10.10.2014 Views

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

10.1.1.2 Implement Physical Access Controls<br />

Restrict physical access to system components and the facilities that<br />

house them through the use <strong>of</strong> physical access restrictions:<br />

• All facilities that host system components, including input and<br />

output mechanisms, must house those components in a<br />

dedicated area within that facility.<br />

• Access to the dedicated area that houses system component<br />

shall be restricted.<br />

• Keep components <strong>of</strong> high and very high risk systems in locked<br />

cabinets within the dedicated area within the facility.<br />

10.1.1.3 Make Use <strong>of</strong> Access Logs<br />

To properly vet and maintain records <strong>of</strong> those individuals that have<br />

physically accessed information system components and the facilities<br />

that house them, an access log that captures pertinent information<br />

about each access must be maintained.<br />

10.1.1.4 Make Use <strong>of</strong> Delivery and Removal Documentation<br />

Ensure that system components are not illicitly removed from<br />

facilities nor that materials are illicitly delivered by making use <strong>of</strong><br />

delivery and removal orders and logs.<br />

10.1.1.5 Monitor Physical Access to Systems<br />

To ensure that physical access controls have not been breeched or<br />

otherwise violated, monitoring and physical review is necessary:<br />

• All visitors are to be escorted by facilities personnel while<br />

within the facility.<br />

• Components <strong>of</strong> high risk and very high risk systems will be<br />

actively monitored via camera equipment.<br />

10.2. Physical Environmental Control<br />

The following are the Non-Mandatory Procedures that support the Physical<br />

Environmental Control section <strong>of</strong> the Default Security Requirements:<br />

10.2.1. Provide Environmental Controls<br />

Agencies should implement appropriate environmental controls to ensure the<br />

availability <strong>of</strong> systems:<br />

10.2.1.1 Monitor and Control Temperature and Humidity<br />

The computing components <strong>of</strong> systems are extremely susceptible to<br />

temperature and static electricity and so air quality must be<br />

controlled:<br />

• Temperature most be controlled to prevent the overheating<br />

<strong>of</strong> system components.<br />

• Humidity must be controlled to prevent the build-up <strong>of</strong> static<br />

electricity.<br />

35

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!