7.14 Physical Security Operations
7.14 Physical Security Operations
Cybersecurity does not stop at the network boundary.
An attacker who can enter a restricted facility may be able to steal equipment, connect a rogue device, access network ports, remove storage media, interfere with cabling, tamper with hardware or observe sensitive information directly.
Physical security therefore controls who can physically reach the organisation's people, facilities, information and technology.
CISSP 7.14 focuses on the operational side of this protection: implementing and managing perimeter and internal physical security controls.
Perimeter
Control who and what can approach and enter the protected facility.
KEEP THREATS OUTInternal
Restrict movement inside the facility according to business need.
LIMIT WHERE THEY CAN GOMonitor
Detect suspicious access and respond when controls are bypassed.
KNOW WHAT IS HAPPENINGImplement and Manage Physical Security
The current CISSP Exam Outline explicitly identifies two areas.
Controls protecting the outer boundary and access points of a site or facility.
Controls restricting and monitoring movement after a person has entered the facility.
Official 7.14 Scope
Domain 3 vs Domain 5 vs Domain 7
Site and facility security architecture and design.
Think: HOW SHOULD THE FACILITY BE DESIGNED?
Control physical and logical access to assets.
Think: WHO IS AUTHORISED?
Implement and manage operational physical security controls.
Think: HOW DO WE OPERATE THE PHYSICAL CONTROLS?
Design ยท Authorise ยท Operate
What Are We Protecting Against?
Intruders entering buildings or restricted areas.
Removal of devices, media, documents or other assets.
Modification or interference with systems, cabling or equipment.
Deliberate damage intended to disrupt operations.
Observation, photography, recording or theft of sensitive information.
People entering areas where they do not belong.
Misuse of legitimate physical access.
Physical access used to bypass or weaken logical security controls.
Physical Access Can Undermine Logical Security
An unauthorised individual obtains physical access to the server room.
They may attempt to:
Physical Security Uses Layers
Physical Security Operational Model
๐ก๏ธ Why Delay Matters A barrier does not need to be impossible to defeat to be useful
Perimeter Security Controls
Perimeter controls establish and protect the outer boundary around a facility or protected site.
Establish a visible and physical boundary.
Channel authorised vehicles and people through controlled entry points.
Bollards and other barriers can restrict unauthorised vehicle approach.
Supports visibility, monitoring and deterrence.
Provides surveillance and evidence of activity around the boundary.
Sensors or alarms can identify attempted perimeter breaches.
Provide observation, verification and human response.
Communicates property boundaries and access restrictions.
Channel People Through Controlled Entry Points
Main entrance: badge controlled.
Side loading door: frequently left unlocked.
An attacker will generally prefer: the easiest path.
๐ Vehicle Controls Physical security applies to vehicles as well as people
Security Lighting
Lighting is often a supporting rather than standalone control.
An intruder may be less willing to operate where they are easily visible.
Cameras require adequate conditions to observe activity effectively.
Personnel can more easily identify unusual activity.
Lighting supports other controls but does not itself determine whether a person is authorised to enter.
Security Guards
Identify suspicious people, vehicles or behaviour.
Confirm identity and access authorisation.
Question individuals who appear to be somewhere they should not be.
React to alarms, incidents and unauthorised activity.
Support visitors, emergency response and evacuation procedures.
Contact security management or emergency services when required.
Guards require appropriate training, communication, escalation procedures and clearly defined authority.
CCTV / Video Surveillance
Observe suspicious activity.
Help security personnel understand what triggered an alarm.
Provide records that may assist investigation after an event.
Visible surveillance may discourage some activity.
๐น A Camera Existing Does Not Mean the Area Is Monitored Effectively Operational management matters
Physical security teams should consider:
Security attempts to review footage.
Camera covering the door: failed three months ago.
CCTV Is Primarily Detective
Records an intruder entering: restricted room.
If nobody responds and no door control prevents access:
the camera may provide: evidence rather than prevention.
Camera + Door + Response
Physical Intrusion Alarms
Alarm systems can detect conditions such as:
๐ Physical Security Can Have Alert Fatigue Too Repeated nuisance alarms can weaken response
Generates: 40 false door-open alarms every day.
Guards begin: ignoring the alarm.
Internal Security Controls
Passing through the building entrance should not automatically grant access to every room inside.
Divide the facility according to sensitivity and business need.
Verify authorised credentials at internal access points.
