal areas.

Better design

Visitor meeting rooms are positioned close to reception.

Visitors can attend meetings without travelling through sensitive employee work areas.

Weaker design

Every visitor must cross the entire operations floor to reach a meeting room at the back of the building.

This unnecessarily exposes internal information and increases supervision requirements.

Visitor Design

KEEP Visitor activity near public zones
AVOID Unnecessary travel through restricted zones
πŸ“¦ Deliveries & Loading Areas Operational entrances require separate security consideration

Loading areas introduce frequent interaction with drivers, couriers, suppliers and physical goods.

External Parties

Delivery personnel may not be trusted employees.

Large Openings

Loading doors may provide much larger access paths than normal pedestrian entrances.

Vehicles

Vehicles may approach close to the facility.

Goods

Packages entering and leaving the organisation may require appropriate controls.

Separate operational flows where practical

The public entrance, employee entrance and loading area serve different purposes and may therefore require different security designs.

Critical CISSP Principle

Security Must Not Override Life Safety

A highly secure facility must still allow people to evacuate during an emergency.

Security Requirement

Prevent unauthorised people entering the building.

Safety Requirement

Allow occupants to escape during a fire or other emergency.

Protection of human life takes priority over protection of equipment and information.
CISSP-style example

A locked exit would make a restricted room harder for an attacker to enter.

But if employees cannot evacuate safely during a fire, the design is unacceptable.

Safety vs Security

CONTROL ENTRY Keep attackers out
ALLOW ESCAPE Keep people safe

People first.

πŸŒͺ️ Natural vs Human-Caused Threats Facility design must consider both
Natural
Flood Earthquake Storm Wildfire Extreme Temperature Lightning
Human-Caused
Burglary Vandalism Sabotage Terrorism Civil Disturbance Accidental Damage
Intent does not determine impact

A construction crew accidentally cutting both network feeds can cause the same availability loss as deliberate sabotage.

πŸ₯· Visibility of the Facility Sometimes attracting less attention reduces risk

Organisations should consider whether the site needs to advertise the value of what is inside.

Example

A building contains critical technology infrastructure.

Large external signs announcing:

"GLOBAL FINANCIAL DATA CENTRE"

may unnecessarily advertise the importance of the facility.

Low profile can reduce target attractiveness

Security through obscurity is not sufficient protection, but there is little benefit in unnecessarily advertising a sensitive facility.

🌐 Geographic Diversity Do not let one regional event destroy every critical facility

Where multiple facilities provide resilience, their locations should be evaluated for shared regional risks.

Poor resilience

Primary data centre: Building A

Disaster recovery site: Building B - 500 metres away

Both depend on:

  • the same flood plain;
  • the same electrical substation;
  • the same telecommunications exchange;
  • the same road access.

They are separate buildings but may not provide meaningful geographic resilience.

Separate does not necessarily mean independent

Resilient facility design considers correlated failures and shared dependencies.

Secure Site Design Process

1️⃣ Requirements β†’ What must the facility support?
2️⃣ Asset Identification β†’ What requires protection?
3️⃣ Threat Assessment β†’ What could affect the site?
4️⃣ Site Selection β†’ Which location best manages the risk?
5️⃣ Zoning β†’ How should areas be separated?
6️⃣ Movement β†’ How should people and vehicles move?
7️⃣ Controls β†’ Which physical controls are required?
8️⃣ Validate β†’ Does the design satisfy security and safety requirements?
Practical Scenario

Selecting a New Data Centre Site

An organisation is comparing two possible data-centre locations.

Site A

Very cheap.

  • located in a flood-prone area;
  • only one access road;
  • adjacent to a chemical facility;
  • one local electricity substation;
  • telecom routes share one physical corridor.
Site B

More expensive.

  • lower environmental risk;
  • multiple road approaches;
  • greater distance from hazardous facilities;
  • more diverse utility options;
  • space for layered physical boundaries.
CISSP perspective

The cheapest building is not necessarily the lowest-cost security solution.

Risk created by poor site selection may require expensive compensating controls for the entire lifetime of the facility.

Second Scenario

Designing a Secure Office

An organisation designs a new headquarters building.

🌍 Street β†’ Public
🏒 Reception β†’ Visitor Zone
πŸͺͺ Access Point β†’ Employee Zone
πŸ” Internal Boundary β†’ Restricted Operations
πŸ’Ž Inner Area β†’ Critical Technology

Meeting rooms for external visitors are positioned near reception.

