Security Principles in Site and Facility Design
If an attacker gains physical access to an organization, they can steal data, corrupt data, deploy rogue devices, or obtain confidential records. Holders of the CISSP certification and security professionals in general must understand the value of introducing mitigations to protect the organization’s site and facility against physical attacks.
Physical controls limit access, restrict unauthorized individuals, and monitor individuals in specific locations within the organization and how they interact with items of value. Controls such as security guards or barriers can be placed to limit access to buildings, equipment, the security operations center (SOC), human resources, legal areas, network centers, financial zones, and more.
Which areas need to be prioritized for physical access controls and the controls to be used are decided through qualitative or quantitative risk assessment. There might also be some legal and regulatory...