3.8 Secure Site & Facility Design Principles
3.8 Secure Site & Facility Design Principles
Physical security begins long before locks, cameras and access-control systems are installed.
Secure facility design considers where a site is located, what surrounds it, how people and vehicles approach it, where sensitive activities are placed inside it and how the design reduces opportunities for intrusion, disruption and environmental damage.
Choose Carefully
Understand threats surrounding the location before selecting the site.
SITE SELECTIONLayer Protection
Move from public areas toward progressively more restricted zones.
DEFENCE IN DEPTHDesign Out Risk
Use layout, visibility and controlled movement to discourage and detect unwanted activity.
SECURE BY DESIGNThe Big Idea
A secure building should not rely on a single door, guard or security technology.
The entire site should be designed so an attacker encounters multiple boundaries while legitimate users can move safely and efficiently.
Facility Design Flow
Outside β Inside β More Restricted
Design Before Controls
Physical security is strongest when it is incorporated into the original site and building design.
Select a building based only on price and convenience.
Discover security problems afterwards.
Attempt to compensate with additional cameras, guards and barriers.
Identify threats before selecting or designing the site.
Position critical assets appropriately.
Build security boundaries into the layout.
A data centre designed away from flood-prone areas is preferable to deliberately building in a high-risk location and relying entirely on pumps and emergency procedures.
π Site Selection Security begins with choosing the right location
Before selecting a site, the organisation should understand threats associated with both the property and the surrounding area.
Environmental Considerations
Rivers, coastlines, drainage and local flood history may affect availability.
Seismic risk can influence building design and equipment protection.
Vegetation, climate and access routes can affect fire exposure.
Storms, extreme temperatures, snow or wind may affect the facility and its utilities.
Stability, drainage and geological characteristics can influence physical risk.
The site should consider both external flooding and nearby water infrastructure.
Human & Infrastructure Considerations
Local crime patterns influence the threat environment.
Some locations may face greater protest, disorder or unrest risk.
Nearby organisations may attract threats unrelated to your own organisation.
Chemical plants, fuel storage and other hazardous facilities can introduce external risk.
Airports, railways and major roads can provide convenience while also introducing additional hazards.
Access to fire, police and medical services can influence response capability.
Also ask:
"Is this a sensible place to put the building?"
π Understand the Surrounding Environment The organisation does not control everything beyond its property line
The security architecture should consider nearby buildings, infrastructure and activities.
A highly resilient data centre has excellent internal security.
It is located immediately beside a large chemical-processing facility.
A serious incident at the neighbouring facility could still make the data centre inaccessible or unsafe.
Site assessment therefore considers both direct attacks and indirect hazards created by neighbouring infrastructure.
β‘ Utility Dependencies A secure building still depends on external services
Facilities depend on external infrastructure that may fail even when the building itself remains undamaged.
A data centre receives two network connections.
They appear redundant.
Investigation reveals that both cables travel through the same underground duct before reaching the building.
One construction accident could cut both connections.
Logical redundancy does not necessarily mean physical diversity.Two systems that appear independent may still share the same power substation, telecommunications path, fuel source or physical access route.
π° Physical Defence in Depth Use multiple boundaries between the public and critical assets
Defence in depth applies to physical environments just as it does to networks and information systems.
Placing critical infrastructure deeper inside a facility forces an attacker to cross additional controlled zones before reaching it.
Physical Defence in Depth
More sensitive β Deeper inside
πΊοΈ Security Zones Not every part of a building requires the same level of trust
Facility layouts can divide space according to security requirements.
Reception, customer-facing or other areas accessible without significant authorisation.
Access limited to employees or otherwise authorised people.
Access requires a specific business requirement.
Critical assets require stronger authentication, monitoring and access restrictions.
An employee may legitimately need access to the office without requiring access to the data centre, evidence store or security operations area.
π’ Internal Placement & Adjacency Where an asset sits inside the building matters
Secure design considers what surrounds sensitive spaces.
A critical server room shares a wall with:
a public corridor and external loading area.
This creates greater physical exposure than placing the room deeper within the controlled area of the building.
Questions to Ask
Security design is not just about the door to the room.
Floors, ceilings, walls, ducts, windows and neighbouring spaces may create alternative access or environmental risks.
ποΈ Crime Prevention Through Environmental Design - CPTED Use the physical environment itself to reduce opportunities for crime
Crime Prevention Through Environmental Design uses building and landscape design to discourage unwanted behaviour and make suspicious activity easier to observe.
Design spaces so legitimate occupants can observe entrances, walkways and surrounding areas.
Use layout and pathways to guide people toward appropriate entry points.
Make boundaries between public, private and restricted space clear.
Well-maintained spaces communicate ownership and make unusual activity more noticeable.
Natural Surveillance
Shrubs surrounding an entrance are kept low enough that they do not create hiding locations.
Interior windows allow reception staff to observe people approaching the entrance.
Natural Access Control
Landscaping and pathways naturally direct visitors toward the reception entrance rather than allowing easy access to employee-only side entrances.
Territorial Reinforcement
Changes in paving, fencing, signs and landscaping make the transition from public space to organisational property obvious.
CPTED
See Β· Guide Β· Define Β· Maintain
π³ Visibility & Landscaping Landscape design can help or hurt security
Trees, shrubs, walls and decorative structures affect both visibility and physical access.
Allows occupants and security personnel to observe approaches to the facility.
Dense vegetation or structures can provide concealment.
Landscaping can guide movement away from sensitive areas.
Vegetation should not gradually undermine security visibility.
Effective design can integrate physical protection into ordinary architectural and landscaping features.
π Vehicle Approach & Standoff Control how close vehicles can get to sensitive structures
Vehicle access can introduce threats ranging from accidental collision to deliberate attack.
Design Considerations
Instead of placing unrestricted public parking immediately against a critical building wall, the site design creates distance between normal vehicle areas and sensitive parts of the facility.
Site layout can reduce the impact of vehicle-related threats before additional barriers are considered.
πͺ Entry Point Design Every entrance increases the area that must be controlled
Doors are necessary for people and operations, but every entrance represents another potential access path.
The objective is not to remove every entrance.
It is to avoid unnecessary access points while still meeting operational and life-safety requirements.
πͺ Windows & External Exposure Convenience and natural light can introduce additional exposure
Windows can create several security considerations.
A vulnerable window may provide another means of entering the building.
Sensitive information or activity may be visible from outside.
Windows may influence heat, weather and structural risk.
Highly sensitive rooms may be better positioned away from external walls or easily accessible windows.
π¬ Shared & Multi-Tenant Facilities Other occupants create additional trust relationships
Organisations often occupy shared office buildings, colocation facilities or other multi-tenant environments.
Additional Questions
An organisation secures its office door carefully.
However, the suspended ceiling extends over the partition wall into an adjacent tenant's space.
The actual security boundary may therefore be weaker than the visible wall suggests.
A security boundary includes floors, ceilings, shared maintenance spaces and utility routes - not just doors and walls visible to employees.
πΆ People Flow Design how employees, visitors and contractors move through the facility
Secure layout separates different categories of people where their access requirements differ.
A contractor repairing an air-conditioning system does not need unrestricted access to unrelated sensitive areas simply because they have legitimate work inside the building.
πͺͺ Visitor Considerations Visitors are legitimate outsiders, not trusted employees
Facility design should provide a way for legitimate visitors to conduct business without unnecessarily exposing internal areas.
Visitor meeting rooms are positioned close to reception.
Visitors can attend meetings without travelling through sensitive employee work areas.
Every visitor must cross the entire operations floor to reach a meeting room at the back of the building.
This unnecessarily exposes internal information and increases supervision requirements.
Visitor Design
π¦ Deliveries & Loading Areas Operational entrances require separate security consideration
Loading areas introduce frequent interaction with drivers, couriers, suppliers and physical goods.
Delivery personnel may not be trusted employees.
Loading doors may provide much larger access paths than normal pedestrian entrances.
Vehicles may approach close to the facility.
Packages entering and leaving the organisation may require appropriate controls.
The public entrance, employee entrance and loading area serve different purposes and may therefore require different security designs.
Security Must Not Override Life Safety
A highly secure facility must still allow people to evacuate during an emergency.
Prevent unauthorised people entering the building.
Allow occupants to escape during a fire or other emergency.
A locked exit would make a restricted room harder for an attacker to enter.
But if employees cannot evacuate safely during a fire, the design is unacceptable.
Safety vs Security
People first.
πͺοΈ Natural vs Human-Caused Threats Facility design must consider both
A construction crew accidentally cutting both network feeds can cause the same availability loss as deliberate sabotage.
π₯· Visibility of the Facility Sometimes attracting less attention reduces risk
Organisations should consider whether the site needs to advertise the value of what is inside.
A building contains critical technology infrastructure.
