3.9 Physical & Environmental Security Controls
3.9 Physical & Environmental Security Controls
Once a secure facility has been designed, physical and environmental controls must protect the people, systems, media and infrastructure operating inside it.
Effective physical security combines access control, monitoring, environmental protection, fire protection, utility resilience and emergency procedures rather than depending on a single defensive layer.
Control Access
Restrict who can physically reach critical systems and information.
PHYSICAL ACCESSProtect Environment
Manage temperature, humidity, water, fire and environmental hazards.
ENVIRONMENTAL CONTROLMaintain Service
Protect power, cooling and other utilities needed for continued operation.
RESILIENCEThe Big Idea
Information systems depend on a physical environment.
A perfectly configured server is still unavailable if:
What You Need to Understand
Protect network cabling and distribution equipment.
Protect concentrated technology and critical services.
Protect stored information throughout the media lifecycle.
Preserve integrity, accountability and chain of custody.
Control people, information and activity in sensitive spaces.
Maintain the environmental services systems require.
Protect against natural and human-caused events.
Prevent, detect and suppress fire safely.
Provide clean, redundant and backup electrical supply.
Physical Security Control Strategy
Different physical controls serve different purposes.
A reinforced door may: deny and delay.
CCTV may: deter and detect.
A security guard may: deter, detect and respond.
Physical Protection
๐ Wiring Closets & Intermediate Distribution Facilities Network infrastructure is a critical physical asset
Wiring closets and Intermediate Distribution Facilities - IDFs - contain network cabling and equipment connecting users and systems to the wider network infrastructure.
They may contain:
Physical access to network distribution equipment may allow someone to disconnect services, attach unauthorised devices, interfere with cabling or disrupt connectivity.
Controls
Only personnel with a legitimate requirement should enter.
Network infrastructure should not be accessible through an unlocked general-purpose cupboard.
Access to important network facilities should be attributable.
Networking equipment generates heat and requires appropriate ventilation.
Cables should be protected from accidental and deliberate damage.
The room should not become general storage for combustible materials or unrelated equipment.
An IDF containing production switches is also used to store:
This introduces unnecessary fire, accidental damage and access risk.
Wiring Closet
๐ฅ๏ธ Server Rooms & Data Centres High concentrations of technology, information and business dependency
Server rooms and data centres may support hundreds or thousands of business services.
Their physical compromise can therefore have organisation-wide impact.
Access Controls
Infrastructure Controls
Critical workloads should not depend unnecessarily on one power path.
UPS systems and generators can maintain service when utility power fails.
Heat generated by computing equipment must be removed reliably.
Detection and suppression should protect life and critical infrastructure.
Leaks should be detected before they cause extensive damage.
Temperature, humidity and other important conditions should be monitored.
A data centre provides efficiency by concentrating technology.
That concentration also makes power, cooling, fire protection and physical access especially important.
๐๏ธ Racks & Equipment Protection Room access may not be sufficiently granular
Some environments require controls inside the data centre itself.
Several organisations host equipment in the same data-centre hall.
All authorised customers may enter the hall, but they should not automatically have physical access to another customer's servers.
Locked cages or racks can create additional boundaries.
Being authorised to enter the facility does not necessarily justify access to every rack, console or system.
๐พ Media Storage Facilities Protect information even when it is not inside a running system
Removable and backup media may contain complete copies of sensitive organisational information.
Examples include:
Protection Requirements
Only authorised personnel should access sensitive media.
The organisation should know which media exists and where it is.
Protection should reflect the sensitivity of the information stored.
Media should be stored under conditions appropriate to its technology.
Important media requires appropriate protection from fire.
Protection continues while media is moved between locations.
A database is strongly protected in production.
Its nightly backup is copied onto removable media and left on an unattended desk.
The backup may contain the same sensitive information as production.
Copying information onto backup media does not make the information less sensitive.
Media Storage
๐ Evidence Storage Preserve integrity, authenticity and accountability
Evidence may be needed for internal investigation, disciplinary action, litigation, regulatory investigation or criminal proceedings.
Physical evidence therefore requires stronger accountability than ordinary storage.
Important Controls
Only authorised evidence custodians or investigators should have access.
Transfers and handling should be documented.
Packaging or containers can make unauthorised interference visible.
The organisation should know who accessed evidence and when.