Restrict physical entry to rooms, cabinets and equipment.
Control the number and flow of people entering sensitive areas.
Monitor sensitive corridors, entrances and restricted areas.
Limit and supervise non-employee access.
Protect keys, media, evidence, documents and valuable equipment.
Record who entered controlled areas and when.
Security Zones
Physical Least Privilege
Works in: Marketing.
Needs access to: office floor and meeting rooms.
Does not need access to:
PACS
A Physical Access Control System can authenticate and authorise people or vehicles at controlled entry points.
Physical AAA
Physical Access Credentials
Traditional possession-based access device.
Knowledge used to unlock a controlled area.
Electronic credential presented to an access-control reader.
Uses a physical or behavioural characteristic to assist authentication.
Sensitive areas may require more than one authentication factor.
Physical Access Has a Lifecycle
Physical Access Lifecycle
๐ชช Employment Ends - Physical Access Ends Too Logical deprovisioning is only part of offboarding
Termination or transfer may require:
Review Physical Access Regularly
Transferred from: Data Centre Operations
to: Procurement.
Their badge still permits: 24/7 data-centre access.
Key & Combination Management
Know which keys and access devices exist.
Record who receives sensitive keys.
Secure spare and master keys.
Retrieve keys when no longer required.
Assess whether locks need to be replaced or re-keyed.
Change combinations when compromise or personnel change requires it.
The Shared Door Code
Restricted storage room uses: one PIN shared by 40 employees.
An employee leaves.
Organisation cannot determine: which specific person entered using the code.
Fail-Safe vs Fail-Secure Locks
The locking mechanism releases when power is lost.
Emphasis: life safety / availability of exit.
The locking mechanism remains secure against entry when power is lost.
Emphasis: security of the protected area.
Door and lock behaviour must comply with applicable life-safety and emergency-egress requirements. A door intended to remain secure against entry must not improperly trap occupants inside.
Fail-Safe vs Fail-Secure
Security Must Not Defeat Life Safety
Fire alarm activates.
Employees must be able to: leave the building safely.
Access-Control Vestibule / Interlock
A secure vestibule, sometimes called a mantrap, uses two controlled doors so that access can be verified before a person passes fully into the protected area.
Turnstiles & Controlled Passage
Turnstiles can help enforce: one credentialed person per access event.
Reduces uncontrolled flow through access points.
The mechanism must still be monitored for bypass, jumping or tailgate behaviour.
Tailgating & Piggybacking
Both terms are commonly used for situations where an unauthorised person gains physical access by following an authorised person through a controlled entrance.
Some organisations distinguish:
The authorised person may be unaware that someone has followed them.
The authorised person knowingly or helpfully allows another person through.
Do not rely too heavily on the distinction between the two words. The security problem is unauthorised entry by following an authorised person.
The Delivery Box
Attacker approaches employee entrance carrying: a large box.
Employee badges through the door.
Attacker says:
"Could you hold that for me? My hands are full."
Employee holds the secured door open.
๐ Anti-Passback Reduce credential sharing and impossible access sequences
Some physical access systems track entry and exit state.
Badge already recorded: inside the facility.
Same badge attempts: another entry without an exit.
The system may: deny or flag the event.
Visitors Are Different From Employees
Visitors typically require controlled temporary access.
Visitor Memory Aid
The Network Engineer
External engineer arrives to repair: a core switch.
Reception confirms: the maintenance appointment.
But the engineer does not automatically require access to:
๐ท๏ธ Visitor Identification Make temporary access visually distinguishable
A visitor badge can help employees and guards identify:
Physical Access Logs
Physical access systems can create audit records describing:
What Might Physical Access Monitoring Detect?
Entry at 03:00 by an employee who normally works office hours.
Access to locations unrelated to the person's role.
Multiple attempts against restricted doors.
Person remains in a sensitive area much longer than expected.
Physical movement appears inconsistent with expected entry and exit records.
Door opened without a valid access event.
๐ Physical + Logical Correlation Different logs can tell a stronger story together
Employee badge shows: London office at 09:02.
Same account authenticates: from another country at 09:04.
Lost Access Badge
Employee reports: corporate badge missing.
The Propped-Open Door
Employees prop a secure door open because: they are repeatedly carrying equipment through it.
Badge reader remains: fully operational.
But everyone can now: walk around the control.
