Physical security
Also known as: physical controls
Protecting buildings, rooms and equipment so that nobody can simply walk in, take, break or plug into them.
Draft - this entry has not been reviewed yet.
Formal
The controls that protect the physical surroundings of information - sites, server rooms, devices and paper - against entry by outsiders, theft, damage and dangers such as fire, water and power loss. ISO 27002 groups them as its physical controls.
In plain English
The best lock on a diary is no help if someone can simply pick up the whole diary and walk off with it.
In practice
At a regional hospital, a visitor follows a porter through a card-locked door, finds an empty meeting room and plugs a small device into a free network socket; a no-following rule and switched-off sockets would have stopped it.
Why it matters
Anyone with hands on a machine can often get around its digital protection, and fire or flooding can end availability as surely as any attack.
How to put it into practice
The usual steps, in order. Adapt them to your organisation.
- List the sites, rooms and equipment that hold or process important information, including server rooms, network cabinets, printers and paper archives, with an owner for each.
- Assess the physical and environmental threats for each location, such as break-in, tailgating, theft of laptops, fire, water and power loss.
- Set up zones from public areas to secure rooms, with locks or card access at each boundary, and give people access only to the zones their work requires.
- Stop tailgating with a clear rule, visible badges, visitor registration and escorts, and mantraps or anti-passback at the most sensitive doors.
- Protect server rooms with fire detection and suitable suppression, UPS and backup power, cooling, and water and temperature sensors that raise an alarm.
- Protect devices outside secure areas with full-disk encryption, locked screens, disabled unused network sockets and a clear desk rule.
- Wipe or destroy disks, phones and printer drives before disposal or reuse following NIST SP 800-88, and keep a record for each device.
- Review access lists and logs every quarter, remove leavers at once, and test alarms, backup power and the tailgating rule at least once a year.
Common pitfalls
- Treating physical security as a facilities matter, so network sockets, printers and disposal are left out of the security work.
- Access cards that are never withdrawn from leavers or temporary staff.
- A tailgating rule that nobody enforces because it feels rude to stop a colleague.
- Sending old disks and multifunction printers for recycling without wiping them.
Good guides
- NIST SP 800-88 Rev. 2 - Guidelines for Media Sanitization(opens in a new tab) · NIST
- NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations (PE Physical and Environmental Protection)(opens in a new tab) · NIST
- Security Planning Workbook(opens in a new tab) · CISA
Technical deep dive
Physical security is the control domain that protects the tangible environment of information: sites, rooms, cabling, devices and paper. ISO/IEC 27002:2022 gathers it under clause 7 (Physical controls), which spans physical security perimeters, entry controls, securing offices and facilities, protection against physical and environmental threats, working in secure areas, clear desk and clear screen, equipment siting and protection, supporting utilities, cabling security, equipment maintenance, and secure disposal or re-use of equipment. These sit alongside the organisational, people and technological controls in the same standard, reflecting that a control failure in any one domain can undo the others.
In practice physical controls are layered in concentric rings - site fence, building, floor, room, cabinet - so that defeating one barrier does not grant access to the asset, a physical analogue of defence-in-depth. Deterrent, preventive, detective and corrective measures are combined: fencing and lighting deter, card readers and mantraps (interlocking double-door vestibules that defeat tailgating) prevent, CCTV and intrusion sensors detect, and guards or response procedures correct. A central threat is tailgating or piggybacking, where an unauthorised person follows an authorised one through a controlled door; anti-passback logic in the access system and mantraps are the standard countermeasures. Environmental protection is equally part of the domain: fire detection and suppression (VESDA aspirating detection, inert-gas or clean-agent systems rather than water in server rooms), redundant power via UPS and generators, and HVAC for temperature and humidity all defend availability, since a flood or overheating ends service as effectively as an intruder.
Data centres formalise this with tiered availability models: the Uptime Institute Tier I-IV classification (Tier IV being fault-tolerant with concurrently maintainable, redundant infrastructure) and the EN 50600 series in Europe define expected redundancy and physical protection. Access is typically logged and often gated by multi-factor physical authentication (card plus PIN or biometric), and racks themselves are locked so that colocation tenants cannot reach each other's hardware.
A key principle is that physical access frequently defeats logical controls: an attacker with hands on a device can boot from external media, extract disks, capture data from memory (cold-boot attacks), attach a hardware keylogger, or plant a rogue network implant, which is why full-disk encryption, disabled boot from removable media, port control and tamper-evident seals matter. A common misconception is that physical security is a facilities concern separate from cyber; NIS2 and ISO 27001 treat it as an integral part of information security precisely because so many logical protections assume the attacker is remote. Secure disposal is the frequently forgotten end of the lifecycle: drives and multifunction printers retain data and must be sanitised (per NIST SP 800-88 media-sanitisation guidance) or physically destroyed before disposal.
What to learn first
Everything this builds on, foundations first.
Relationships
- A kind of
- Security control
- Part of
- Defence in depth
- Requires
- Asset
- Don't confuse with
- Organisational controlPeople control
- Mitigates
- Data breachInsider threat
- Mandated by
- CER Directive
Sources & further reading
Standards & official texts
- ISO/IEC 27002:2022 - clause 7, Physical controls · ISO/IEC
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…