7.14 Physical Security Operations

CISSP Domain 7 ยท Security Operations

7.14 Physical Security Operations

Cybersecurity does not stop at the network boundary.

An attacker who can enter a restricted facility may be able to steal equipment, connect a rogue device, access network ports, remove storage media, interfere with cabling, tamper with hardware or observe sensitive information directly.

Physical security therefore controls who can physically reach the organisation's people, facilities, information and technology.

CISSP 7.14 focuses on the operational side of this protection: implementing and managing perimeter and internal physical security controls.

๐Ÿข

Perimeter

Control who and what can approach and enter the protected facility.

KEEP THREATS OUT
๐Ÿšช

Internal

Restrict movement inside the facility according to business need.

LIMIT WHERE THEY CAN GO
๐Ÿ‘๏ธ

Monitor

Detect suspicious access and respond when controls are bypassed.

KNOW WHAT IS HAPPENING
Current CISSP 7.14 Scope

Implement and Manage Physical Security

The current CISSP Exam Outline explicitly identifies two areas.

Perimeter Security Controls

Controls protecting the outer boundary and access points of a site or facility.

Fences Gates Barriers Lighting Guards Cameras Alarms
Internal Security Controls

Controls restricting and monitoring movement after a person has entered the facility.

Badges Locks Access Zones Visitors Server Rooms Internal CCTV Access Logs

Official 7.14 Scope

PERIMETER Control entry to the site
INTERNAL Control movement inside
Cross-Domain Distinction

Domain 3 vs Domain 5 vs Domain 7

Domain 3.8 / 3.9

Site and facility security architecture and design.

Think: HOW SHOULD THE FACILITY BE DESIGNED?

Domain 5.1

Control physical and logical access to assets.

Think: WHO IS AUTHORISED?

Domain 7.14

Implement and manage operational physical security controls.

Think: HOW DO WE OPERATE THE PHYSICAL CONTROLS?

Design ยท Authorise ยท Operate

DOMAIN 3 Design physical security
DOMAIN 5 Authorise physical access
DOMAIN 7 Operate physical security

What Are We Protecting Against?

Unauthorised Entry

Intruders entering buildings or restricted areas.

Theft

Removal of devices, media, documents or other assets.

Tampering

Modification or interference with systems, cabling or equipment.

Sabotage

Deliberate damage intended to disrupt operations.

Espionage

Observation, photography, recording or theft of sensitive information.

Accidental Access

People entering areas where they do not belong.

Insider Threat

Misuse of legitimate physical access.

Hardware Attack

Physical access used to bypass or weaken logical security controls.

Critical Security Principle

Physical Access Can Undermine Logical Security

Highly secured server
MFA Firewall EDR Encryption SIEM

An unauthorised individual obtains physical access to the server room.

They may attempt to:

Steal Hardware Connect USB Media Connect Rogue Network Device Access Console Ports Remove Drives Reset Equipment Tamper With Cabling
Logical controls and physical controls reinforce one another. Neither should be treated as a complete substitute for the other.
Defense in Depth

Physical Security Uses Layers

Property Boundary โ†’ Perimeter Controls
Building Entrance โ†’ Entry Controls
Internal Building โ†’ Security Zones
Restricted Area โ†’ Additional Authentication
Critical Asset โ†’ Asset-Specific Protection
The objective is not one perfect barrier. It is multiple layers an attacker must overcome.

Physical Security Operational Model

DETER Discourage the attempt
DETECT Know the attempt is happening
DELAY Slow the attacker
RESPOND Intervene
๐Ÿ›ก๏ธ Why Delay Matters A barrier does not need to be impossible to defeat to be useful
Fence โ†’ Delays Entry
Camera โ†’ Detects Activity
Alarm โ†’ Notifies Security
Security Team โ†’ Responds
Physical barriers are especially valuable when they delay an attacker long enough for detection and response to succeed.
Official 7.14 Topic 1

Perimeter Security Controls

Perimeter controls establish and protect the outer boundary around a facility or protected site.

Fences & Walls

Establish a visible and physical boundary.

Gates

Channel authorised vehicles and people through controlled entry points.

Vehicle Barriers

Bollards and other barriers can restrict unauthorised vehicle approach.

Lighting

Supports visibility, monitoring and deterrence.

CCTV

Provides surveillance and evidence of activity around the boundary.

Intrusion Detection

Sensors or alarms can identify attempted perimeter breaches.

Security Guards

Provide observation, verification and human response.

Signage

Communicates property boundaries and access restrictions.

Channel People Through Controlled Entry Points

Poor design / operation

Main entrance: badge controlled.

Side loading door: frequently left unlocked.

An attacker will generally prefer: the easiest path.

Strong control at one entrance does not compensate for an uncontrolled alternate entrance.
๐Ÿš— Vehicle Controls Physical security applies to vehicles as well as people
Bollards Vehicle Gates Security Barriers Controlled Parking Vehicle Inspection Delivery Controls
Vehicle controls can prevent unauthorised approach to sensitive facilities and channel deliveries through controlled locations.

Security Lighting

Lighting is often a supporting rather than standalone control.

Deterrence

An intruder may be less willing to operate where they are easily visible.

Surveillance

Cameras require adequate conditions to observe activity effectively.

Guard Visibility

Personnel can more easily identify unusual activity.

Lighting โ‰  Access Control

Lighting supports other controls but does not itself determine whether a person is authorised to enter.

Human Control

Security Guards

Observe

Identify suspicious people, vehicles or behaviour.

Verify

Confirm identity and access authorisation.

Challenge

Question individuals who appear to be somewhere they should not be.

Respond

React to alarms, incidents and unauthorised activity.

