/Facilities-and-Physical-Security-Considerations/data-security Facilities and Physical Security Considerations

Facilities and Physical Security Considerations

by Maggie Shawman.

Share
|
Homepage | Submit your article | Contact | TOS
More articles on data security  

You are here: Categories » Computers and technology » Data security

In this inter-networked age, many people often associate security with the more virtual aspects—network, operating system and application security, the underground, crackers, and all of the media-hyped fear, uncertainty, and doubt that surrounds these aspects. Prior to this time, the term security conjured images of armed guards or large, burly men posted by each door. Physical security is a large component of any security policy, and rightfully so. The front door is the most easily utilized point of attack.

The site and infrastructure security policy should outline the methods used to provide and control physical access to the building and the conditions under which access is granted. Important elements are

· Methods of physical access

· Procedures by which access is granted, modified, or denied

· Access restrictions based on employee status

· Hours of operation

· Points of contact for access

· Procedures for incident handling and escalation levels

Physical access methods describe the actual means of accessing the facility, offices, labs, or other areas. These are often a lock and key, proximity cards, or biometric methods. Consideration should also be given to guidelines for the appropriate use and handling of the keys. The procedures used to obtain keys/cards and by which access is granted or modified should be outlined clearly, as it is often a point of confusion for both new and long-time employees. Equally important is a list of the people and departments to whom an employee must go to gain access to the business site—filling out forms or asking approval becomes futile if the person to whom these request should be addressed is unknown.

Many organizations distinguish between full-time, part-time, and contract employees and limit facility access based on these categories. Along with the hours of operation, the site security policy should specify any restrictions for special employees during and outside of regular working hours. Related to the segmentation of employees, the segmentation of the facility is also common. Labs, offices, and storage areas often merit access restrictions in order to prevent unauthorized entry.

Should an incident occur, the procedures for incident handling are vital to the security of an organization, as well as the safety of the employees. Incidents vary in nature, from unauthorized visitors and broken access methods to the removal of employees. Many organizations have security personnel to assist in these matters and suggested methods to react to specific situations. Defined escalation levels help an employee understand incident seriousness and to decide when is the appropriate time to notify external support, such as local law enforcement and legal counsel.

Company Z has installed and uses proximity-based card readers at all external entrances, lab doors, storage closets, and key financial offices for access control.

The administration has defined the following security policy that regulates access into the facility:

· During weekday business hours—between 8 a.m. and 6 p.m.—card access is not required for full-time and part-time employees.

· Contract employees are required to sign in with the receptionist.

· All external doors are locked outside of normal business hours, and card access is required for full-time and part-time employees.

· Contract employees are restricted from access outside of normal business hours unless specialized access forms are filled out and approved by the hiring manager.

· Access to restricted labs, storage areas, and financial offices is gained via specialized access forms and management approval.

· Access cards are obtained at the security office after the hiring manager approves access forms.

· Misplaced or stolen access cards must be reported immediately to security.

· Access cards should be kept on the person at all times; cards should not be loaned to anyone or left unsecured.

The following security policy for incident response is also provided to employees:

In order to ensure safety and security within the Company Z facility, employees should read and understand the following guidelines for dealing with incidents:

· In the event of an unauthorized visitor, the employee should immediately notify the security department and request assistance for removal of the visitor.

· Should the visitor be witnessed committing an act of larceny, attack, or destruction of property, notify the security department, and they will then contact the appropriate authorities.

· All witnesses should provide the security department with an affidavit indicating their presence and the details of the incident, and should be available for further questioning by security and the appropriate authorities.

· All doors, locks, and access methods that are non-functional should be reported to the security department. Security will coordinate with maintenance to fix the broken equipment.

· Managers should be notified when an employee is involved with a breach of security.

· Employees should not handle these situations alone, but instead should notify security and allow the security staff to control the situation.

This example demonstrates important aspects of a site and infrastructure security policy. Constraints on physical access are defined, including the actual methods that employees use to enter the facility and the differentiation between employee types. The processes and procedures used to control access and to acquire the appropriate privileges are outlined, including the identification of the responsible individuals. The response guidelines for any incidents are clearly outlined with the safety of the employee in mind. Individuals trained to handle incidents of this nature are identified and involved in each response method.

Leave a comment or ask a question
Total comments: 0

Data security Disclaimer

  • The e-articles directory is not responsible for any and all copyright infringements by writers and authors. If you suspect the information contained by this page for any copyright infringements, please contact us to investigate the issue
How to speed up your computer - Most of People surf sites daily and don't care which should be visited, when they felt thier computer slow, they start worrying about it. Five tips You must adapt 1: Use Antivirus and update (more...)
Tips on Buying Biometric Locks - The security of your home is essential. You owe it to yourself and your loved ones to make sure you are safe at all times. So, with the development of biometric security locks things h (more...)
3 Signs You Need a Virus Removal Service - Virus and malware infestations are some of the most common computer repair problems that computer owners everywhere deals with. These malicious hijacking attempts of your (more...)
Six Myths about Nulled Scripts, or There's No Such Thing as Free Lunch - Once every so often our customers are asking us how come on some websites our software is sold at a fraction of price or is even free. They further ask how come they have to pay for the software if (more...)
How to protect against Spoofing and Session Hijacking - Spoofing is the term hackers use to describe the act of faking information sent to a computer. This is a broad definition of spoofing, but there are many subtle variations of this attack. Howev (more...)
Online Security on Public Computers - Using public computers can put you at risk for password hackers who use tools such as keystroke logging devices. Find out how to protect yourself from criminals preying on public computers. (more...)
How to Create a Strong Password - Using a password keeper can help you keep your online information more secure by allowing you to create more complex passwords for your Internet accounts without having to remember them. Here a (more...)
How Many Passwords do You Know to Protect Your Computer Privacy - 1.Administrators Password: It is the most common way to lock your computer. But is it the safest way? Mostly, it is the easiest way to lock your computer. How to (more...)
What will be a perfect password - Myth: if it is encrypted, it is secure Truth: if it is not encrypted, it is not secure Before creating a password you should know: ⑴ NO passwo (more...)
How to bypass Windows Password - Forgot or lost windows password? Have been locked out of computer? Do not want to reinstall the computer because there is vital data on your computer? Oh, well, it is not that scar (more...)

 
free content
    Copyright © 2006 - 2012 e-articles.info.
The texts, articles and tutorials in the directory are property of their respective owners and authors.