3.9 Physical & Environmental Security Controls

CISSP Domain 3 ยท Security Architecture and Engineering

3.9 Physical & Environmental Security Controls

Once a secure facility has been designed, physical and environmental controls must protect the people, systems, media and infrastructure operating inside it.

Effective physical security combines access control, monitoring, environmental protection, fire protection, utility resilience and emergency procedures rather than depending on a single defensive layer.

๐Ÿšช

Control Access

Restrict who can physically reach critical systems and information.

PHYSICAL ACCESS
๐ŸŒก๏ธ

Protect Environment

Manage temperature, humidity, water, fire and environmental hazards.

ENVIRONMENTAL CONTROL
โšก

Maintain Service

Protect power, cooling and other utilities needed for continued operation.

RESILIENCE

The Big Idea

Information systems depend on a physical environment.

A perfectly configured server is still unavailable if:

The power fails The room overheats Water enters the facility A fire destroys equipment An intruder reaches the hardware Critical cabling is damaged
๐Ÿšช Access โ†’ Who can reach it?
๐Ÿ‘๏ธ Monitoring โ†’ Would we know if someone entered?
๐ŸŒก๏ธ Environment โ†’ Can equipment operate safely?
๐Ÿ”ฅ Fire โ†’ Can fire be prevented, detected and controlled?
โšก Power โ†’ What happens when utility power fails?
๐Ÿ†˜ Emergency โ†’ Can people and systems respond safely?
CISSP 3.9 Scope

What You Need to Understand

Wiring Closets / IDFs

Protect network cabling and distribution equipment.

Server Rooms / Data Centres

Protect concentrated technology and critical services.

Media Storage

Protect stored information throughout the media lifecycle.

Evidence Storage

Preserve integrity, accountability and chain of custody.

Restricted Work Areas

Control people, information and activity in sensitive spaces.

Utilities & HVAC

Maintain the environmental services systems require.

Environmental Hazards

Protect against natural and human-caused events.

Fire Protection

Prevent, detect and suppress fire safely.

Power

Provide clean, redundant and backup electrical supply.

Physical Security Control Strategy

Different physical controls serve different purposes.

๐Ÿšจ Deter โ†’ Discourage the attempt
๐Ÿ›‘ Deny โ†’ Prevent unauthorised access
โณ Delay โ†’ Slow the attacker
๐Ÿ‘๏ธ Detect โ†’ Identify suspicious activity
๐Ÿš“ Respond โ†’ Take action after detection
Example

A reinforced door may: deny and delay.

CCTV may: deter and detect.

A security guard may: deter, detect and respond.

Physical Protection

DETER Don't try
DENY You cannot enter
DELAY Slow you down
DETECT We know you're there
RESPOND Someone acts
๐Ÿ”Œ Wiring Closets & Intermediate Distribution Facilities Network infrastructure is a critical physical asset

Wiring closets and Intermediate Distribution Facilities - IDFs - contain network cabling and equipment connecting users and systems to the wider network infrastructure.

They may contain:

Switches Patch Panels Fiber Connections Network Cabling Power Equipment Telecommunications Equipment
A wiring closet is not just a cupboard

Physical access to network distribution equipment may allow someone to disconnect services, attach unauthorised devices, interfere with cabling or disrupt connectivity.

Controls

Restricted Access

Only personnel with a legitimate requirement should enter.

Locked Doors

Network infrastructure should not be accessible through an unlocked general-purpose cupboard.

Access Logging

Access to important network facilities should be attributable.

Environmental Control

Networking equipment generates heat and requires appropriate ventilation.

Cabling Protection

Cables should be protected from accidental and deliberate damage.

Housekeeping

The room should not become general storage for combustible materials or unrelated equipment.

Poor practice

An IDF containing production switches is also used to store:

Cleaning chemicals Cardboard boxes Office supplies Personal belongings

This introduces unnecessary fire, accidental damage and access risk.