Assist

Support visitors, emergency response and evacuation procedures.

Escalate

Contact security management or emergency services when required.

Human controls need procedures

Guards require appropriate training, communication, escalation procedures and clearly defined authority.

Monitoring

CCTV / Video Surveillance

Detection

Observe suspicious activity.

Assessment

Help security personnel understand what triggered an alarm.

Investigation

Provide records that may assist investigation after an event.

Deterrence

Visible surveillance may discourage some activity.

๐Ÿ“น A Camera Existing Does Not Mean the Area Is Monitored Effectively Operational management matters

Physical security teams should consider:

Camera Health Coverage Image Quality Lighting Retention Time Synchronisation Tamper Detection Monitoring Responsibility
Incident

Security attempts to review footage.

Camera covering the door: failed three months ago.

Installed control โ‰  functioning control.

CCTV Is Primarily Detective

Camera

Records an intruder entering: restricted room.

If nobody responds and no door control prevents access:

the camera may provide: evidence rather than prevention.

Camera + Door + Response

DOOR Restrict
CAMERA Observe
ALARM Notify
SECURITY Respond
Detection

Physical Intrusion Alarms

Alarm systems can detect conditions such as:

Door Forced Open Door Held Open Window Breach Motion Fence Disturbance Restricted-Area Entry
Detection is valuable only when an appropriate response process follows the alarm.
๐Ÿ”” Physical Security Can Have Alert Fatigue Too Repeated nuisance alarms can weaken response
Loading door

Generates: 40 false door-open alarms every day.

Guards begin: ignoring the alarm.

Poorly tuned or poorly maintained physical detection controls can degrade human response just like noisy cyber alerts.
Official 7.14 Topic 2

Internal Security Controls

Passing through the building entrance should not automatically grant access to every room inside.

Security Zones

Divide the facility according to sensitivity and business need.

Badge Readers

Verify authorised credentials at internal access points.

Locks

Restrict physical entry to rooms, cabinets and equipment.

Turnstiles / Interlocks

Control the number and flow of people entering sensitive areas.

Internal CCTV

Monitor sensitive corridors, entrances and restricted areas.

Visitor Controls

Limit and supervise non-employee access.

Secure Storage

Protect keys, media, evidence, documents and valuable equipment.

Access Records

Record who entered controlled areas and when.

Security Zones

Public Area โ†’ Lobby
Controlled Area โ†’ Employee Office
Restricted Area โ†’ Operations Room
Highly Restricted Area โ†’ Data Centre / Sensitive Vault
Physical access should become progressively more restricted as asset sensitivity increases.
Least Privilege

Physical Least Privilege

Employee

Works in: Marketing.

Needs access to: office floor and meeting rooms.

Does not need access to:

Data Centre Network Closets Evidence Room Backup Media Vault
Being authorised to enter the building does not imply authorisation to enter every internal area.
Physical Access Control System

PACS

A Physical Access Control System can authenticate and authorise people or vehicles at controlled entry points.

Person โ†’ Presents Credential
Credential โ†’ Identify / Authenticate
Access Policy โ†’ Authorise
Door / Gate โ†’ Grant or Deny
Access Event โ†’ Log

Physical AAA

WHO? Identity
ALLOWED? Authorisation
WHEN / WHERE? Accountability

Physical Access Credentials

Physical Key

Traditional possession-based access device.

PIN / Combination

Knowledge used to unlock a controlled area.

Badge / Smart Card

Electronic credential presented to an access-control reader.

Biometric

Uses a physical or behavioural characteristic to assist authentication.

Multi-Factor Physical Access

Sensitive areas may require more than one authentication factor.

Operational Management

Physical Access Has a Lifecycle

Business Need โ†’ Request Access
Request โ†’ Approve
Approval โ†’ Issue Credential
Access โ†’ Monitor
Role Changes โ†’ Review / Modify
Access No Longer Needed โ†’ Revoke
Credential โ†’ Recover / Disable

Physical Access Lifecycle

AUTHORISE Approve access
ISSUE Provide credential
MONITOR Observe use
REVIEW Still needed?
REVOKE Remove access
๐Ÿชช Employment Ends - Physical Access Ends Too Logical deprovisioning is only part of offboarding

Termination or transfer may require:

Disable Badge Recover Keys Change Combinations Remove Parking Access Remove Restricted-Area Access Recover ID Card
Account disabled โ‰  building access disabled.

Review Physical Access Regularly

Employee

Transferred from: Data Centre Operations

to: Procurement.

Their badge still permits: 24/7 data-centre access.

Physical access should be reviewed and removed when the business need disappears.
Physical Credentials

Key & Combination Management

Inventory

Know which keys and access devices exist.

Issue

Record who receives sensitive keys.

Storage

Secure spare and master keys.

Recovery

Retrieve keys when no longer required.

Lost Key Response

Assess whether locks need to be replaced or re-keyed.

Combination Change

Change combinations when compromise or personnel change requires it.

Access-Control Scenario

The Shared Door Code

Restricted storage room uses: one PIN shared by 40 employees.

An employee leaves.

Organisation cannot determine: which specific person entered using the code.

Shared physical credentials weaken individual accountability.
Door Behaviour

Fail-Safe vs Fail-Secure Locks

Fail-Safe

The locking mechanism releases when power is lost.

Emphasis: life safety / availability of exit.

Fail-Secure

The locking mechanism remains secure against entry when power is lost.

Emphasis: security of the protected area.

Important life-safety nuance

Door and lock behaviour must comply with applicable life-safety and emergency-egress requirements. A door intended to remain secure against entry must not improperly trap occupants inside.