Critical technology rooms are positioned away from exterior walls, public areas and unnecessary water sources.

Delivery traffic uses a separate controlled area rather than the main employee entrance.

Good facility design reduces how often security controls need to fight against a poor building layout.
πŸŽ“ CISSP Scenarios Apply physical security principles to the design
Scenario 1

A company is selecting a site for a critical data centre. One proposed location lies in an area with frequent flooding.

What should be considered FIRST?

Whether the site itself is appropriate given the identified environmental risk.

Scenario 2

A highly sensitive server room is located directly beside the public reception area.

Which design principle could be improved?

Defence in depth and security zoning.

Scenario 3

A visitor must walk through a sensitive operations floor to reach a meeting room.

What is the best design improvement?

Place visitor facilities closer to the public/reception zone.

Scenario 4

Tall dense shrubs beside an office entrance provide concealment from security staff.

Which design concept is most directly affected?

Natural surveillance / CPTED.

Scenario 5

Landscaping naturally directs pedestrians toward a monitored reception entrance.

Which CPTED concept is demonstrated?

Natural access control.

Scenario 6

Signs, paving and landscaping clearly distinguish public space from private organisational property.

Which CPTED concept is demonstrated?

Territorial reinforcement.

Scenario 7

Two internet circuits enter a data centre through the same physical underground duct.

What is the primary concern?

A shared physical dependency creates a common point of failure.

Scenario 8

A company's disaster-recovery facility is directly across the street from its primary facility.

What should be evaluated?

Whether both locations are vulnerable to the same regional event and shared infrastructure failures.

Scenario 9

A secure facility has only one road that can be used to reach it.

Which concern should the architect recognise?

The access route can become a single point of failure.

Scenario 10

A restricted room is designed without an emergency exit because management wants to maximise physical security.

What is the most important issue?

Life-safety requirements take priority over asset protection.

Scenario 11

A contractor requires access to one mechanical area but receives access to the entire building for convenience.

Which principle has been violated?

Physical least privilege.

Scenario 12

A server room is located beneath a large water-storage tank.

What design concept was insufficiently considered?

Internal placement, adjacency and environmental risk.

Scenario 13

A high-security facility has unrestricted visitor parking directly against its exterior wall.

Which design consideration should be reviewed?

Vehicle approach and standoff distance.

Scenario 14

A company occupies one floor of a multi-tenant office. The partition walls terminate at a suspended ceiling that is shared with other tenants.

What should the security architect recognise?

The visible wall may not represent the complete physical security boundary.

Scenario 15

Management wants a prominent sign outside a critical infrastructure site advertising exactly what the building contains.

Which principle should be considered?

Avoid unnecessarily increasing the facility's visibility and target attractiveness.

CISSP Exam Perspective

Recognise the Clue Words

Flood / Earthquake / Wildfire

Before building controls.

Site Selection

Public β†’ Restricted β†’ Critical

Increasing protection inward.

Security Zoning

Multiple Physical Boundaries

No single control protects everything.

Defence in Depth

Visibility

Reduce hiding places.

Natural Surveillance

Guide People to Entrance

Layout directs movement.

Natural Access Control

Clearly Defined Property

Public vs private space.

Territorial Reinforcement

Critical Room Near Public Space

Poor internal positioning.

Adjacency / Zoning

Two Links, One Cable Route

Hidden common dependency.

Physical Diversity

Visitors Cross Secure Areas

Poor movement design.

Visitor Zoning

Vehicles Close to Building

Physical approach risk.

Standoff

Shared Building

Floors, ceilings and service spaces.

True Security Boundary

Locked Emergency Exit

Asset security conflicts with human safety.

Life Safety First

3.8 vs 3.9 - Know the Difference

3.8 Site & Facility Design Principles3.9 Site & Facility Security Controls
Where should the site be?How should the site be protected?
How should areas be positioned?Which controls protect those areas?
Where should trust boundaries exist?How are those boundaries enforced?
How should people and vehicles move?Which access mechanisms are required?
Which environmental risks influence design?How are fire, power and HVAC protected?
What dependencies should be avoided?What redundancy and backup controls should be implemented?