Wiring Closet

LOCK Control access
COOL Protect equipment
PROTECT Cabling
KEEP CLEAR Not a storage room
๐Ÿ–ฅ๏ธ Server Rooms & Data Centres High concentrations of technology, information and business dependency

Server rooms and data centres may support hundreds or thousands of business services.

Their physical compromise can therefore have organisation-wide impact.

Access Controls

Badge Access Biometric Controls Security Guards Mantraps CCTV Access Logs Visitor Escorts

Infrastructure Controls

Redundant Power

Critical workloads should not depend unnecessarily on one power path.

Backup Power

UPS systems and generators can maintain service when utility power fails.

Cooling

Heat generated by computing equipment must be removed reliably.

Fire Protection

Detection and suppression should protect life and critical infrastructure.

Water Detection

Leaks should be detected before they cause extensive damage.

Environmental Monitoring

Temperature, humidity and other important conditions should be monitored.

Concentration risk

A data centre provides efficiency by concentrating technology.

That concentration also makes power, cooling, fire protection and physical access especially important.

๐Ÿ—„๏ธ Racks & Equipment Protection Room access may not be sufficiently granular

Some environments require controls inside the data centre itself.

Colocation example

Several organisations host equipment in the same data-centre hall.

All authorised customers may enter the hall, but they should not automatically have physical access to another customer's servers.

Locked cages or racks can create additional boundaries.

Physical least privilege applies inside secure rooms too

Being authorised to enter the facility does not necessarily justify access to every rack, console or system.

๐Ÿ’พ Media Storage Facilities Protect information even when it is not inside a running system

Removable and backup media may contain complete copies of sensitive organisational information.

Examples include:

Backup Tapes External Drives Optical Media Removable Storage Archived Media

Protection Requirements

Access Control

Only authorised personnel should access sensitive media.

Inventory

The organisation should know which media exists and where it is.

Classification

Protection should reflect the sensitivity of the information stored.

Environmental Protection

Media should be stored under conditions appropriate to its technology.

Fire Protection

Important media requires appropriate protection from fire.

Secure Transport

Protection continues while media is moved between locations.

Backup example

A database is strongly protected in production.

Its nightly backup is copied onto removable media and left on an unattended desk.

The backup may contain the same sensitive information as production.

Backup โ‰  lower classification

Copying information onto backup media does not make the information less sensitive.

Media Storage

KNOW What you have
CONTROL Who can access it
PROTECT Its environment
TRACK Where it goes
๐Ÿ”Ž Evidence Storage Preserve integrity, authenticity and accountability

Evidence may be needed for internal investigation, disciplinary action, litigation, regulatory investigation or criminal proceedings.

Physical evidence therefore requires stronger accountability than ordinary storage.

Important Controls

Restricted Access

Only authorised evidence custodians or investigators should have access.

Chain of Custody

Transfers and handling should be documented.

Tamper Evidence

Packaging or containers can make unauthorised interference visible.

Access Records

The organisation should know who accessed evidence and when.

Environmental Protection

Evidence must be protected from conditions that could alter or destroy it.

Segregation

Evidence should not normally be mixed casually with ordinary operational media.

Collect โ†’ Identify
Identify โ†’ Package
Package โ†’ Record Transfer
Transfer โ†’ Secure Storage
Future Access โ†’ Record Again

Evidence

WHO? Handled it
WHEN? Was it transferred
WHERE? Was it stored
UNCHANGED? Can integrity be demonstrated
๐Ÿ” Restricted & Sensitive Work Areas Protect information during normal human activity

Sensitive information is often exposed not because a server is hacked, but because humans use information in physical workspaces.

Risks

Shoulder Surfing Unattended Documents Unlocked Screens Unattended Printers Visitors Photography Removable Media Conversations

Controls

Access Restrictions

Only people with a legitimate requirement should enter.