Fail-Safe vs Fail-Secure

FAIL-SAFE Power lost โ†’ lock releases
FAIL-SECURE Power lost โ†’ entry remains secured

Security Must Not Defeat Life Safety

Emergency

Fire alarm activates.

Employees must be able to: leave the building safely.

Physical access controls should prevent unauthorised entry without creating unsafe emergency egress.
High-Security Entry

Access-Control Vestibule / Interlock

A secure vestibule, sometimes called a mantrap, uses two controlled doors so that access can be verified before a person passes fully into the protected area.

Door 1 โ†’ Enter Vestibule
Person โ†’ Verify
Door 1 โ†’ Secure
Door 2 โ†’ Release
The control helps prevent several people simply following one authorised person through a sensitive entrance.

Turnstiles & Controlled Passage

Turnstiles can help enforce: one credentialed person per access event.

Benefit

Reduces uncontrolled flow through access points.

Limitation

The mechanism must still be monitored for bypass, jumping or tailgate behaviour.

Social Engineering

Tailgating & Piggybacking

Both terms are commonly used for situations where an unauthorised person gains physical access by following an authorised person through a controlled entrance.

Some organisations distinguish:

Tailgating

The authorised person may be unaware that someone has followed them.

Piggybacking

The authorised person knowingly or helpfully allows another person through.

Terminology varies

Do not rely too heavily on the distinction between the two words. The security problem is unauthorised entry by following an authorised person.

Social Engineering Scenario

The Delivery Box

Attacker approaches employee entrance carrying: a large box.

Employee badges through the door.

Attacker says:

"Could you hold that for me? My hands are full."

Employee holds the secured door open.

Physical security awareness is necessary because social engineering can bypass technically functioning doors and badge readers.
๐Ÿ” Anti-Passback Reduce credential sharing and impossible access sequences

Some physical access systems track entry and exit state.

Badge record

Badge already recorded: inside the facility.

Same badge attempts: another entry without an exit.

The system may: deny or flag the event.

Anti-passback can make simple credential sharing more difficult and identify unusual access sequences.
Visitor Management

Visitors Are Different From Employees

Visitors typically require controlled temporary access.

Arrival โ†’ Verify Identity / Purpose
Host โ†’ Confirm Visit
Visitor โ†’ Register
Temporary Access โ†’ Issue Visitor Badge
Restricted Areas โ†’ Escort / Control
Departure โ†’ Sign Out / Recover Badge

Visitor Memory Aid

VERIFY Who are they?
AUTHORISE Why are they here?
IDENTIFY Visitor badge
LIMIT Where can they go?
ESCORT Where required
RECORD Entry and departure
Visitor Scenario

The Network Engineer

External engineer arrives to repair: a core switch.

Reception confirms: the maintenance appointment.

But the engineer does not automatically require access to:

Entire Data Centre Backup Vault Security Operations Room Other Network Rooms
Visitor and contractor access should be limited to the locations necessary for the authorised purpose.
๐Ÿท๏ธ Visitor Identification Make temporary access visually distinguishable

A visitor badge can help employees and guards identify:

Temporary Access Host Permitted Area Expiry
A visitor badge identifies temporary status. It does not automatically authorise unrestricted movement.
Physical Monitoring

Physical Access Logs

Physical access systems can create audit records describing:

Identity / Credential Door / Area Date Time Entry / Exit Granted / Denied Alarm Event
Physical access should be observable and accountable where the risk warrants it.

What Might Physical Access Monitoring Detect?

Unusual Time

Entry at 03:00 by an employee who normally works office hours.

Unusual Area

Access to locations unrelated to the person's role.

Repeated Denials

Multiple attempts against restricted doors.

Unusual Duration

Person remains in a sensitive area much longer than expected.

Out-of-Sequence Access

Physical movement appears inconsistent with expected entry and exit records.

Forced Door

Door opened without a valid access event.

An anomalous badge event is an indicator to investigate, not automatic proof of malicious activity.
๐Ÿ”— Physical + Logical Correlation Different logs can tell a stronger story together
Physical access

Employee badge shows: London office at 09:02.

Logical access

Same account authenticates: from another country at 09:04.

Physical and logical telemetry can provide useful context when investigating unusual activity.
Credential Scenario

Lost Access Badge

Employee reports: corporate badge missing.

Report โ†’ Disable Credential
Recent Activity โ†’ Review if Appropriate
Employee โ†’ Verify Identity
Replacement โ†’ Issue New Credential
Lost credential = potential unauthorised access path until it is disabled.
Control Failure Scenario

The Propped-Open Door

Employees prop a secure door open because: they are repeatedly carrying equipment through it.

Badge reader remains: fully operational.

But everyone can now: walk around the control.

A functioning security mechanism can still be defeated by operational behaviour.
Critical Internal Area

Server Rooms & Data Centres

Restricted Access Access Logging Visitor Escort CCTV Door Alarms Locked Racks Key Management Environmental Monitoring
The more critical the assets within an area, the stronger and more closely monitored the physical access controls are likely to need to be.

Do Not Forget Wiring Closets

Network closet

Contains:

Switches Patch Panels Network Cabling Management Ports

Unauthorised physical access could allow someone to:

Disconnect Network Connect Rogue Device Observe Cabling Tamper With Equipment
A network closet is part of the security boundary, not merely a maintenance cupboard.
Physical Communications Protection

Protect Transmission Paths

Physical access to communications cabling and distribution points can create opportunities for:

Damage Disconnection Tampering Unauthorised Connections Interception

Controls can include:

Locked Wiring Closets Conduit Protected Cable Routes Secured Spare Ports Tamper Monitoring

Protect Output Devices Too

Printers

Sensitive documents should not sit unattended in public locations.