3.8 vs 3.9

3.8 DESIGN the facility securely
3.9 PROTECT the facility with controls

3.8 = Architecture Β· 3.9 = Controls

⚠️ Common CISSP Mistakes Physical security is about architecture as well as locks
Physical Security β‰  Doors and Cameras Only

Site location, layout, zoning, visibility and dependencies can be equally important.

Cheap Site β‰  Low-Cost Site

A poor location may require expensive controls and carry higher residual risk throughout the facility's lifetime.

Separate Connections β‰  Diverse Connections

Multiple services may still share the same physical infrastructure.

Separate Buildings β‰  Geographic Diversity

Nearby facilities may share the same environmental and utility risks.

Employee β‰  Access Everywhere

Physical access should follow least privilege and business need.

Visitor β‰  Employee

Visitor routes should minimise unnecessary exposure to internal spaces.

Wall β‰  Complete Boundary

Ceilings, floors, ducts, windows and shared service spaces may bypass visible boundaries.

Maximum Security β‰  Ignore Safety

Controls must support safe emergency evacuation.

More Entrances β‰  Better Operations Without Cost

Every additional access point expands the area that must be secured and monitored.

Obscurity β‰  Security

Keeping a facility low-profile may reduce attention, but strong physical controls are still necessary.

Quick Reference

If the design problem is...Think...
Building located in high-risk flood areaSite Selection
Critical assets immediately accessible from public areasZoning / Defence in Depth
Dense vegetation hides intrudersNatural Surveillance
Layout directs visitors to receptionNatural Access Control
Public/private areas are visually obviousTerritorial Reinforcement
Critical room shares wall with public areaAdjacency
Multiple circuits use one physical routeCommon Dependency
Backup site faces same regional disasterGeographic Diversity
Visitors walk through sensitive officesPeople Flow / Zoning
Public parking is directly against critical buildingVehicle Standoff
Shared ceiling bypasses secure wallTrue Physical Boundary
Locked exit prevents evacuationLife Safety

Secure Facility Master Memory Aid

PLACE Choose a safe location
BOUNDARY Define the perimeter
ZONE Separate public and sensitive spaces
SEE Maintain visibility
GUIDE Control movement naturally
DISTANCE Keep threats away from critical assets
DIVERSIFY Avoid common dependencies
ESCAPE Protect human life

Place Β· Boundary Β· Zone Β· See Β· Guide Β· Distance Β· Diversify Β· Escape

The Facility Architect's Questions

WHERE? Where should the facility be located?
AROUND? What surrounds it?
APPROACH? How can people and vehicles reach it?
INSIDE? Where should sensitive areas be placed?
FAIL? Which external dependencies could fail together?
ESCAPE? Can people leave safely?

A secure facility protects assets without trapping people.

Key Takeaways

Secure facility design begins with risk assessment and site selection, not with purchasing physical security products.

Avoiding a major risk through intelligent design is often preferable to compensating for a poor location throughout the facility's lifetime.

Site selection should consider natural hazards, crime, neighbouring facilities, transport infrastructure, emergency response and utility dependencies.

Physical defence in depth places multiple security boundaries between public areas and critical assets.

The more sensitive the asset, the deeper within controlled space it should generally be positioned.

Security zoning allows public, controlled, restricted and highly restricted activities to be separated.

Internal placement matters. Floors, ceilings, walls, windows, pipes and neighbouring rooms can create security or environmental exposure.

CPTED uses environmental design to reduce opportunities for unwanted behaviour.

Natural surveillance improves visibility, natural access control guides movement and territorial reinforcement makes ownership boundaries clear.

Landscaping should support security rather than create concealment or uncontrolled approaches.

Vehicle routes, parking and loading areas should be considered during design rather than treated purely as operational concerns.

Visitors and contractors should be able to perform legitimate activities without receiving unnecessary access to sensitive areas.

Shared and multi-tenant facilities require careful understanding of the real physical security boundary.

Multiple utilities or facilities may still share the same physical dependency, so apparent redundancy should be checked for genuine diversity.

Geographic separation should consider correlated risks such as flooding, electricity, telecommunications and transport access.

Physical least privilege means people receive access only to the areas required for their role or task.

The visibility of a sensitive facility should also be considered. Organisations do not need to unnecessarily advertise valuable targets.

Most importantly, physical security must account for life safety. Occupants must be able to evacuate safely during emergencies.

Good physical architecture makes legitimate movement easy, unauthorised movement difficult and critical assets progressively harder to reach.

πŸ“š Sources & Further Reading Facility design and physical security guidance