Clean Desk

Sensitive information should not remain exposed unnecessarily.

Screen Protection

Workstations should be positioned and configured to reduce unauthorised viewing.

Secure Printing

Sensitive documents should not sit unattended on shared printers.

Visitor Control

Visitors should be appropriately authorised, identified and escorted where necessary.

Secure Disposal

Sensitive papers and media should not enter ordinary waste streams without appropriate destruction.

Example

A fraud-investigation team works with confidential customer records.

Their office may require:

  • restricted physical access;
  • visitor controls;
  • secure document storage;
  • privacy-aware screen placement;
  • secure printing and disposal.
๐ŸŒก๏ธ Heating, Ventilation & Air Conditioning - HVAC Computers require a controlled operating environment

Computing equipment generates substantial heat.

Environmental systems must maintain appropriate conditions for the technology being protected.

Temperature

Too Hot

Equipment may throttle, become unstable, shut down or suffer accelerated component degradation.

Appropriate Range

Cooling should maintain operating conditions suitable for the equipment.

Humidity

Too Low

Very dry environments can increase the risk of electrostatic discharge.

Too High

Excessive moisture can contribute to condensation and corrosion.

Humidity

TOO DRY Static electricity
TOO WET Condensation / corrosion

Control both temperature AND humidity.

๐Ÿ’จ Cooling & Airflow Cooling capacity is only useful if air reaches the equipment

Data-centre layouts should manage how cool air reaches equipment and how hot exhaust air is removed.

Airflow Management

Prevent hot exhaust air from unnecessarily mixing with cool supply air.

Hot / Cold Aisles

Rack orientation can help separate equipment intake air from hot exhaust air.

Environmental Sensors

Monitoring should detect developing problems before systems reach unsafe conditions.

Cooling Redundancy

Critical environments should consider the consequences of losing a cooling component.

Cooling is an availability dependency

Servers may continue receiving electrical power after air conditioning fails, but they cannot continue operating indefinitely as heat accumulates.

๐Ÿ—๏ธ Utility Protection Critical systems depend on infrastructure beyond the server rack

Utility infrastructure can create both availability and physical hazards.

Electricity Cooling Water Telecommunications Fuel Drainage

Questions to Ask

Dependency โ†’ What does the facility depend on?
Failure โ†’ What happens when it stops?
Redundancy โ†’ Is another source available?
Diversity โ†’ Does the backup share the same failure point?
Testing โ†’ Does failover actually work?
๐Ÿ’ง Water Damage Protection Water does not need to originate from a flood

Water damage can result from:

Flooding Roof Leaks Plumbing HVAC Sprinkler Systems Drainage Failure

Controls

Location

Avoid placing critical equipment directly beneath unnecessary water sources where practical.

Leak Detection

Sensors can identify water before extensive damage occurs.

Drainage

Water needs a safe path away from critical equipment.

Shutoff Capability

Personnel should understand how relevant water supplies can be isolated when necessary.

CISSP-style example

A server room is located directly beneath employee bathrooms.

Even without a regional flood, plumbing failure creates an obvious environmental risk.

๐ŸŒช๏ธ Environmental Hazards Natural and human-caused events can both affect facilities
Natural Hazards
Flood Earthquake Storm Wildfire Lightning Extreme Heat
Human-Caused Hazards
Fire Sabotage Construction Damage Utility Failure Chemical Release Accidental Water Release
Design for consequences, not only intent

An accidental electrical failure can create the same service outage as deliberate sabotage.

Fire Protection

Understand What Sustains Fire

Fire suppression works by interfering with one or more conditions required to sustain combustion.

๐Ÿ”ฅ

Heat

Enough energy to sustain combustion.

REMOVE HEAT
๐ŸŒฌ๏ธ

Oxygen

Supports the combustion process.

REDUCE OXYGEN
๐Ÿชต

Fuel

Material available to burn.