Displays

Position sensitive screens to reduce unauthorised observation.

Copiers / Scanners

Restrict access when they handle sensitive information.

Audio

Consider whether conversations or audio output can be overheard.

Data can leave a secure system through a physical output device.
๐Ÿ‘€ Shoulder Surfing Sometimes information theft requires no technical exploit
Visitor

Waits near reception.

Nearby employee laptop displays: sensitive customer records.

Screen position, privacy filters and staff awareness can be physical information-security controls.
Deliveries & Removal

Loading Docks & Deliveries

Delivery areas can create an alternative route into a facility.

Verify Delivery

Confirm the shipment or collection is expected.

Control Entry

Drivers and couriers should not receive unnecessary internal access.

Separate Sensitive Areas

Loading areas should not provide uncontrolled access to critical assets.

Control Removal

Valuable equipment leaving the facility may require authorisation.

Asset Removal Scenario

The Server on the Trolley

Individual wearing contractor clothing pushes: a server toward the loading dock.

They say: "It's being taken for repair."

No one checks: whether removal was authorised.

Physical security should consider assets leaving the facility as well as people entering it.

Visible Identification

Organisations may use visible identification to help employees recognise:

Employees Visitors Contractors Temporary Staff
Visible identification supports challenge culture: people who do not belong are easier to notice.
โ“ Challenge Culture Employees are part of physical security

An unfamiliar person is walking inside: a restricted employee area without identification.

Appropriate response might be to:

Politely Challenge Contact Security Follow Organisational Procedure
Physical security awareness helps employees recognise and report suspicious access rather than assuming someone else will handle it.

Physical Information Exposure

Documents

Sensitive paperwork left on desks can be read or removed.

Whiteboards

Architecture diagrams and credentials should not remain exposed to unauthorised visitors.

Portable Devices

Laptops and removable media can be stolen.

Waste

Sensitive information should not enter ordinary waste without appropriate destruction.

Privacy

Physical Monitoring Also Creates Information

Access logs, visitor records and video surveillance can contain information about individuals.

Organisations therefore need appropriate rules for:

Purpose Access Retention Disclosure Security Applicable Privacy Requirements
Security monitoring should itself be appropriately governed and protected.

Emergency Access

Emergency responders may need rapid physical access that differs from normal operations.

Fire Service Medical Responders Facilities Team Emergency Maintenance
Emergency access procedures should support safety without creating an unmanaged permanent bypass of normal controls.
๐Ÿ‘ฅ Two-Person / Dual-Control Areas Some sensitive activities may require more than one authorised person

High-value physical processes can be designed so that one person cannot perform the entire sensitive activity alone.

Example

Opening a sensitive vault requires: two authorised individuals.

Dual control reduces the risk that one individual can independently misuse sensitive physical access.
Incident Response

Physical Security Events Need Response Procedures

Forced Door Lost Badge Tailgating Unknown Person Camera Tampering Broken Fence Missing Equipment Repeated Access Denials
Detect โ†’ Verify
Verify โ†’ Respond
Response โ†’ Protect / Contain
Event โ†’ Document / Investigate
Finding โ†’ Correct
Cyber-Physical Scenario

Unknown Device in the Network Closet

Technician discovers: an unfamiliar small device connected to a network switch.

Appropriate response may require coordination between:

Physical Security Network Security Incident Response Digital Forensics
Physical security incidents can become cybersecurity incidents and vice versa.
Monitoring Scenario

The 02:47 Data Centre Entry

Badge log records: developer entering the data centre at 02:47.

Developer normally works: 09:00โ€“17:00.

The event should not automatically be labelled malicious.

It should be: validated against authorised activity.

Anomaly โ‰  incident. Anomaly = investigate the context.
Detection Scenario

One Badge - Two People

Access system records: one successful badge entry.

Camera shows: two people entering.

Correlating access-control records with surveillance can reveal tailgating that the badge system alone cannot see.

Physical Security Logs Need Protection

Access records can support investigations and accountability.

Therefore consider:

Access Restrictions Integrity Time Synchronisation Retention Availability
An attacker who can erase the physical access log can weaken evidence of how they entered.
Operational Assurance

Test Physical Security Controls

Badge Test

Are revoked credentials actually denied?

Door Alarm Test

Does a forced or held-open door generate the expected alert?

CCTV Test

Are cameras functioning and recording usable footage?

Visitor Test

Are visitors appropriately verified and escorted?

Key Audit

Can sensitive physical keys be accounted for?

Response Test

Do security personnel respond appropriately to alarms?

Control documented โ‰  control operational.

Physical Controls Require Maintenance

Doors Locks Badge Readers Cameras Lighting Fences Alarms Intercoms Barriers
Security gate

Broken for: six weeks.

Staff workaround: leave gate open during office hours.

A broken security control that remains broken can become the normal operating state.
โš ๏ธ Temporary Physical Security Exceptions Control the workaround
Badge reader failure

Temporary process: guard manually verifies access.

Good temporary control should have:

Owner Procedure Monitoring Expiry Repair Action
Temporary workaround โ‰  permanent uncontrolled bypass.
Monitoring Effectiveness

Useful Physical Security Metrics

Access Revocation

Are terminated or transferred personnel removed promptly?

Door Alarms

How many forced or held-open door events occur?

Response Time

How quickly are significant physical alarms investigated?

Camera Availability

What proportion of surveillance capability is operational?

Visitor Exceptions

How often are visitor procedures bypassed?

Lost Credentials

Are missing badges and keys reported and disabled promptly?

