Domain 5: Protection of Information Assets7 min · 3 questions

Physical and Environmental Controls

Logical controls mean nothing if someone can walk out with the server or the room floods. The exam tests tailgating, and why environmental controls protect the availability of everything else.

What this makes you able to do

Evaluate whether physical access to facilities and environmental threats to equipment are adequately controlled.

By the end you can

  • Identify the control that prevents tailgating into a secure area.
  • Explain why physical security is part of protecting information assets.
  • Recognise the role of environmental controls in protecting availability.

Transcript

Physical and environmental controls. Most of Domain five is logical. This lesson is the physical and environmental layer that everything logical sits on.

The scene. The data centre has a badge reader, and access to it is treated as solved. But you watch someone hold the door open for a colleague whose hands are full, and a second person walks in unbadged. Inside, there is no water detection under the raised floor, the air conditioning is a single unit, and the uninterruptible power supply has not been tested in years. Every login to those servers is strongly controlled. Getting to the servers is not.

Here is the core point. Logical controls, passwords, permissions, encryption, protect data through the system. Physical access goes around them. Someone who can reach the hardware can remove a disk, walk off with a device, plug into a port, or simply destroy equipment, and none of the logical controls stop them.

That is why physical security is part of protecting information assets: it is a layer of defence in depth, and without it the logical layer can be bypassed entirely. So secure facilities use layered physical controls: perimeter security, guards and C-C-T-V, badge or biometric access, visitor logs and escorts, and locked cabinets for the most sensitive equipment.

Now the badge gap, the exam’s favourite physical point. A badge reader authenticates one person, but it does nothing to stop a second person tailgating, or piggybacking, through on that entry, exactly what you watched happen. The control that addresses this is a mantrap, or access-control vestibule: a small enclosure that admits one authenticated person at a time.

So when a question describes unauthorised entry behind an authorised person, a stronger password or a longer badge number is never the answer, those do not address a human following another through a door. The mantrap, admitting one person per authentication, is. Turnstiles and anti-passback controls serve the same purpose.

Physical threats are not only intruders. Fire, heat, humidity, water and power loss can destroy equipment, so environmental controls protect it. First, fire detection and suppression appropriate to a computer room, so a fire is caught without destroying the equipment.

Second, climate control, keeping temperature and humidity within the range hardware tolerates.

And third, uninterruptible power plus backup generators, so a power cut does not drop systems, and water detection, especially under raised floors, so a leak is caught before it reaches equipment.

What do these protect. They protect availability and integrity. Fire, heat, humidity, water and power loss can destroy equipment and take systems down, so these controls connect directly to the continuity and availability themes of Domain four.

And the data centre in the scenario fails several of them: no water detection, a single air-conditioning unit, an untested U-P-S. Each is a route to an outage or data loss that no logical control would prevent.

So carry this away. Physical access bypasses logical controls, so a mantrap against tailgating and controlled facility access are real, necessary controls. And the environmental layer, fire, climate, power, water, protects the availability and integrity of the systems, and therefore the information, which is squarely part of protecting information assets.

Knowledge check
0 / 3
  1. 1.A secure data centre uses a badge reader on the door. Which additional control BEST prevents an unauthorised person from tailgating in behind an authorised one?

  2. 2.Why is physical security considered part of protecting information assets?

  3. 3.What is the PRIMARY purpose of environmental controls such as fire suppression, climate control and uninterruptible power?

Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.