Server Rooms & Data Centres
Do Not Forget Wiring Closets
Contains:
Unauthorised physical access could allow someone to:
Protect Transmission Paths
Physical access to communications cabling and distribution points can create opportunities for:
Controls can include:
Protect Output Devices Too
Sensitive documents should not sit unattended in public locations.
Position sensitive screens to reduce unauthorised observation.
Restrict access when they handle sensitive information.
Consider whether conversations or audio output can be overheard.
๐ Shoulder Surfing Sometimes information theft requires no technical exploit
Waits near reception.
Nearby employee laptop displays: sensitive customer records.
Loading Docks & Deliveries
Delivery areas can create an alternative route into a facility.
Confirm the shipment or collection is expected.
Drivers and couriers should not receive unnecessary internal access.
Loading areas should not provide uncontrolled access to critical assets.
Valuable equipment leaving the facility may require authorisation.
The Server on the Trolley
Individual wearing contractor clothing pushes: a server toward the loading dock.
They say: "It's being taken for repair."
No one checks: whether removal was authorised.
Visible Identification
Organisations may use visible identification to help employees recognise:
โ Challenge Culture Employees are part of physical security
An unfamiliar person is walking inside: a restricted employee area without identification.
Appropriate response might be to:
Physical Information Exposure
Sensitive paperwork left on desks can be read or removed.
Architecture diagrams and credentials should not remain exposed to unauthorised visitors.
Laptops and removable media can be stolen.
Sensitive information should not enter ordinary waste without appropriate destruction.
Physical Monitoring Also Creates Information
Access logs, visitor records and video surveillance can contain information about individuals.
Organisations therefore need appropriate rules for:
Emergency Access
Emergency responders may need rapid physical access that differs from normal operations.
๐ฅ Two-Person / Dual-Control Areas Some sensitive activities may require more than one authorised person
High-value physical processes can be designed so that one person cannot perform the entire sensitive activity alone.
Opening a sensitive vault requires: two authorised individuals.
Physical Security Events Need Response Procedures
Unknown Device in the Network Closet
Technician discovers: an unfamiliar small device connected to a network switch.
Appropriate response may require coordination between:
The 02:47 Data Centre Entry
Badge log records: developer entering the data centre at 02:47.
Developer normally works: 09:00โ17:00.
The event should not automatically be labelled malicious.
It should be: validated against authorised activity.
One Badge - Two People
Access system records: one successful badge entry.
Camera shows: two people entering.
Physical Security Logs Need Protection
Access records can support investigations and accountability.
Therefore consider:
Test Physical Security Controls
Are revoked credentials actually denied?
Does a forced or held-open door generate the expected alert?
Are cameras functioning and recording usable footage?
Are visitors appropriately verified and escorted?
Can sensitive physical keys be accounted for?
Do security personnel respond appropriately to alarms?
Physical Controls Require Maintenance
Broken for: six weeks.
Staff workaround: leave gate open during office hours.
โ ๏ธ Temporary Physical Security Exceptions Control the workaround
Temporary process: guard manually verifies access.
Good temporary control should have:
Useful Physical Security Metrics
Are terminated or transferred personnel removed promptly?
How many forced or held-open door events occur?
How quickly are significant physical alarms investigated?
What proportion of surveillance capability is operational?
How often are visitor procedures bypassed?
Are missing badges and keys reported and disabled promptly?
The Small Remote Office
Headquarters has:
Small branch office has: an unlocked networking cabinet in reception.
The Camera-Protected Server Room
Server-room door: unlocked.
Camera: records everyone entering.
The Perfect Lock With No Monitoring
Restricted room has: a strong electronic lock.
Door is forced overnight.
No alarm, camera or guard detects it until: next morning.
The Forgotten Badge
Employee leaves organisation on Friday.
Logical accounts: disabled.
Building badge: remains active.
The Missing Master Key
Master key can open: every restricted office on the floor.
Key cannot be located.
The Unescorted Cleaner
Cleaning contractor has legitimate reason to enter: office areas.
Same credential also opens: the evidence-storage room.
The Reception Printer
Sensitive HR report prints to: a shared printer beside visitor reception.
The Camera Blind Spot
Main corridor: well monitored.
Emergency stairwell: not covered.
Stairwell provides: access to the same restricted floor.
๐ท Do Not Expose Credentials Unnecessarily Physical access information itself can be sensitive
Employee posts selfie showing: high-resolution corporate badge.