REMOVE FUEL
Fire tetrahedron

A more complete model also includes the chemical chain reaction that sustains combustion.

Fire

HEAT +
FUEL +
OXYGEN +
CHAIN REACTION = sustained fire
๐Ÿ›‘ Fire Prevention The best fire is the one that never starts

Fire protection should begin with prevention rather than relying only on suppression after ignition.

Housekeeping

Remove unnecessary combustible materials.

Electrical Maintenance

Damaged or overloaded electrical systems can create ignition risk.

Controlled Storage

Flammable materials should not be stored casually near critical infrastructure.

Construction Materials

Appropriate fire-resistant materials can reduce fire spread.

Smoking Controls

Ignition sources should be controlled.

Maintenance

Equipment faults should be addressed before they become hazards.

๐Ÿšจ Fire Detection Detect the problem early enough to protect people and assets
Smoke Detection

Identifies products associated with smoke or combustion.

Heat Detection

Responds to elevated temperature or rapid temperature change, depending on the system.

Flame Detection

Detects characteristics associated with visible or invisible flame radiation.

Very Early Warning

Sensitive air-sampling systems can identify developing combustion before conventional conditions become severe.

Detection and suppression are different functions

A detector identifies the developing fire.

A suppression system attempts to control or extinguish it.

๐Ÿ’ฆ Water-Based Fire Suppression Wet pipe ยท Dry pipe ยท Pre-action ยท Deluge
Wet-Pipe System

Water is already present in the sprinkler piping.

Simple and capable of rapid response.

Dry-Pipe System

Pipes normally contain pressurised air or gas rather than water.

Activation allows water to enter the piping.

Pre-Action System

A detection event is normally required before water is admitted to the sprinkler piping.

This provides additional protection against accidental water release.

Deluge System

Designed to release large quantities of water through open discharge points when the system activates.

Used where rapid fire spread is a major concern.

Sprinkler Memory Aid

WET Water already in pipes
DRY Air first, water later
PRE-ACTION Detection before pipes fill
DELUGE Large rapid water release
Why pre-action is relevant to technology facilities

Accidental water release can itself damage computing equipment.

Pre-action designs add an additional activation condition before water enters the sprinkler network.

๐ŸŒซ๏ธ Clean-Agent & Gaseous Suppression Suppress fire without leaving water or powder residue

Some specialised environments use engineered gaseous or clean-agent suppression systems to reduce equipment damage associated with water or residue.

Advantages

Minimal Residue Suitable for Electronic Equipment Rapid Suppression

Design Considerations

Human Safety Room Integrity Agent Concentration Alarm Before Discharge Emergency Procedures Environmental Requirements
Life safety comes first

Any suppression technology used in occupied environments must be professionally designed around applicable life-safety requirements.

COโ‚‚ requires particular life-safety consideration

Carbon dioxide suppresses fire but can create a serious hazard for people at concentrations used for total-flooding fire suppression.

Halon is primarily a legacy concept

Halon is historically important in information-security study material, but its environmental impact led to substantial restrictions on new production and use.

CISSP Principle

Fire: Protect People First

1๏ธโƒฃ Human Life โ†’ Highest priority
2๏ธโƒฃ Environment / Facility โ†’ Contain the hazard
3๏ธโƒฃ Equipment โ†’ Protect where safely possible
4๏ธโƒฃ Information / Service โ†’ Recover using resilience controls
Do not sacrifice human safety to protect servers.
โšก Power Security Availability depends on both power quality and power continuity

Electrical problems can interrupt service or damage equipment even when power is not completely lost.

ConditionConcept
BlackoutComplete loss of electrical power.
BrownoutExtended reduction in supplied voltage.
SagShort-duration voltage reduction.
SpikeVery brief increase in voltage.
SurgeVoltage increase lasting longer than a very short spike.
Electrical NoiseUnwanted electrical disturbance affecting power quality.