Large external signs announcing:
"GLOBAL FINANCIAL DATA CENTRE"
may unnecessarily advertise the importance of the facility.
Security through obscurity is not sufficient protection, but there is little benefit in unnecessarily advertising a sensitive facility.
π Geographic Diversity Do not let one regional event destroy every critical facility
Where multiple facilities provide resilience, their locations should be evaluated for shared regional risks.
Primary data centre: Building A
Disaster recovery site: Building B - 500 metres away
Both depend on:
- the same flood plain;
- the same electrical substation;
- the same telecommunications exchange;
- the same road access.
They are separate buildings but may not provide meaningful geographic resilience.
Resilient facility design considers correlated failures and shared dependencies.
Secure Site Design Process
Selecting a New Data Centre Site
An organisation is comparing two possible data-centre locations.
Very cheap.
- located in a flood-prone area;
- only one access road;
- adjacent to a chemical facility;
- one local electricity substation;
- telecom routes share one physical corridor.
More expensive.
- lower environmental risk;
- multiple road approaches;
- greater distance from hazardous facilities;
- more diverse utility options;
- space for layered physical boundaries.
The cheapest building is not necessarily the lowest-cost security solution.
Risk created by poor site selection may require expensive compensating controls for the entire lifetime of the facility.
Designing a Secure Office
An organisation designs a new headquarters building.
Meeting rooms for external visitors are positioned near reception.
Critical technology rooms are positioned away from exterior walls, public areas and unnecessary water sources.
Delivery traffic uses a separate controlled area rather than the main employee entrance.
π CISSP Scenarios Apply physical security principles to the design
A company is selecting a site for a critical data centre. One proposed location lies in an area with frequent flooding.
What should be considered FIRST?
Whether the site itself is appropriate given the identified environmental risk.
A highly sensitive server room is located directly beside the public reception area.
Which design principle could be improved?
Defence in depth and security zoning.
A visitor must walk through a sensitive operations floor to reach a meeting room.
What is the best design improvement?
Place visitor facilities closer to the public/reception zone.
Tall dense shrubs beside an office entrance provide concealment from security staff.
Which design concept is most directly affected?
Natural surveillance / CPTED.
Landscaping naturally directs pedestrians toward a monitored reception entrance.
Which CPTED concept is demonstrated?
Natural access control.
Signs, paving and landscaping clearly distinguish public space from private organisational property.
Which CPTED concept is demonstrated?
Territorial reinforcement.
Two internet circuits enter a data centre through the same physical underground duct.
What is the primary concern?
A shared physical dependency creates a common point of failure.
A company's disaster-recovery facility is directly across the street from its primary facility.
What should be evaluated?
Whether both locations are vulnerable to the same regional event and shared infrastructure failures.
A secure facility has only one road that can be used to reach it.
Which concern should the architect recognise?
The access route can become a single point of failure.
A restricted room is designed without an emergency exit because management wants to maximise physical security.
What is the most important issue?
Life-safety requirements take priority over asset protection.
A contractor requires access to one mechanical area but receives access to the entire building for convenience.
Which principle has been violated?
Physical least privilege.
A server room is located beneath a large water-storage tank.
What design concept was insufficiently considered?
Internal placement, adjacency and environmental risk.
A high-security facility has unrestricted visitor parking directly against its exterior wall.
Which design consideration should be reviewed?
Vehicle approach and standoff distance.
A company occupies one floor of a multi-tenant office. The partition walls terminate at a suspended ceiling that is shared with other tenants.
What should the security architect recognise?
The visible wall may not represent the complete physical security boundary.
Management wants a prominent sign outside a critical infrastructure site advertising exactly what the building contains.
Which principle should be considered?
Avoid unnecessarily increasing the facility's visibility and target attractiveness.
Recognise the Clue Words
Flood / Earthquake / Wildfire
Before building controls.
Site SelectionPublic β Restricted β Critical
Increasing protection inward.
Security ZoningMultiple Physical Boundaries
No single control protects everything.
Defence in DepthVisibility
Reduce hiding places.
Natural SurveillanceGuide People to Entrance
Layout directs movement.
Natural Access ControlClearly Defined Property
Public vs private space.
Territorial ReinforcementCritical Room Near Public Space
Poor internal positioning.
Adjacency / ZoningTwo Links, One Cable Route
Hidden common dependency.
Physical DiversityVisitors Cross Secure Areas
Poor movement design.
Visitor ZoningVehicles Close to Building
Physical approach risk.
StandoffShared Building
Floors, ceilings and service spaces.