Exposed information might reveal:
Physical Controls Can Serve Different Functions
| Function | Physical Example |
|---|---|
| Deterrent | Visible guards, fencing, warning signage |
| Preventive | Locked door, gate, bollard, turnstile |
| Detective | CCTV, door alarm, motion sensor |
| Corrective | Repairing a compromised barrier or access control |
| Compensating | Guard stationed at a door while the badge reader is broken |
Strong Physical Security
๐ CISSP Scenarios Recognise the physical security principle being tested
A fence surrounds the organisation's property.
Which type of control?
Perimeter physical security control.
A badge reader controls entry to the data centre.
Which category?
Internal physical security control.
A camera records people entering a restricted room.
Primary control function?
Detective / monitoring.
A locked door stops unauthorised entry.
Primary control function?
Preventive.
Visible guards discourage attempted intrusion.
Which additional function?
Deterrent.
A broken badge reader is temporarily replaced by a security guard checking identification.
Which control concept?
Compensating control.
The main entrance is strongly protected but an unlocked side door leads to the same facility.
Primary weakness?
Alternative uncontrolled entry path.
An employee can enter the office but has no business need to enter the data centre.
Which principle?
Physical least privilege.
Employee changes role but retains access to highly restricted rooms.
What should occur?
Review and modify physical access.
An employee leaves the organisation.
What should happen to the badge?
Physical access should be revoked and credential recovered or disabled.
A lost badge remains active for several days.
Primary concern?
It can potentially be used for unauthorised physical access.
One door PIN is shared by 100 people.
Primary weakness?
Poor individual accountability.
A master key is lost.
Why is this particularly serious?
Its broad access increases the potential impact of compromise.
A visitor arrives for an authorised meeting.
Should this automatically grant unrestricted building access?
No.
A contractor requires access to one network cabinet.
Best principle?
Limit physical access to the authorised need.
A visitor walks around a restricted floor without escort.
Which control has failed?
Visitor activity control / escort process.
An unauthorised person follows an employee through a secured entrance.
Which threat?
Tailgating / piggybacking.
An employee politely holds the secured door for an unknown person.
What helped bypass security?
Social engineering / human behaviour.
A turnstile permits one person for each successful credential event.
What risk does this help reduce?
Uncontrolled multiple-person entry.
Two badge entries occur without an intervening exit.
Which mechanism may flag this?
Anti-passback.
A door unlocks when electrical power fails.
Which lock behaviour?
Fail-safe.
A door remains secured against entry when power fails.
Which behaviour?
Fail-secure.
A fire occurs while access-controlled doors are operating.
Highest priority?
Human life and safe emergency egress.
A secure vestibule allows the first door to close before the second opens.
Which physical control?
Access-control vestibule / interlock.
A camera records an intruder but does nothing to stop entry.
Primary lesson?
Detective control is not necessarily preventive.
A locked room has no surveillance or alarms.
Primary lesson?
Preventive and detective controls should complement each other.
CCTV camera has been offline for three months.
Primary issue?
The control exists but is not operationally effective.
A door generates dozens of false alarms every day and guards begin ignoring it.
Primary concern?
Alarm fatigue and degraded response.
Badge access occurs at 03:00 for an office-hours employee.
Does this prove malicious activity?
No. It is an anomaly requiring context and investigation.
Badge logs show one entry while CCTV shows two people.
Likely issue?
Tailgating or other unauthorised entry.
A secure door is propped open for convenience.
Primary lesson?
Operational behaviour can bypass a functioning technical control.
A server room is secure but its network closet is unlocked.
Primary concern?
Critical network infrastructure remains physically exposed.
Unused network jacks in a public area remain connected.
Physical-security consideration?
Restrict or secure access to communications infrastructure.
Sensitive documents print beside a public waiting area.
Which concern?
Physical access to output devices and information.
A visitor can see confidential information on an employee's monitor.
Which risk?
Visual exposure / shoulder surfing.
A courier can walk directly from the loading dock into the data centre corridor.
Primary concern?
Delivery area provides an uncontrolled internal access path.
An expensive server leaves the building without verification.
Which process is weak?
Physical control of equipment removal.
An employee posts a detailed photograph of their corporate access badge online.
Primary concern?
Exposure of physical credential information.
Access logs are deleted after an intrusion.
What has been weakened?
Accountability and investigation evidence.
Badge log shows employee in London while their account logs in from another country two minutes later.
What can this demonstrate?
Value of correlating physical and logical access information.
A badge reader breaks and a guard manually verifies authorised staff until repair.
Which concept?
Temporary compensating control.
A temporary door-control workaround remains in place for six months.
Primary concern?
A temporary security exception has become the normal state.
Security installs expensive cameras but never verifies whether they are functioning.
Primary lesson?
Physical security controls require monitoring, testing and maintenance.
What is the distinction between Domain 3.9 and 7.14?
Best answer?
Domain 3 focuses on facility control design; Domain 7.14 focuses on implementing and managing physical security operations.
Management asks for the main principle of 7.14.
Best answer?
Use layered perimeter and internal controls to authorise, restrict, monitor and record physical access, then maintain and respond to those controls throughout their operational lifecycle.
Recognise the Clue Words
Outside Boundary
Site protection.
Perimeter ControlInside Building
Restricted movement.
Internal ControlDiscourage Entry
Control purpose.
DeterrentStop Entry
Control purpose.
PreventiveObserve Entry
Control purpose.
DetectiveBroken Reader + Guard
Temporary alternative.
Compensating ControlPerson / Vehicle Authentication
Electronic access.
PACSBuilding Access but Not Data Centre
Authorisation.
Physical Least PrivilegeEmployee Changes Role
Access lifecycle.
Review AccessEmployee Leaves
Offboarding.
Revoke Badge / KeysPerson Follows Another
Unauthorised entry.
Tailgating / PiggybackingTwo Controlled Doors
High-security entry.
Access Vestibule / InterlockOne Person per Badge
Access flow.
TurnstileBadge Entered Twice
Sequence control.
Anti-PassbackUnlocks on Power Loss
Door behaviour.
Fail-SafeStays Secure on Power Loss
Door behaviour.
Fail-SecureTemporary External Person
Access management.
Visitor ControlUnusual 03:00 Entry
Monitoring.
Investigate Access LogDoor Forced
Detection.
Physical AlarmObserve Area
Surveillance.
CCTVVehicle Threat
Perimeter.
Bollard / BarrierNetwork Closet
Infrastructure.
Restricted Physical AccessPrinter Exposes Data
Information.
Output Device ProtectionEquipment Leaves Site
Asset control.
Delivery / Removal ControlSecurity System Exists but Broken
Operations.
Maintenance / Testingโ ๏ธ Common CISSP Mistakes Physical security is layered and operational
Physical access can expose systems, devices and information.
Attackers may use another entrance.
Use internal security zones and least privilege.
Physical access requires lifecycle review.
Offboarding includes badges, keys and building access.
Shared credentials make attribution harder.
Visitor movement should remain controlled.
Give access required for the authorised task.
Cameras primarily support monitoring and investigation.
A lock may delay entry without alerting anyone that it was defeated.
Someone or something must act on the detection.
Surveillance requires operational monitoring and maintenance.
Lighting supports deterrence and observation.
Physical controls can still be valuable by delaying and detecting an intruder.
Human behaviour can bypass perfectly functioning doors.
Terminology varies. Focus on the unauthorised following behaviour.
One releases on loss of power; the other maintains entry security.
Emergency life safety and egress requirements remain paramount.
Investigate business context.
Protect its integrity, availability and retention.
Wiring closets and cabling also need physical protection.
Sensitive information can still be visually observed.
Physical outputs can expose protected information.
Loading areas require physical access controls too.
Removal of sensitive equipment may require verification.
Temporary exceptions require ownership and remediation.
Test, monitor and maintain physical controls.
Domain 3 emphasises physical facility design. Domain 7.14 emphasises implementation and operational management.