Protective Measures

UPS Generator Surge Protection Power Conditioning Grounding Redundant Feeds Monitoring
๐Ÿ”‹ Uninterruptible Power Supply - UPS Bridge short-term power disruption

A UPS provides temporary electrical power when normal utility power is lost or unsuitable.

Normal Utility โ†’ Systems Operating
Utility Fails โ†’ UPS Supplies Power
UPS Window โ†’ Generator Starts OR systems shut down safely
UPS is normally the bridge, not the long-term power source

Batteries provide immediate power while longer-duration backup power becomes available or systems shut down safely.

A UPS Can Support

Immediate Backup Power Graceful Shutdown Power Conditioning Generator Start-Up Window
A UPS must be maintained and tested

Batteries degrade over time.

A UPS that has never been tested may fail precisely when it is required.

โ›ฝ Backup Generators Provide longer-duration power during extended outages

Backup generators can provide electrical power after a utility outage exceeds the practical battery capacity of a UPS.

Utility Power โŒ FAILS
UPS โ†’ Immediate temporary power
Generator โ†’ Starts
Transfer โ†’ Longer-duration backup supply

Generator Dependencies

Fuel Maintenance Starting System Cooling Transfer Equipment Testing
Hidden dependency

A facility has a generator capable of running for many hours.

However, the organisation has no reliable arrangement to replenish fuel during a regional emergency.

The generator therefore has a resilience limit that must be understood.

Power Resilience Chain

โšก Utility Supply โ†’ Normal Power
๐Ÿ”‹ UPS โ†’ Immediate Backup
โ›ฝ Generator โ†’ Extended Backup
๐Ÿ”Œ Distribution โ†’ Deliver power to equipment
๐Ÿ–ฅ๏ธ Equipment โ†’ Continue operating

Power Memory Aid

UTILITY Normal
UPS NOW
GENERATOR LONGER

UPS bridges the gap โ†’ Generator carries the load

๐Ÿ” Redundant Power Remove single points of failure from the electrical path

Critical infrastructure may use multiple power paths so failure of one component does not immediately interrupt service.

Power Path A โ†’ Equipment Supply A
Power Path B โ†’ Equipment Supply B
Dual-power server

A server contains two power supplies.

Both are plugged into the same PDU.

Both power supplies therefore fail if that single PDU loses power.

The server has duplicate components but not a fully independent power path.

Redundancy must be end-to-end

Duplicate components offer limited resilience if they eventually converge on the same single point of failure.

๐Ÿ›‘ Emergency Power Shutoff Sometimes removing power is the safest response

Facilities may need an emergency mechanism for quickly disconnecting electrical power when continued energisation creates a serious hazard.

Protect against accidental activation

An emergency shutoff is powerful by design.

Its location and protection should reduce the chance that an unauthorised or accidental action causes a major outage.

Example

Placing an unprotected emergency power-off button beside an ordinary light switch could introduce unnecessary availability risk.

๐Ÿ’ก Emergency Lighting Power failure must not prevent safe evacuation

Loss of normal power should not leave occupants unable to find exits or safely move through the facility.

Emergency lighting therefore supports:

Life Safety Evacuation Emergency Response Operational Safety
๐Ÿ“น Physical Access Monitoring Access control is stronger when events are visible and attributable
CCTV

Provides visual monitoring and potentially recorded evidence.

Access Logs

Record badge or other access-control events.

Security Guards

Provide human observation and response.

Door Alarms

Identify forced or unexpectedly open doors.

Intrusion Sensors

Detect unexpected physical movement or boundary crossing.

Review

Logs and recordings provide limited value if relevant events are never reviewed or monitored.

Detection needs response

A camera that records an intrusion but produces no timely response may provide evidence afterwards without actually stopping the attack.

Physical Access Authentication

The same authentication-factor concepts used in logical security also apply to physical access.

Something You Have

Badge, smart card or physical token.

Something You Know

PIN or access code.