Branch Scenario

The Small Remote Office

Headquarters has:

24/7 Guards Turnstiles CCTV Badge-Controlled Server Rooms

Small branch office has: an unlocked networking cabinet in reception.

Security requirements should follow the assets and risk, not merely the size or prestige of the building.
Control Scenario

The Camera-Protected Server Room

Server-room door: unlocked.

Camera: records everyone entering.

Detective control does not replace appropriate preventive access control.
Control Scenario

The Perfect Lock With No Monitoring

Restricted room has: a strong electronic lock.

Door is forced overnight.

No alarm, camera or guard detects it until: next morning.

Preventive and detective physical controls should complement one another.
Offboarding Scenario

The Forgotten Badge

Employee leaves organisation on Friday.

Logical accounts: disabled.

Building badge: remains active.

Effective offboarding includes both logical and physical access.
Key Scenario

The Missing Master Key

Master key can open: every restricted office on the floor.

Key cannot be located.

The greater the access granted by a physical credential, the greater the impact if that credential is lost or compromised.
Visitor Scenario

The Unescorted Cleaner

Cleaning contractor has legitimate reason to enter: office areas.

Same credential also opens: the evidence-storage room.

Legitimate presence in the building does not justify unnecessary access to restricted areas.
Information Scenario

The Reception Printer

Sensitive HR report prints to: a shared printer beside visitor reception.

Physical security includes protecting where sensitive information is displayed, printed and collected.
Monitoring Scenario

The Camera Blind Spot

Main corridor: well monitored.

Emergency stairwell: not covered.

Stairwell provides: access to the same restricted floor.

Physical security should consider alternative routes around the primary control.
๐Ÿ“ท Do Not Expose Credentials Unnecessarily Physical access information itself can be sensitive
Social media

Employee posts selfie showing: high-resolution corporate badge.

Exposed information might reveal:

Name Employee Number Organisation Badge Appearance Access Information
Physical-security credentials should not be treated as harmless souvenirs.
Control Types

Physical Controls Can Serve Different Functions

FunctionPhysical Example
DeterrentVisible guards, fencing, warning signage
PreventiveLocked door, gate, bollard, turnstile
DetectiveCCTV, door alarm, motion sensor
CorrectiveRepairing a compromised barrier or access control
CompensatingGuard stationed at a door while the badge reader is broken

Strong Physical Security

BOUNDARY Define protected area
ACCESS Verify authorisation
MONITOR Detect activity
RECORD Maintain accountability
RESPOND Act on incidents
REVIEW Keep controls effective
๐ŸŽ“ CISSP Scenarios Recognise the physical security principle being tested
Scenario 1

A fence surrounds the organisation's property.

Which type of control?

Perimeter physical security control.

Scenario 2

A badge reader controls entry to the data centre.

Which category?

Internal physical security control.

Scenario 3

A camera records people entering a restricted room.

Primary control function?

Detective / monitoring.

Scenario 4

A locked door stops unauthorised entry.

Primary control function?

Preventive.

Scenario 5

Visible guards discourage attempted intrusion.

Which additional function?

Deterrent.

Scenario 6

A broken badge reader is temporarily replaced by a security guard checking identification.

Which control concept?

Compensating control.

Scenario 7

The main entrance is strongly protected but an unlocked side door leads to the same facility.

Primary weakness?

Alternative uncontrolled entry path.

Scenario 8

An employee can enter the office but has no business need to enter the data centre.

Which principle?

Physical least privilege.

Scenario 9

Employee changes role but retains access to highly restricted rooms.

What should occur?

Review and modify physical access.

Scenario 10

An employee leaves the organisation.

What should happen to the badge?

Physical access should be revoked and credential recovered or disabled.

Scenario 11

A lost badge remains active for several days.

Primary concern?

It can potentially be used for unauthorised physical access.

Scenario 12

One door PIN is shared by 100 people.

Primary weakness?

Poor individual accountability.

Scenario 13

A master key is lost.

Why is this particularly serious?

Its broad access increases the potential impact of compromise.

Scenario 14

A visitor arrives for an authorised meeting.

Should this automatically grant unrestricted building access?

No.

Scenario 15

A contractor requires access to one network cabinet.

Best principle?

Limit physical access to the authorised need.

Scenario 16

A visitor walks around a restricted floor without escort.

Which control has failed?

Visitor activity control / escort process.

Scenario 17

An unauthorised person follows an employee through a secured entrance.

Which threat?

Tailgating / piggybacking.

Scenario 18

An employee politely holds the secured door for an unknown person.

What helped bypass security?

Social engineering / human behaviour.

Scenario 19

A turnstile permits one person for each successful credential event.

What risk does this help reduce?

Uncontrolled multiple-person entry.

Scenario 20

Two badge entries occur without an intervening exit.

Which mechanism may flag this?

Anti-passback.

Scenario 21

A door unlocks when electrical power fails.

Which lock behaviour?

Fail-safe.

Scenario 22

A door remains secured against entry when power fails.

Which behaviour?

Fail-secure.

Scenario 23

A fire occurs while access-controlled doors are operating.

Highest priority?

Human life and safe emergency egress.

Scenario 24

A secure vestibule allows the first door to close before the second opens.

Which physical control?

Access-control vestibule / interlock.

Scenario 25

A camera records an intruder but does nothing to stop entry.

Primary lesson?

Detective control is not necessarily preventive.

Scenario 26

A locked room has no surveillance or alarms.

Primary lesson?

Preventive and detective controls should complement each other.

Scenario 27

CCTV camera has been offline for three months.

Primary issue?

The control exists but is not operationally effective.

Scenario 28

A door generates dozens of false alarms every day and guards begin ignoring it.