Evidence must be protected from conditions that could alter or destroy it.
Evidence should not normally be mixed casually with ordinary operational media.
Evidence
๐ Restricted & Sensitive Work Areas Protect information during normal human activity
Sensitive information is often exposed not because a server is hacked, but because humans use information in physical workspaces.
Risks
Controls
Only people with a legitimate requirement should enter.
Sensitive information should not remain exposed unnecessarily.
Workstations should be positioned and configured to reduce unauthorised viewing.
Sensitive documents should not sit unattended on shared printers.
Visitors should be appropriately authorised, identified and escorted where necessary.
Sensitive papers and media should not enter ordinary waste streams without appropriate destruction.
A fraud-investigation team works with confidential customer records.
Their office may require:
- restricted physical access;
- visitor controls;
- secure document storage;
- privacy-aware screen placement;
- secure printing and disposal.
๐ก๏ธ Heating, Ventilation & Air Conditioning - HVAC Computers require a controlled operating environment
Computing equipment generates substantial heat.
Environmental systems must maintain appropriate conditions for the technology being protected.
Temperature
Equipment may throttle, become unstable, shut down or suffer accelerated component degradation.
Cooling should maintain operating conditions suitable for the equipment.
Humidity
Very dry environments can increase the risk of electrostatic discharge.
Excessive moisture can contribute to condensation and corrosion.
Humidity
Control both temperature AND humidity.
๐จ Cooling & Airflow Cooling capacity is only useful if air reaches the equipment
Data-centre layouts should manage how cool air reaches equipment and how hot exhaust air is removed.
Prevent hot exhaust air from unnecessarily mixing with cool supply air.
Rack orientation can help separate equipment intake air from hot exhaust air.
Monitoring should detect developing problems before systems reach unsafe conditions.
Critical environments should consider the consequences of losing a cooling component.
Servers may continue receiving electrical power after air conditioning fails, but they cannot continue operating indefinitely as heat accumulates.
๐๏ธ Utility Protection Critical systems depend on infrastructure beyond the server rack
Utility infrastructure can create both availability and physical hazards.
Questions to Ask
๐ง Water Damage Protection Water does not need to originate from a flood
Water damage can result from:
Controls
Avoid placing critical equipment directly beneath unnecessary water sources where practical.
Sensors can identify water before extensive damage occurs.
Water needs a safe path away from critical equipment.
Personnel should understand how relevant water supplies can be isolated when necessary.
A server room is located directly beneath employee bathrooms.
Even without a regional flood, plumbing failure creates an obvious environmental risk.
๐ช๏ธ Environmental Hazards Natural and human-caused events can both affect facilities
An accidental electrical failure can create the same service outage as deliberate sabotage.
Understand What Sustains Fire
Fire suppression works by interfering with one or more conditions required to sustain combustion.
Heat
Enough energy to sustain combustion.
REMOVE HEATOxygen
Supports the combustion process.
REDUCE OXYGENFuel
Material available to burn.
REMOVE FUELA more complete model also includes the chemical chain reaction that sustains combustion.
Fire
๐ Fire Prevention The best fire is the one that never starts
Fire protection should begin with prevention rather than relying only on suppression after ignition.
Remove unnecessary combustible materials.
Damaged or overloaded electrical systems can create ignition risk.
Flammable materials should not be stored casually near critical infrastructure.
Appropriate fire-resistant materials can reduce fire spread.
Ignition sources should be controlled.
Equipment faults should be addressed before they become hazards.
๐จ Fire Detection Detect the problem early enough to protect people and assets
Identifies products associated with smoke or combustion.
Responds to elevated temperature or rapid temperature change, depending on the system.
Detects characteristics associated with visible or invisible flame radiation.
Sensitive air-sampling systems can identify developing combustion before conventional conditions become severe.
A detector identifies the developing fire.
A suppression system attempts to control or extinguish it.
๐ฆ Water-Based Fire Suppression Wet pipe ยท Dry pipe ยท Pre-action ยท Deluge
Water is already present in the sprinkler piping.
Simple and capable of rapid response.
Pipes normally contain pressurised air or gas rather than water.
Activation allows water to enter the piping.
A detection event is normally required before water is admitted to the sprinkler piping.
This provides additional protection against accidental water release.