Something You Are

Biometric characteristic.

High-security area

Access might require:

badge + PIN

or:

badge + biometric verification.

๐Ÿšช Mantraps / Access Control Vestibules Control passage between security zones

An access-control vestibule uses two controlled doors to regulate entry into a more restricted area.

Door 1 โ†’ Person enters controlled space
Verification โ†’ Access checked
Door 2 โ†’ Restricted area
Useful against tailgating

The design can make it harder for an unauthorised individual to simply follow an authorised person through a controlled entrance.

Life safety still applies

Physical access controls must be designed so they do not create an unsafe evacuation condition.

Practical Scenario

Protecting a Critical Data Centre

A financial organisation operates a data centre supporting critical customer services.

๐Ÿšง Facility Boundary โ†’ Controlled physical access
๐Ÿชช Building Entrance โ†’ Authentication and monitoring
๐Ÿšช Data Centre Entry โ†’ Additional restricted access
๐Ÿ—„๏ธ Equipment โ†’ Locked racks where appropriate
๐ŸŒก๏ธ Environment โ†’ Redundant cooling and monitoring
๐Ÿ”ฅ Fire โ†’ Detection and appropriate suppression
โšก Power โ†’ UPS + generator + redundant distribution
๐Ÿ’ง Water โ†’ Leak detection and safe drainage
๐Ÿ“น Monitoring โ†’ CCTV and access records
Facility resilience comes from independent layers, not one impressive security control.
Failure Scenario

Utility Power Suddenly Fails

0 seconds โ†’ Utility power lost
Immediately โ†’ UPS maintains critical load
Shortly Afterwards โ†’ Generator starts
Transfer โ†’ Generator supports critical load
Extended Outage โ†’ Fuel and maintenance become critical
What else must remain powered?

Protecting only the servers is insufficient if cooling, network infrastructure or supporting systems fail during the outage.

๐ŸŽ“ CISSP Scenarios Identify the physical or environmental control
Scenario 1

A network distribution closet containing production switches is left unlocked in a public corridor.

Primary issue?

Inadequate physical access protection for network infrastructure.

Scenario 2

The same wiring closet is also used to store cardboard boxes and cleaning chemicals.

Primary concern?

Unnecessary fire, environmental and accidental-damage risk.

Scenario 3

A server-room cooling system fails while electrical power continues operating normally.

What security objective is threatened?

Availability.

Scenario 4

Humidity in a server room becomes extremely low.

Which risk increases?

Electrostatic discharge.

Scenario 5

Humidity becomes excessively high.

Which risks increase?

Condensation and corrosion.

Scenario 6

The organisation wants a sprinkler design in which water is not normally present in the distribution pipes and detection occurs before water is admitted to the piping.

Which system is most relevant?

Pre-action sprinkler system.

Scenario 7

Sprinkler piping permanently contains water ready for discharge.

Which system?

Wet-pipe system.

Scenario 8

Sprinkler piping normally contains pressurised air rather than water.

Which system?

Dry-pipe system.

Scenario 9

A data centre loses normal electrical supply and needs immediate power while its generator starts.

Which control provides the bridge?

UPS.

Scenario 10

A facility must continue operating through an outage lasting several hours.

Which control is most relevant after the UPS bridge?

Backup generator.

Scenario 11

A server has two power supplies, but both connect to one power distribution unit.

What is the architectural weakness?

The two power supplies share a single downstream point of failure.

Scenario 12

A hard drive containing investigative evidence is moved between investigators without anyone recording the transfer.

What has been weakened?

Chain of custody.

Scenario 13

Backup media contains highly confidential production data but is kept in an unlocked general storage room.

Primary problem?

Physical protection does not reflect the sensitivity of the information.

Scenario 14

An unauthorised person follows an employee through a secure doorway before it closes.

What attack is demonstrated?

Tailgating.

Scenario 15

A two-door controlled vestibule is installed to reduce the risk of people following authorised employees into a data centre.