Primary concern?

Alarm fatigue and degraded response.

Scenario 29

Badge access occurs at 03:00 for an office-hours employee.

Does this prove malicious activity?

No. It is an anomaly requiring context and investigation.

Scenario 30

Badge logs show one entry while CCTV shows two people.

Likely issue?

Tailgating or other unauthorised entry.

Scenario 31

A secure door is propped open for convenience.

Primary lesson?

Operational behaviour can bypass a functioning technical control.

Scenario 32

A server room is secure but its network closet is unlocked.

Primary concern?

Critical network infrastructure remains physically exposed.

Scenario 33

Unused network jacks in a public area remain connected.

Physical-security consideration?

Restrict or secure access to communications infrastructure.

Scenario 34

Sensitive documents print beside a public waiting area.

Which concern?

Physical access to output devices and information.

Scenario 35

A visitor can see confidential information on an employee's monitor.

Which risk?

Visual exposure / shoulder surfing.

Scenario 36

A courier can walk directly from the loading dock into the data centre corridor.

Primary concern?

Delivery area provides an uncontrolled internal access path.

Scenario 37

An expensive server leaves the building without verification.

Which process is weak?

Physical control of equipment removal.

Scenario 38

An employee posts a detailed photograph of their corporate access badge online.

Primary concern?

Exposure of physical credential information.

Scenario 39

Access logs are deleted after an intrusion.

What has been weakened?

Accountability and investigation evidence.

Scenario 40

Badge log shows employee in London while their account logs in from another country two minutes later.

What can this demonstrate?

Value of correlating physical and logical access information.

Scenario 41

A badge reader breaks and a guard manually verifies authorised staff until repair.

Which concept?

Temporary compensating control.

Scenario 42

A temporary door-control workaround remains in place for six months.

Primary concern?

A temporary security exception has become the normal state.

Scenario 43

Security installs expensive cameras but never verifies whether they are functioning.

Primary lesson?

Physical security controls require monitoring, testing and maintenance.

Scenario 44

What is the distinction between Domain 3.9 and 7.14?

Best answer?

Domain 3 focuses on facility control design; Domain 7.14 focuses on implementing and managing physical security operations.

Scenario 45

Management asks for the main principle of 7.14.

Best answer?

Use layered perimeter and internal controls to authorise, restrict, monitor and record physical access, then maintain and respond to those controls throughout their operational lifecycle.

CISSP Exam Perspective

Recognise the Clue Words

Outside Boundary

Site protection.

Perimeter Control

Inside Building

Restricted movement.

Internal Control

Discourage Entry

Control purpose.

Deterrent

Stop Entry

Control purpose.

Preventive

Observe Entry

Control purpose.

Detective

Broken Reader + Guard

Temporary alternative.

Compensating Control

Person / Vehicle Authentication

Electronic access.

PACS

Building Access but Not Data Centre

Authorisation.

Physical Least Privilege

Employee Changes Role

Access lifecycle.

Review Access

Employee Leaves

Offboarding.

Revoke Badge / Keys

Person Follows Another

Unauthorised entry.

Tailgating / Piggybacking

Two Controlled Doors

High-security entry.

Access Vestibule / Interlock

One Person per Badge

Access flow.

Turnstile

Badge Entered Twice

Sequence control.

Anti-Passback

Unlocks on Power Loss

Door behaviour.

Fail-Safe

Stays Secure on Power Loss

Door behaviour.

Fail-Secure

Temporary External Person

Access management.

Visitor Control

Unusual 03:00 Entry

Monitoring.

Investigate Access Log

Door Forced

Detection.

Physical Alarm

Observe Area

Surveillance.

CCTV

Vehicle Threat

Perimeter.

Bollard / Barrier

Network Closet

Infrastructure.

Restricted Physical Access

Printer Exposes Data

Information.

Output Device Protection

Equipment Leaves Site

Asset control.

Delivery / Removal Control

Security System Exists but Broken

Operations.

Maintenance / Testing
โš ๏ธ Common CISSP Mistakes Physical security is layered and operational
Cybersecurity โ‰  Only Logical Security

Physical access can expose systems, devices and information.

One Strong Door โ‰  Secure Facility

Attackers may use another entrance.

Inside Building โ‰  Authorised Everywhere

Use internal security zones and least privilege.

Badge Issued โ‰  Badge Needed Forever

Physical access requires lifecycle review.

Logical Account Disabled โ‰  Physical Access Disabled

Offboarding includes badges, keys and building access.

Shared Door Code โ‰  Individual Accountability

Shared credentials make attribution harder.

Visitor Badge โ‰  Unrestricted Access

Visitor movement should remain controlled.

Contractor โ‰  Employee-Level Access

Give access required for the authorised task.

CCTV โ‰  Preventive Lock

Cameras primarily support monitoring and investigation.

Lock โ‰  Detection

A lock may delay entry without alerting anyone that it was defeated.

Alarm โ‰  Response

Someone or something must act on the detection.

Camera Installed โ‰  Camera Working

Surveillance requires operational monitoring and maintenance.

Lighting โ‰  Access Control

Lighting supports deterrence and observation.

Fence โ‰  Impossible to Cross

Physical controls can still be valuable by delaying and detecting an intruder.

Tailgating โ‰  Technical Failure Only

Human behaviour can bypass perfectly functioning doors.

Tailgating vs Piggybacking โ‰  Universal Definition

Terminology varies. Focus on the unauthorised following behaviour.

Fail-Safe โ‰  Fail-Secure

One releases on loss of power; the other maintains entry security.

Security โ‰  Trapping People

Emergency life safety and egress requirements remain paramount.

