Effective Period: Until superceded
Review Schedule: Annually
Effective Date: 10/01/2014
References: ?????????
UTILITIES
INFORMATION TECHNOLOGY
Physical Security Policy
987
1. Purpose
The purpose of this policy is to provide a safe and secure working environment and promote
the protection of our assets. We must maintain the security of our confidential information
(such as Town sensitive information and personally identifiable information (“PII”)), as well as
the information shared with us by our customers and Town Consultants. We strive to maintain
customer-friendly procedures to ensure only authorized employees, consultants, contractors,
and visitors have access to our facilities.
Scope
This policy applies to the physical areas where information assets are kept. These areas
include server rooms, telecom closets and certain office areas that may contain Town sensitive
information or PII. These areas must be physically secured to prevent theft, tampering or
tapping, or damage.
2. Policy
Facility Access Control
It is every employee’s responsibility to work toward, maintain and preserve a secure physical
work environment.
Supervisors are responsible for ensuring that proper building security practices
are maintained and that their employees follow access control policies and
procedures.
Line managers and the Human Resources Department (“Human Resources”) will
authorize the issuance of badges (Town photo badge) to new employees
granting them appropriate facility access beginning on the date of hire (via
physical keys, or electronic access devices). Employees shall wear their issued
badges at all time while on Town premises.
Revisions:
Effective Period: Until superceded
Review Schedule: Annually
Effective Date: 10/01/2014
References: ?????????
UTILITIES
INFORMATION TECHNOLOGY
Physical Security Policy
987
All employees are to enter the building at the facility’s designated employee
entrance.
At termination, all employees must return their badges to their supervisor.
At termination, it is the supervisor’s responsibility to retrieve the badge from
the terminated employee and return it to the Facilities
Management/Information Technology department for deactivation and
shredding.
Facilities Management/Information Technology develops and maintains
procedures to follow when employees forget or lose their badges.
No individual will be permitted to access our facilities beyond the main
reception area without an appropriate badge worn visibly.
Facilities Management is responsible for developing procedures to control the
use and dissemination of building keys. Lost and stolen keys must be reported
to Loss Prevention immediately.
Effective Building Security
The following rules apply:
Keys and badges are not to be left unattended in plain view or carried in a way
that makes them easy to lose or be stolen.
When employees leave the building after hours, the exterior doors (including
overhead receiving doors and shipping doors) must be locked to prevent
unauthorized access.
If a door does not close or lock properly, notify Facilities Management
immediately.
Revisions:
Effective Period: Until superceded
Review Schedule: Annually
Effective Date: 10/01/2014
References: ?????????
UTILITIES
INFORMATION TECHNOLOGY
Physical Security Policy
987
Information Technology, Facilities Management, and the Police must be notified
whenever a potential or actual security problem exists, including unauthorized
entry, theft of property, or loss of keys or badges.
Protection of Sensitive and Critical Information
The physical areas where information assets are kept must be protected from unauthorized
access. The following rules apply to physical access:
Employees and administrative contractors must secure their work areas to
protect Town sensitive information and PII.
Workstations shall be placed in locations that protect the confidentiality of
data. All confidential documents and media must be securely stored.
All documents and media containing PII must be discarded carefully.
Documents, DVDs, and CDs containing PII must be shredded. Electronic media
containing PII must be destroyed by Information Technology.
Facilities Management will provide high-level physical and environmental
protection of the technical infrastructure to minimize the risk of unauthorized
access and environmental hazards.
Telecommunication lines and equipment will be protected by locking and
controlling access points to ensure both availability and the confidentiality.
Any movement of information, software media, hardware or other IT physical assets will be
strictly controlled. Only authorized personnel are permitted to take company property off-
premises. Computing equipment taken off premises is subject to the Laptop/Mobile
Computing Security Policy.
Revisions:
Effective Period: Until superceded
Review Schedule: Annually
Effective Date: 10/01/2014
References: ?????????
UTILITIES
INFORMATION TECHNOLOGY
Physical Security Policy
987
Procedures
Physical Security Audits
It is the responsibility of Police Department, Facilities Management, and the Information
Technology Department to conduct periodic (annual) physical security audits to ensure
compliance. This shall include:
An audit of the physical security on the perimeter of the building to ensure door
alarms are working properly.
An audit of the physical security of the server, telecom, and other sensitive
storage areas.
Compliance
Violations of this policy may lead to the suspension or revocation of system privileges and/or
disciplinary action up to and including termination of employment. We reserve the right to
advise appropriate authorities of any violation of law.
Accountability
All employees, consultants, contractors, and non-employee users are responsible for the
secure handling, processing, transmittal and safeguarding of PII and Town sensitive
information. Third parties/vendors are responsible for ensuring that (1) their use and access
to us and our computing resources, whether on their own information assets or through our
assets, meets our security protection procedures, (2) their use of our assets are appropriate
and (3) they follow this Physical Security Policy.
Line Managers are responsible for ensuring that this Physical Security Policy is followed.
Revisions:
Effective Period: Until superceded
Review Schedule: Annually
Effective Date: 10/01/2014
References: ?????????
UTILITIES
INFORMATION TECHNOLOGY
Physical Security Policy
987
Approved:
_______________________________
Frank Lancaster, Town Administrator
Date:___________________________
Revisions: