Information Security - Chapter 9: Physical Security (Simplified Notes)
Topic 1: Introduction to Physical Security
Physical security means protecting physical items like computers, rooms, and buildings from unauthorized
access or damage.
Real-world example: Amy caught a 'tailgater' sneaking into a secure office. Tailgating = following someone
through a locked door.
Why is it important?
- Software protections like firewalls are useless if someone can steal your hard drive.
- Physical threats include theft, fire, water, human error, power failure.
7 Sources of Physical Loss (TGLLPME):
1. Temperature (heat/cold)
2. Gases (chemicals)
3. Liquids (water)
4. Living organisms (humans, bacteria)
5. Projectiles (moving objects)
6. Movement (earthquake, vibration)
7. Energy anomalies (electric surges)
Responsibilities:
- General Management: external building, fire, guards
- IT Team: server room, cooling, dust
- InfoSec Team: risk assessment
Topic 2: Physical Access Controls
Controls that manage who can physically access company areas.
Secure facility = building with strong controls to prevent attacks.
Information Security - Chapter 9: Physical Security (Simplified Notes)
Managed by:
- General Management (building access)
- Facilities Management (ID cards, doors)
- IT and InfoSec teams
Use layered security (defense-in-depth): gate -> ID -> keypad -> login.
Topic 3: Physical Security Controls
Tools used to protect physical access to people, systems, and rooms.
Types:
1. Walls, Fences, Gates: first layer of protection.
2. Guards: can make decisions and act.
3. Dogs: detect intruders by smell/hearing.
4. ID Cards/Badges: verify identity (tailgating risk).
5. Locks: mechanical, programmable, electronic, biometric.
6. Mantraps: small entry area that locks intruders inside.
7. CCTV: monitors activity, needs live monitoring.
8. Alarms: detect motion, temperature, window openings.
9. Server/Wiring Rooms: restricted, clean, secure.
10. Walls/Doors: full floor-to-ceiling walls in secure areas.
Topic 4: Fire Security and Safety
Fire is a major risk to both people and equipment.
Fire needs: heat + fuel + oxygen
Detection systems:
Information Security - Chapter 9: Physical Security (Simplified Notes)
- Thermal: detects heat rise or fixed temperature.
- Smoke: photoelectric, ionization, or air-aspirating.
- Flame: detects UV/IR light from flames.
Fire suppression:
- Fire extinguishers: Class A (paper), B (liquids), C (electric), D (metal), K (kitchen).
- Sprinklers: wet-pipe, dry-pipe, pre-action, deluge, mist.
- Gases: CO2 (removes oxygen), Halon (chemical reaction), clean agents (safe for people/electronics).
Also: drills, marked exits, fire marshals, smoke detectors.
Topic 5: Failure of Supporting Utilities & Structural Collapse
If utilities fail (power, HVAC, water), systems crash or get damaged.
HVAC:
- Temperature: too hot or cold = risk to devices
- Humidity: low = static; high = short-circuits
- ESD = electrostatic discharge = can destroy circuits
Power:
- Grounding, GFCI, emergency power-off
- UPS types: Standby, Line-interactive, Ferroresonant, Double conversion, Delta conversion
Water problems:
- Leaks and flooding destroy hardware/paper
- Use raised floors, plastic covers, water sensors
Structural safety:
- Inspect buildings regularly
- Use strong, fire-rated construction
Information Security - Chapter 9: Physical Security (Simplified Notes)
Maintenance:
- Test systems regularly, update disaster plans
Topic 6: Interception of Data
Attackers can steal data without touching devices directly.
3 Ways to Intercept Data:
1. Direct Observation:
- Shoulder surfing, spying in cafes
- Prevent: use screen filters, awareness
2. Data Transmission Interception:
- Sniffers, Wi-Fi snooping, cable tapping
- Prevent: encryption, secure ports, use fiber
3. Electromagnetic Interception (EMR):
- Devices leak signals; hackers can recreate data
- Prevent: shielded devices, TEMPEST program
TEMPEST = U.S. government's shield against EM eavesdropping.