Badge Anomaly โ‰  Proof of Attack

Investigate business context.

Physical Log โ‰  Automatically Trustworthy Forever

Protect its integrity, availability and retention.

Data Centre Secure โ‰  Network Secure

Wiring closets and cabling also need physical protection.

Screen โ‰  Private Because System Is Authenticated

Sensitive information can still be visually observed.

Printer โ‰  Harmless Peripheral

Physical outputs can expose protected information.

Delivery Entrance โ‰  Trusted Entrance

Loading areas require physical access controls too.

Asset Leaving โ‰  Automatically Authorised

Removal of sensitive equipment may require verification.

Temporary Door Bypass โ‰  Permanent Solution

Temporary exceptions require ownership and remediation.

Installed Control โ‰  Managed Control

Test, monitor and maintain physical controls.

Domain 3.9 โ‰  Domain 7.14

Domain 3 emphasises physical facility design. Domain 7.14 emphasises implementation and operational management.

Quick Reference

If you see...Think...
Outer site boundaryPerimeter Security
Restricted area inside buildingInternal Security
Fence / wallBoundary / delay
BollardVehicle Barrier
CameraDetective / Surveillance
Locked doorPreventive Access Control
Guard while reader brokenCompensating Control
Electronic building accessPACS
Only required roomsPhysical Least Privilege
Person follows employee through doorTailgating / Piggybacking
Two controlled doorsSecurity Vestibule / Interlock
One person per entryTurnstile
Impossible badge sequenceAnti-Passback
Unlock on power lossFail-Safe
Remain secure on power lossFail-Secure
Temporary non-employeeVisitor Control
Who entered and when?Physical Access Log
03:00 unusual entryInvestigate Access Anomaly
Forced doorPhysical Intrusion Alarm
Network cablingTransmission Path Protection
Unsecured printerOutput Device Protection
Equipment leaving buildingDelivery / Removal Controls
Employee leavesRevoke Badge + Recover Keys
System installed but never checkedOperational Testing / Maintenance

Perimeter Memory Aid

BOUNDARY Fence / wall
CHANNEL Gate / entrance
BLOCK Barrier / bollard
SEE Lighting / CCTV
DETECT Alarm / sensor
RESPOND Guard / security team

Internal Security Memory Aid

IDENTIFY Who are you?
AUTHORISE Where may you go?
RESTRICT Doors + zones
MONITOR Cameras + alarms
LOG Who went where?
REVIEW Still required?

Physical Defense Memory Aid

DETER Make attack unattractive
DETECT See the attack
DELAY Slow the attacker
RESPOND Stop or manage the event

7.14 Master Memory Aid

PERIMETER Control approach to site
ENTRY Verify access
ZONES Restrict internal movement
VISITORS Verify + limit + escort
MONITOR Cameras + alarms + logs
RESPOND Act on physical incidents
REVIEW Access + control effectiveness

Deter โ†’ Restrict โ†’ Detect โ†’ Record โ†’ Respond โ†’ Review

The Physical Security Manager's Questions

BOUNDARY? Where does the protected area begin?
ENTRY? How do people and vehicles enter?
AUTHORISED? Who should have access?
NEED? Which areas do they actually require?
VISITORS? How is temporary access controlled?
TAILGATING? Can someone bypass the entry process?
MONITORED? Can suspicious activity be detected?
LOGGED? Can physical access be reconstructed?
RESPONDED? What happens when an alarm occurs?
SAFE? Does security preserve emergency egress?
WORKING? Are cameras, locks and alarms operational?
CURRENT? Are old badges and keys revoked?
TESTED? Do the controls actually work?

Key Takeaways

CISSP 7.14 is officially: Implement and manage physical security.

The current ISC2 outline explicitly identifies: perimeter security controls and internal security controls.

Physical security protects people, facilities, information and technology against unauthorised physical access.

Cybersecurity does not stop at the network boundary.

Physical access can allow an attacker to steal hardware, connect rogue devices, tamper with cabling, access consoles, remove storage media or directly observe sensitive information.

Physical controls and logical controls reinforce one another.

Physical security should normally use multiple layers.

Layers may include property boundaries, building entrances, internal security zones and additional protection around critical assets.

A useful physical-security model is:

deter โ†’ detect โ†’ delay โ†’ respond.

A barrier does not need to be impossible to defeat in order to provide value.

If it delays an attacker long enough for detection and response, it has contributed to security.

Perimeter security protects the outer boundary.

Examples include fences, walls, gates, vehicle barriers, lighting, guards, cameras and intrusion alarms.

Strong protection at one entrance does not compensate for another uncontrolled entrance.

Physical access should therefore be channelled through controlled entry and exit points.

Bollards and other vehicle barriers can help control vehicle approach to sensitive facilities.

Security lighting supports surveillance, deterrence and guard visibility.

Lighting supports security but is not itself access authorisation.

Security guards provide flexible human observation and response.

Guards may verify identity, challenge suspicious individuals, respond to alarms and coordinate emergencies.

Human security controls require training and clearly defined procedures.

CCTV provides valuable monitoring and investigative capability.

Cameras are primarily detective controls.

A camera recording an intrusion does not necessarily prevent the intrusion.

Camera = observe. Lock = restrict. Alarm = notify. Response = act.

Surveillance equipment must be maintained.

A camera that has been offline for months does not provide useful monitoring merely because it remains mounted on the wall.

Camera coverage, image quality, lighting, retention, timestamps and monitoring responsibility should therefore be considered.

Physical intrusion alarms can detect forced doors, held-open doors, movement and other suspicious conditions.

Detection is only useful when there is an appropriate response.