Quick Reference
| If you see... | Think... |
|---|---|
| Outer site boundary | Perimeter Security |
| Restricted area inside building | Internal Security |
| Fence / wall | Boundary / delay |
| Bollard | Vehicle Barrier |
| Camera | Detective / Surveillance |
| Locked door | Preventive Access Control |
| Guard while reader broken | Compensating Control |
| Electronic building access | PACS |
| Only required rooms | Physical Least Privilege |
| Person follows employee through door | Tailgating / Piggybacking |
| Two controlled doors | Security Vestibule / Interlock |
| One person per entry | Turnstile |
| Impossible badge sequence | Anti-Passback |
| Unlock on power loss | Fail-Safe |
| Remain secure on power loss | Fail-Secure |
| Temporary non-employee | Visitor Control |
| Who entered and when? | Physical Access Log |
| 03:00 unusual entry | Investigate Access Anomaly |
| Forced door | Physical Intrusion Alarm |
| Network cabling | Transmission Path Protection |
| Unsecured printer | Output Device Protection |
| Equipment leaving building | Delivery / Removal Controls |
| Employee leaves | Revoke Badge + Recover Keys |
| System installed but never checked | Operational Testing / Maintenance |
Perimeter Memory Aid
Internal Security Memory Aid
Physical Defense Memory Aid
7.14 Master Memory Aid
Deter โ Restrict โ Detect โ Record โ Respond โ Review
The Physical Security Manager's Questions
Key Takeaways
CISSP 7.14 is officially: Implement and manage physical security.
The current ISC2 outline explicitly identifies: perimeter security controls and internal security controls.
Physical security protects people, facilities, information and technology against unauthorised physical access.
Cybersecurity does not stop at the network boundary.
Physical access can allow an attacker to steal hardware, connect rogue devices, tamper with cabling, access consoles, remove storage media or directly observe sensitive information.
Physical controls and logical controls reinforce one another.
Physical security should normally use multiple layers.
Layers may include property boundaries, building entrances, internal security zones and additional protection around critical assets.
A useful physical-security model is:
deter โ detect โ delay โ respond.
A barrier does not need to be impossible to defeat in order to provide value.
If it delays an attacker long enough for detection and response, it has contributed to security.
Perimeter security protects the outer boundary.
Examples include fences, walls, gates, vehicle barriers, lighting, guards, cameras and intrusion alarms.
Strong protection at one entrance does not compensate for another uncontrolled entrance.
Physical access should therefore be channelled through controlled entry and exit points.
Bollards and other vehicle barriers can help control vehicle approach to sensitive facilities.
Security lighting supports surveillance, deterrence and guard visibility.
Lighting supports security but is not itself access authorisation.
Security guards provide flexible human observation and response.
Guards may verify identity, challenge suspicious individuals, respond to alarms and coordinate emergencies.
Human security controls require training and clearly defined procedures.
CCTV provides valuable monitoring and investigative capability.
Cameras are primarily detective controls.
A camera recording an intrusion does not necessarily prevent the intrusion.
Camera = observe. Lock = restrict. Alarm = notify. Response = act.
Surveillance equipment must be maintained.
A camera that has been offline for months does not provide useful monitoring merely because it remains mounted on the wall.
Camera coverage, image quality, lighting, retention, timestamps and monitoring responsibility should therefore be considered.
Physical intrusion alarms can detect forced doors, held-open doors, movement and other suspicious conditions.
Detection is only useful when there is an appropriate response.
Excessive nuisance alarms can also cause security personnel to stop treating alarms seriously.
Internal physical security restricts movement after someone has entered the facility.
Entering the building does not automatically authorise entry into every room.
Organisations can establish progressively restricted internal security zones.
Public areas might include reception. Controlled areas might include normal employee offices. Restricted areas might include operations rooms. Highly restricted areas might include data centres or evidence storage.
Physical access should follow the principle of least privilege.
Give people access to the areas required for their role - not every area they might conceivably want to enter.
Physical Access Control Systems can authenticate and authorise people or vehicles at controlled entry points.
Physical credentials can include keys, badges, smart cards, combinations and biometric mechanisms.
Sensitive areas may require stronger authentication than ordinary office areas.
Physical access has a lifecycle.
Access should be authorised, issued, monitored, periodically reviewed and revoked when no longer required.
A transfer between roles should trigger review of physical as well as logical privileges.
Termination should include physical credential revocation.
Account disabled โ badge disabled.
Keys and combinations are also security credentials.
Sensitive keys should be inventoried, securely stored and recovered when no longer required.
Loss of a master key can have much greater impact than loss of a key to a single room.
Shared physical credentials reduce accountability.
If 50 people use the same door code, the organisation may know that the code was used but not which authorised person used it.
Electronic locks can behave differently during power failure.
Fail-safe locks release when power is lost.
Fail-secure locks remain secured against entry when power is lost.
Life-safety and emergency-egress requirements remain paramount.
Security must not improperly trap people inside a dangerous building.
Secure access vestibules or interlocks can provide additional control around highly sensitive entrances.