True Security BoundaryLocked Emergency Exit
Asset security conflicts with human safety.
Life Safety First3.8 vs 3.9 - Know the Difference
| 3.8 Site & Facility Design Principles | 3.9 Site & Facility Security Controls |
|---|---|
| Where should the site be? | How should the site be protected? |
| How should areas be positioned? | Which controls protect those areas? |
| Where should trust boundaries exist? | How are those boundaries enforced? |
| How should people and vehicles move? | Which access mechanisms are required? |
| Which environmental risks influence design? | How are fire, power and HVAC protected? |
| What dependencies should be avoided? | What redundancy and backup controls should be implemented? |
3.8 vs 3.9
3.8 = Architecture Β· 3.9 = Controls
β οΈ Common CISSP Mistakes Physical security is about architecture as well as locks
Site location, layout, zoning, visibility and dependencies can be equally important.
A poor location may require expensive controls and carry higher residual risk throughout the facility's lifetime.
Multiple services may still share the same physical infrastructure.
Nearby facilities may share the same environmental and utility risks.
Physical access should follow least privilege and business need.
Visitor routes should minimise unnecessary exposure to internal spaces.
Ceilings, floors, ducts, windows and shared service spaces may bypass visible boundaries.
Controls must support safe emergency evacuation.
Every additional access point expands the area that must be secured and monitored.
Keeping a facility low-profile may reduce attention, but strong physical controls are still necessary.
Quick Reference
| If the design problem is... | Think... |
|---|---|
| Building located in high-risk flood area | Site Selection |
| Critical assets immediately accessible from public areas | Zoning / Defence in Depth |
| Dense vegetation hides intruders | Natural Surveillance |
| Layout directs visitors to reception | Natural Access Control |
| Public/private areas are visually obvious | Territorial Reinforcement |
| Critical room shares wall with public area | Adjacency |
| Multiple circuits use one physical route | Common Dependency |
| Backup site faces same regional disaster | Geographic Diversity |
| Visitors walk through sensitive offices | People Flow / Zoning |
| Public parking is directly against critical building | Vehicle Standoff |
| Shared ceiling bypasses secure wall | True Physical Boundary |
| Locked exit prevents evacuation | Life Safety |
Secure Facility Master Memory Aid
Place Β· Boundary Β· Zone Β· See Β· Guide Β· Distance Β· Diversify Β· Escape
The Facility Architect's Questions
A secure facility protects assets without trapping people.
Key Takeaways
Secure facility design begins with risk assessment and site selection, not with purchasing physical security products.
Avoiding a major risk through intelligent design is often preferable to compensating for a poor location throughout the facility's lifetime.
Site selection should consider natural hazards, crime, neighbouring facilities, transport infrastructure, emergency response and utility dependencies.
Physical defence in depth places multiple security boundaries between public areas and critical assets.
The more sensitive the asset, the deeper within controlled space it should generally be positioned.
Security zoning allows public, controlled, restricted and highly restricted activities to be separated.
Internal placement matters. Floors, ceilings, walls, windows, pipes and neighbouring rooms can create security or environmental exposure.
CPTED uses environmental design to reduce opportunities for unwanted behaviour.
Natural surveillance improves visibility, natural access control guides movement and territorial reinforcement makes ownership boundaries clear.
Landscaping should support security rather than create concealment or uncontrolled approaches.
Vehicle routes, parking and loading areas should be considered during design rather than treated purely as operational concerns.
Visitors and contractors should be able to perform legitimate activities without receiving unnecessary access to sensitive areas.
Shared and multi-tenant facilities require careful understanding of the real physical security boundary.
Multiple utilities or facilities may still share the same physical dependency, so apparent redundancy should be checked for genuine diversity.
Geographic separation should consider correlated risks such as flooding, electricity, telecommunications and transport access.
Physical least privilege means people receive access only to the areas required for their role or task.
The visibility of a sensitive facility should also be considered. Organisations do not need to unnecessarily advertise valuable targets.
Most importantly, physical security must account for life safety. Occupants must be able to evacuate safely during emergencies.
Good physical architecture makes legitimate movement easy, unauthorised movement difficult and critical assets progressively harder to reach.
π Sources & Further Reading Facility design and physical security guidance
- ISC2 - CISSP Certification Exam Outline
View the current CISSP Exam Outline - NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations
View NIST physical and environmental protection guidance - NIST SP 800-160 Vol. 1 Rev. 1 - Engineering Trustworthy Secure Systems
View NIST systems security engineering guidance