Excessive nuisance alarms can also cause security personnel to stop treating alarms seriously.

Internal physical security restricts movement after someone has entered the facility.

Entering the building does not automatically authorise entry into every room.

Organisations can establish progressively restricted internal security zones.

Public areas might include reception. Controlled areas might include normal employee offices. Restricted areas might include operations rooms. Highly restricted areas might include data centres or evidence storage.

Physical access should follow the principle of least privilege.

Give people access to the areas required for their role - not every area they might conceivably want to enter.

Physical Access Control Systems can authenticate and authorise people or vehicles at controlled entry points.

Physical credentials can include keys, badges, smart cards, combinations and biometric mechanisms.

Sensitive areas may require stronger authentication than ordinary office areas.

Physical access has a lifecycle.

Access should be authorised, issued, monitored, periodically reviewed and revoked when no longer required.

A transfer between roles should trigger review of physical as well as logical privileges.

Termination should include physical credential revocation.

Account disabled โ‰  badge disabled.

Keys and combinations are also security credentials.

Sensitive keys should be inventoried, securely stored and recovered when no longer required.

Loss of a master key can have much greater impact than loss of a key to a single room.

Shared physical credentials reduce accountability.

If 50 people use the same door code, the organisation may know that the code was used but not which authorised person used it.

Electronic locks can behave differently during power failure.

Fail-safe locks release when power is lost.

Fail-secure locks remain secured against entry when power is lost.

Life-safety and emergency-egress requirements remain paramount.

Security must not improperly trap people inside a dangerous building.

Secure access vestibules or interlocks can provide additional control around highly sensitive entrances.

Turnstiles can help enforce one-person-per-credential entry.

Tailgating and piggybacking describe unauthorised entry by following someone through a controlled entrance.

Some organisations distinguish tailgating as occurring without the authorised person's knowledge and piggybacking as occurring with their cooperation.

The terminology is not universally used consistently.

The important concept is: someone bypassed individual physical authentication.

Physical security is therefore vulnerable to social engineering.

A perfectly functioning badge reader cannot stop an employee from holding a secure door open for an unauthorised person.

Employee awareness and challenge culture are therefore part of effective physical security.

Anti-passback mechanisms can detect or prevent certain impossible badge sequences, such as the same credential entering twice without a recorded exit.

Visitors require temporary controlled access.

Visitor processes may include identity verification, host confirmation, registration, temporary badges, limited access, escort and sign-out.

Visitor badge โ‰  unrestricted access.

Contractors should receive only the physical access required for their authorised work.

Physical access logging provides accountability.

Useful records can identify the credential, location, time and access result.

Monitoring can identify events such as after-hours entry, repeated denied access, unusual locations and forced doors.

Unusual physical access โ‰  automatically malicious.

Context should be investigated.

Physical and logical logs can sometimes be correlated.

If a badge shows an employee entering one geographic location while the same user's logical identity authenticates from an implausibly distant location at almost the same time, that correlation may deserve investigation.

Physical logs themselves should be appropriately protected.

Their integrity, retention, availability and timestamps can matter during investigations.

Critical internal areas include server rooms, data centres, wiring closets and restricted storage.

Network closets should not be overlooked.

Physical access to switches, patch panels and cabling can permit disruption, tampering or unauthorised network connection.

Communications transmission paths may require physical protection.

Locked wiring closets, protected cable routes, conduit and controlled network ports can help reduce physical tampering risk.

Physical output devices also require consideration.

Printers, screens, scanners and other output mechanisms can expose data even when the underlying computer system is strongly authenticated.

Secure system โ‰  secure information if the output is physically exposed.

Shoulder surfing and unauthorised visual observation can reveal sensitive information without exploiting any software vulnerability.

Delivery areas and loading docks are additional access routes that should be controlled.

Organisations should consider both people entering and assets leaving the facility.

Equipment removal may require authorisation.

A person wearing contractor clothing should not automatically be allowed to push a server out of the building.

Access badges and other physical-security identifiers can themselves contain sensitive information.

Employees should avoid unnecessarily exposing detailed credentials in photographs or public posts.

Physical-security monitoring creates information about people.

CCTV, visitor logs and access records should therefore be appropriately governed, retained and protected according to applicable requirements.

Emergency access may require special arrangements for emergency services or facilities personnel.

These arrangements should support safety without creating an uncontrolled permanent bypass.

Physical security incidents need response procedures.

Examples include forced doors, lost credentials, tailgating, unknown individuals, damaged barriers, camera tampering and missing equipment.

Physical and cybersecurity incident response can overlap.

A rogue device discovered in a wiring closet may require both physical investigation and technical incident response.

Physical controls require maintenance and testing.

Locks, badge readers, cameras, barriers, lighting and alarms should not simply be installed and forgotten.

Installed control โ‰  functioning control.

Temporary compensating controls may be required when normal controls fail.

For example, a guard might manually verify employees while a badge reader is being repaired.

Temporary exceptions should have an owner, procedure and path back to the normal control.

Useful physical-security measurements can include access revocation, forced-door events, camera availability, visitor exceptions, lost credentials and alarm-response time.

Domain 3.9 and Domain 7.14 should not be confused.

Domain 3.9 concentrates on designing site and facility security controls.

Domain 7.14 concentrates on implementing and managing physical security during day-to-day operations.

The central CISSP principle is:

establish layered perimeter and internal physical controls, grant access according to business need, monitor and record sensitive physical activity, control visitors and credentials, respond to suspicious events, preserve life safety and continuously verify that the controls remain operational and appropriate.

๐Ÿ“š Sources & Further Reading Current physical-security and access-control references