Turnstiles can help enforce one-person-per-credential entry.
Tailgating and piggybacking describe unauthorised entry by following someone through a controlled entrance.
Some organisations distinguish tailgating as occurring without the authorised person's knowledge and piggybacking as occurring with their cooperation.
The terminology is not universally used consistently.
The important concept is: someone bypassed individual physical authentication.
Physical security is therefore vulnerable to social engineering.
A perfectly functioning badge reader cannot stop an employee from holding a secure door open for an unauthorised person.
Employee awareness and challenge culture are therefore part of effective physical security.
Anti-passback mechanisms can detect or prevent certain impossible badge sequences, such as the same credential entering twice without a recorded exit.
Visitors require temporary controlled access.
Visitor processes may include identity verification, host confirmation, registration, temporary badges, limited access, escort and sign-out.
Visitor badge โ unrestricted access.
Contractors should receive only the physical access required for their authorised work.
Physical access logging provides accountability.
Useful records can identify the credential, location, time and access result.
Monitoring can identify events such as after-hours entry, repeated denied access, unusual locations and forced doors.
Unusual physical access โ automatically malicious.
Context should be investigated.
Physical and logical logs can sometimes be correlated.
If a badge shows an employee entering one geographic location while the same user's logical identity authenticates from an implausibly distant location at almost the same time, that correlation may deserve investigation.
Physical logs themselves should be appropriately protected.
Their integrity, retention, availability and timestamps can matter during investigations.
Critical internal areas include server rooms, data centres, wiring closets and restricted storage.
Network closets should not be overlooked.
Physical access to switches, patch panels and cabling can permit disruption, tampering or unauthorised network connection.
Communications transmission paths may require physical protection.
Locked wiring closets, protected cable routes, conduit and controlled network ports can help reduce physical tampering risk.
Physical output devices also require consideration.
Printers, screens, scanners and other output mechanisms can expose data even when the underlying computer system is strongly authenticated.
Secure system โ secure information if the output is physically exposed.
Shoulder surfing and unauthorised visual observation can reveal sensitive information without exploiting any software vulnerability.
Delivery areas and loading docks are additional access routes that should be controlled.
Organisations should consider both people entering and assets leaving the facility.
Equipment removal may require authorisation.
A person wearing contractor clothing should not automatically be allowed to push a server out of the building.
Access badges and other physical-security identifiers can themselves contain sensitive information.
Employees should avoid unnecessarily exposing detailed credentials in photographs or public posts.
Physical-security monitoring creates information about people.
CCTV, visitor logs and access records should therefore be appropriately governed, retained and protected according to applicable requirements.
Emergency access may require special arrangements for emergency services or facilities personnel.
These arrangements should support safety without creating an uncontrolled permanent bypass.
Physical security incidents need response procedures.
Examples include forced doors, lost credentials, tailgating, unknown individuals, damaged barriers, camera tampering and missing equipment.
Physical and cybersecurity incident response can overlap.
A rogue device discovered in a wiring closet may require both physical investigation and technical incident response.
Physical controls require maintenance and testing.
Locks, badge readers, cameras, barriers, lighting and alarms should not simply be installed and forgotten.
Installed control โ functioning control.
Temporary compensating controls may be required when normal controls fail.
For example, a guard might manually verify employees while a badge reader is being repaired.
Temporary exceptions should have an owner, procedure and path back to the normal control.
Useful physical-security measurements can include access revocation, forced-door events, camera availability, visitor exceptions, lost credentials and alarm-response time.
Domain 3.9 and Domain 7.14 should not be confused.
Domain 3.9 concentrates on designing site and facility security controls.
Domain 7.14 concentrates on implementing and managing physical security during day-to-day operations.
The central CISSP principle is:
establish layered perimeter and internal physical controls, grant access according to business need, monitor and record sensitive physical activity, control visitors and credentials, respond to suspicious events, preserve life safety and continuously verify that the controls remain operational and appropriate.
๐ Sources & Further Reading Current physical-security and access-control references
- ISC2 - CISSP Certification Exam Outline
View the current CISSP Exam Outline - NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations
View NIST SP 800-53 - NIST SP 800-171 Rev. 3 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
View NIST SP 800-171 Rev. 3 - NIST - Physical Access Control
View NIST physical-access terminology - NIST - Physical Access Control System
View NIST PACS terminology