Which control?

Mantrap / access-control vestibule.

Scenario 16

A water sensor beneath a raised technical area generates an alarm when a pipe begins leaking.

What type of control is it?

Detective environmental control.

Scenario 17

A generator has never been started under load since it was installed three years ago.

What is missing?

Regular testing and maintenance.

Scenario 18

Management proposes a fire-suppression system that could seriously endanger occupants because it would better protect computer equipment.

What should take priority?

Human life and safety.

Scenario 19

CCTV records a restricted door continuously, but nobody monitors alarms and there is no response procedure.

What is missing?

An effective response capability following detection.

Scenario 20

A critical data centre has backup generators but all cooling equipment loses power during a utility outage.

What was overlooked?

Resilience must protect supporting infrastructure, not only IT equipment.

CISSP Exam Perspective

Recognise the Clue Words

Switches & Patch Panels

Physical network distribution.

Wiring Closet / IDF

Critical Computing Equipment

Cooling, power, access and fire protection.

Server Room / Data Centre

Backup Tapes

Inventory, environment and access.

Media Storage

Chain of Custody

Controlled handling and transfers.

Evidence Storage

Shoulder Surfing

Sensitive human workspace.

Restricted Work Area

Static Electricity

Environment too dry.

Low Humidity

Condensation

Environment too humid.

High Humidity

Water Already in Pipes

Immediate sprinkler supply.

Wet Pipe

Air in Pipes

Water admitted after activation.

Dry Pipe

Detection Before Pipes Fill

Reduce accidental water exposure.

Pre-Action

Immediate Power Loss

Short-term bridge.

UPS

Extended Power Loss

Longer-duration backup.

Generator

Two Power Supplies, Same PDU

Hidden dependency.

Single Point of Failure

Follow Someone Through Door

Unauthorised physical access.

Tailgating

Two Controlled Doors

Restrict passage between zones.

Mantrap

Fire vs Equipment

Which comes first?

Human Safety

3.8 vs 3.9

3.8 Facility Design3.9 Facility Controls
Where should the data centre be?How should access to it be controlled?
Where should critical rooms be positioned?How should those rooms be monitored?
Which environmental threats influence location?Which controls protect against those threats?
Where are the security zones?Which controls enforce those zones?
Which utility dependencies should be avoided?Which backup systems maintain service?

3.8 vs 3.9

3.8 DESIGN the environment
3.9 CONTROL the environment

Design first โ†’ Controls second

โš ๏ธ Common CISSP Mistakes Look beyond the obvious physical control
Locked Building โ‰  Secure Infrastructure

Wiring closets, server rooms and equipment may require additional internal access restrictions.

Backup Media โ‰  Less Sensitive

A backup may contain the same information as the production system.

Evidence Storage โ‰  Ordinary Media Storage

Evidence requires additional accountability and chain-of-custody protection.

Cooling Failure โ‰  Minor Facilities Issue

Loss of HVAC can become a major technology availability incident.

Low Humidity โ‰  Always Better

Excessively dry conditions can increase electrostatic-discharge risk.

High Humidity โ‰  Harmless

Excess moisture can contribute to condensation and corrosion.

Detector โ‰  Suppression System

Detection identifies fire conditions.

Suppression controls the fire.

UPS โ‰  Generator

UPS provides immediate short-term power.

A generator can provide longer-duration backup power.

Two Components โ‰  True Redundancy

Both components may still share the same upstream or downstream point of failure.

Generator Installed โ‰  Generator Reliable

Backup systems require maintenance, testing and fuel planning.

CCTV โ‰  Response

Monitoring can identify an incident, but someone or something must respond appropriately.

Fire Suppression โ‰  Protect Equipment at Any Cost

Human life remains the highest priority.

Server Power โ‰  Complete Resilience

Cooling, networking, storage and supporting infrastructure also need appropriate resilience.