Designed to release large quantities of water through open discharge points when the system activates.
Used where rapid fire spread is a major concern.
Sprinkler Memory Aid
Accidental water release can itself damage computing equipment.
Pre-action designs add an additional activation condition before water enters the sprinkler network.
๐ซ๏ธ Clean-Agent & Gaseous Suppression Suppress fire without leaving water or powder residue
Some specialised environments use engineered gaseous or clean-agent suppression systems to reduce equipment damage associated with water or residue.
Advantages
Design Considerations
Any suppression technology used in occupied environments must be professionally designed around applicable life-safety requirements.
Carbon dioxide suppresses fire but can create a serious hazard for people at concentrations used for total-flooding fire suppression.
Halon is historically important in information-security study material, but its environmental impact led to substantial restrictions on new production and use.
Fire: Protect People First
โก Power Security Availability depends on both power quality and power continuity
Electrical problems can interrupt service or damage equipment even when power is not completely lost.
| Condition | Concept |
|---|---|
| Blackout | Complete loss of electrical power. |
| Brownout | Extended reduction in supplied voltage. |
| Sag | Short-duration voltage reduction. |
| Spike | Very brief increase in voltage. |
| Surge | Voltage increase lasting longer than a very short spike. |
| Electrical Noise | Unwanted electrical disturbance affecting power quality. |
Protective Measures
๐ Uninterruptible Power Supply - UPS Bridge short-term power disruption
A UPS provides temporary electrical power when normal utility power is lost or unsuitable.
Batteries provide immediate power while longer-duration backup power becomes available or systems shut down safely.
A UPS Can Support
Batteries degrade over time.
A UPS that has never been tested may fail precisely when it is required.
โฝ Backup Generators Provide longer-duration power during extended outages
Backup generators can provide electrical power after a utility outage exceeds the practical battery capacity of a UPS.
Generator Dependencies
A facility has a generator capable of running for many hours.
However, the organisation has no reliable arrangement to replenish fuel during a regional emergency.
The generator therefore has a resilience limit that must be understood.
Power Resilience Chain
Power Memory Aid
UPS bridges the gap โ Generator carries the load
๐ Redundant Power Remove single points of failure from the electrical path
Critical infrastructure may use multiple power paths so failure of one component does not immediately interrupt service.
A server contains two power supplies.
Both are plugged into the same PDU.
Both power supplies therefore fail if that single PDU loses power.
The server has duplicate components but not a fully independent power path.
Duplicate components offer limited resilience if they eventually converge on the same single point of failure.
๐ Emergency Power Shutoff Sometimes removing power is the safest response
Facilities may need an emergency mechanism for quickly disconnecting electrical power when continued energisation creates a serious hazard.
An emergency shutoff is powerful by design.
Its location and protection should reduce the chance that an unauthorised or accidental action causes a major outage.
Placing an unprotected emergency power-off button beside an ordinary light switch could introduce unnecessary availability risk.
๐ก Emergency Lighting Power failure must not prevent safe evacuation
Loss of normal power should not leave occupants unable to find exits or safely move through the facility.
Emergency lighting therefore supports:
๐น Physical Access Monitoring Access control is stronger when events are visible and attributable
Provides visual monitoring and potentially recorded evidence.
Record badge or other access-control events.
Provide human observation and response.
Identify forced or unexpectedly open doors.
Detect unexpected physical movement or boundary crossing.
Logs and recordings provide limited value if relevant events are never reviewed or monitored.
A camera that records an intrusion but produces no timely response may provide evidence afterwards without actually stopping the attack.
Physical Access Authentication
The same authentication-factor concepts used in logical security also apply to physical access.
Badge, smart card or physical token.
PIN or access code.
Biometric characteristic.
Access might require:
badge + PIN
or:
badge + biometric verification.
๐ช Mantraps / Access Control Vestibules Control passage between security zones
An access-control vestibule uses two controlled doors to regulate entry into a more restricted area.
The design can make it harder for an unauthorised individual to simply follow an authorised person through a controlled entrance.
Physical access controls must be designed so they do not create an unsafe evacuation condition.
Protecting a Critical Data Centre
A financial organisation operates a data centre supporting critical customer services.
Utility Power Suddenly Fails
Protecting only the servers is insufficient if cooling, network infrastructure or supporting systems fail during the outage.