Quick Reference

If you see...Think...
Switches, patch panels and cablingWiring Closet / IDF
Critical servers and storageServer Room / Data Centre
Backup tapes and removable drivesMedia Storage
Chain of custody and tamper evidenceEvidence Storage
Clean desk and shoulder surfingRestricted Work Area
Temperature and humidityHVAC / Environmental Control
Very dry environmentStatic / ESD Risk
Very humid environmentCondensation / Corrosion
Water already inside sprinkler pipesWet Pipe
Air normally inside sprinkler pipesDry Pipe
Detection required before piping fillsPre-Action
Immediate temporary powerUPS
Longer-duration emergency powerGenerator
Two systems share one dependencyCommon Point of Failure
Person follows employee through doorTailgating
Two controlled doors between security zonesMantrap

Physical & Environmental Security Memory Aid

ACCESS Who can reach it?
MONITOR Would we know?
COOL Can equipment operate safely?
DRY Is water controlled?
FIRE Prevent ยท Detect ยท Suppress
POWER Can systems continue operating?
RECOVER What happens when controls fail?

Access ยท Monitor ยท Cool ยท Dry ยท Fire ยท Power ยท Recover

Fire Protection Memory Aid

PREVENT Stop ignition
DETECT Know it started
ALARM Warn people
SUPPRESS Control the fire
EVACUATE Protect life

People first. Equipment second.

Power Memory Aid

UTILITY Normal source
UPS Immediate bridge
GENERATOR Extended backup
REDUNDANCY Remove single failure points
TEST Prove it works

Power resilience is a chain - protect every link.

Key Takeaways

Physical and environmental controls protect the infrastructure on which information systems depend.

Physical security should deter, deny, delay, detect and support response.

Wiring closets and IDFs contain important network infrastructure and should be treated as restricted technical areas rather than general storage rooms.

Server rooms and data centres require layered physical access, monitoring, resilient power, cooling, fire protection and environmental controls.

Physical least privilege may require additional controls around individual racks or equipment even after a person enters a secure room.

Backup media can contain exactly the same sensitive information as production systems and should receive appropriate protection.

Evidence storage requires controlled access, chain of custody, access records and protection against tampering.

Sensitive work areas should address risks such as shoulder surfing, visitors, exposed documents, unsecured printing and inappropriate disposal.

HVAC is a security dependency because computing equipment requires appropriate temperature and humidity.

Excessively low humidity increases electrostatic-discharge risk, while excessive humidity can contribute to condensation and corrosion.

Cooling infrastructure may require redundancy because loss of cooling can cause an availability incident even while electrical power remains available.

Water damage can originate from plumbing, HVAC, roofs, fire systems and drainage as well as natural flooding.

Fire protection should combine prevention, detection, alerting, suppression and emergency procedures.

Wet-pipe systems normally contain water, while dry-pipe systems normally contain pressurised air or gas before activation.

Pre-action systems add a detection condition before water is admitted to the sprinkler piping, making them particularly relevant where accidental water exposure is a major concern.

Specialised gaseous or clean-agent systems can protect electronic environments, but life safety remains the highest priority.

Electrical security includes both power continuity and power quality.

A UPS provides immediate temporary power and can bridge the period before longer-duration backup power becomes available.

A generator can provide extended backup but depends on fuel, maintenance, transfer equipment and regular testing.

True redundancy requires independent paths. Two components connected to the same single dependency may still fail together.

Emergency power-off systems must be available when genuinely required while being protected against accidental or malicious activation.

Physical monitoring controls such as CCTV and access logs become more valuable when they are connected to an effective response capability.

Environmental and backup systems should be tested regularly rather than assumed to work because they were successfully installed.

For CISSP, remember the hierarchy: protect people first, maintain safe operations, protect equipment and preserve the ability to recover the business.

๐Ÿ“š Sources & Further Reading Physical and environmental security guidance