๐ CISSP Scenarios Identify the physical or environmental control
A network distribution closet containing production switches is left unlocked in a public corridor.
Primary issue?
Inadequate physical access protection for network infrastructure.
The same wiring closet is also used to store cardboard boxes and cleaning chemicals.
Primary concern?
Unnecessary fire, environmental and accidental-damage risk.
A server-room cooling system fails while electrical power continues operating normally.
What security objective is threatened?
Availability.
Humidity in a server room becomes extremely low.
Which risk increases?
Electrostatic discharge.
Humidity becomes excessively high.
Which risks increase?
Condensation and corrosion.
The organisation wants a sprinkler design in which water is not normally present in the distribution pipes and detection occurs before water is admitted to the piping.
Which system is most relevant?
Pre-action sprinkler system.
Sprinkler piping permanently contains water ready for discharge.
Which system?
Wet-pipe system.
Sprinkler piping normally contains pressurised air rather than water.
Which system?
Dry-pipe system.
A data centre loses normal electrical supply and needs immediate power while its generator starts.
Which control provides the bridge?
UPS.
A facility must continue operating through an outage lasting several hours.
Which control is most relevant after the UPS bridge?
Backup generator.
A server has two power supplies, but both connect to one power distribution unit.
What is the architectural weakness?
The two power supplies share a single downstream point of failure.
A hard drive containing investigative evidence is moved between investigators without anyone recording the transfer.
What has been weakened?
Chain of custody.
Backup media contains highly confidential production data but is kept in an unlocked general storage room.
Primary problem?
Physical protection does not reflect the sensitivity of the information.
An unauthorised person follows an employee through a secure doorway before it closes.
What attack is demonstrated?
Tailgating.
A two-door controlled vestibule is installed to reduce the risk of people following authorised employees into a data centre.
Which control?
Mantrap / access-control vestibule.
A water sensor beneath a raised technical area generates an alarm when a pipe begins leaking.
What type of control is it?
Detective environmental control.
A generator has never been started under load since it was installed three years ago.
What is missing?
Regular testing and maintenance.
Management proposes a fire-suppression system that could seriously endanger occupants because it would better protect computer equipment.
What should take priority?
Human life and safety.
CCTV records a restricted door continuously, but nobody monitors alarms and there is no response procedure.
What is missing?
An effective response capability following detection.
A critical data centre has backup generators but all cooling equipment loses power during a utility outage.
What was overlooked?
Resilience must protect supporting infrastructure, not only IT equipment.
Recognise the Clue Words
Switches & Patch Panels
Physical network distribution.
Wiring Closet / IDFCritical Computing Equipment
Cooling, power, access and fire protection.
Server Room / Data CentreBackup Tapes
Inventory, environment and access.
Media StorageChain of Custody
Controlled handling and transfers.
Evidence StorageShoulder Surfing
Sensitive human workspace.
Restricted Work AreaStatic Electricity
Environment too dry.
Low HumidityCondensation
Environment too humid.
High HumidityWater Already in Pipes
Immediate sprinkler supply.
Wet PipeAir in Pipes
Water admitted after activation.
Dry PipeDetection Before Pipes Fill
Reduce accidental water exposure.
Pre-ActionImmediate Power Loss
Short-term bridge.
UPSExtended Power Loss
Longer-duration backup.
GeneratorTwo Power Supplies, Same PDU
Hidden dependency.
Single Point of FailureFollow Someone Through Door
Unauthorised physical access.
TailgatingTwo Controlled Doors
Restrict passage between zones.
MantrapFire vs Equipment
Which comes first?
Human Safety3.8 vs 3.9
| 3.8 Facility Design | 3.9 Facility Controls |
|---|---|
| Where should the data centre be? | How should access to it be controlled? |
| Where should critical rooms be positioned? | How should those rooms be monitored? |
| Which environmental threats influence location? | Which controls protect against those threats? |
| Where are the security zones? | Which controls enforce those zones? |
| Which utility dependencies should be avoided? | Which backup systems maintain service? |
3.8 vs 3.9
Design first โ Controls second
โ ๏ธ Common CISSP Mistakes Look beyond the obvious physical control
Wiring closets, server rooms and equipment may require additional internal access restrictions.
A backup may contain the same information as the production system.
Evidence requires additional accountability and chain-of-custody protection.
Loss of HVAC can become a major technology availability incident.
Excessively dry conditions can increase electrostatic-discharge risk.
Excess moisture can contribute to condensation and corrosion.
Detection identifies fire conditions.
Suppression controls the fire.
UPS provides immediate short-term power.
A generator can provide longer-duration backup power.
Both components may still share the same upstream or downstream point of failure.
Backup systems require maintenance, testing and fuel planning.
Monitoring can identify an incident, but someone or something must respond appropriately.
Human life remains the highest priority.
Cooling, networking, storage and supporting infrastructure also need appropriate resilience.
Quick Reference
| If you see... | Think... |
|---|---|
| Switches, patch panels and cabling | Wiring Closet / IDF |
| Critical servers and storage | Server Room / Data Centre |
| Backup tapes and removable drives | Media Storage |
| Chain of custody and tamper evidence | Evidence Storage |
| Clean desk and shoulder surfing | Restricted Work Area |
| Temperature and humidity | HVAC / Environmental Control |
| Very dry environment | Static / ESD Risk |
| Very humid environment | Condensation / Corrosion |
| Water already inside sprinkler pipes | Wet Pipe |
| Air normally inside sprinkler pipes | Dry Pipe |
| Detection required before piping fills | Pre-Action |
| Immediate temporary power | UPS |
| Longer-duration emergency power | Generator |
| Two systems share one dependency | Common Point of Failure |
| Person follows employee through door | Tailgating |
| Two controlled doors between security zones | Mantrap |
Physical & Environmental Security Memory Aid
Access ยท Monitor ยท Cool ยท Dry ยท Fire ยท Power ยท Recover
Fire Protection Memory Aid
People first. Equipment second.
Power Memory Aid
Power resilience is a chain - protect every link.
Key Takeaways
Physical and environmental controls protect the infrastructure on which information systems depend.
Physical security should deter, deny, delay, detect and support response.
Wiring closets and IDFs contain important network infrastructure and should be treated as restricted technical areas rather than general storage rooms.
Server rooms and data centres require layered physical access, monitoring, resilient power, cooling, fire protection and environmental controls.
Physical least privilege may require additional controls around individual racks or equipment even after a person enters a secure room.
Backup media can contain exactly the same sensitive information as production systems and should receive appropriate protection.
Evidence storage requires controlled access, chain of custody, access records and protection against tampering.
Sensitive work areas should address risks such as shoulder surfing, visitors, exposed documents, unsecured printing and inappropriate disposal.
HVAC is a security dependency because computing equipment requires appropriate temperature and humidity.
Excessively low humidity increases electrostatic-discharge risk, while excessive humidity can contribute to condensation and corrosion.
Cooling infrastructure may require redundancy because loss of cooling can cause an availability incident even while electrical power remains available.
Water damage can originate from plumbing, HVAC, roofs, fire systems and drainage as well as natural flooding.
Fire protection should combine prevention, detection, alerting, suppression and emergency procedures.
Wet-pipe systems normally contain water, while dry-pipe systems normally contain pressurised air or gas before activation.
Pre-action systems add a detection condition before water is admitted to the sprinkler piping, making them particularly relevant where accidental water exposure is a major concern.
Specialised gaseous or clean-agent systems can protect electronic environments, but life safety remains the highest priority.
Electrical security includes both power continuity and power quality.
A UPS provides immediate temporary power and can bridge the period before longer-duration backup power becomes available.
A generator can provide extended backup but depends on fuel, maintenance, transfer equipment and regular testing.
True redundancy requires independent paths. Two components connected to the same single dependency may still fail together.
Emergency power-off systems must be available when genuinely required while being protected against accidental or malicious activation.
Physical monitoring controls such as CCTV and access logs become more valuable when they are connected to an effective response capability.
Environmental and backup systems should be tested regularly rather than assumed to work because they were successfully installed.
For CISSP, remember the hierarchy: protect people first, maintain safe operations, protect equipment and preserve the ability to recover the business.
๐ Sources & Further Reading Physical and environmental security guidance
- ISC2 - CISSP Certification Exam Outline
View the current CISSP Exam Outline - NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations
View NIST security and privacy controls - NIST SP 800-53 - Physical and Environmental Protection Control Family
Explore NIST physical and environmental controls
