Chapter 3: Physical Access Controls - Part 2 Flashcards

1
Q

Physical Access Controls: It can be explicit or implicit (T or F)

A

True. Explicit through a key for each authorized individual or implicit in the job description

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Physical Access Controls: What is the main purpose?

A

Protection from unauthorized individuals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Physical Access Controls: require the traditional metal key to gain entry

A

Bolting Door Locks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Physical Access Controls: The key in bolting door locks should be stamped ___ and issued under_____

A

Do not duplicate

strict management control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Physical Access Controls: use a numeric keypad or dial to gain entry and are often seen
at airport gate entry doors and smaller server rooms

A

Combination door locks (cipher locks)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Physical Access Controls: When must the combination of combination door locks (cipher locks) be changed?

A

At regular intervals or when employees with access is transferred, fired or subject to disciplinary acion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Physical Access Controls: use a magnetic or embedded chip-based plastic card key or token entered into a sensor reader to gain access

A

Electronic Door locks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Physical Access Controls: What are the advantages of electronic door locks over bolted and combination locks?

A
  1. Cards can be assigned to an identifiable individual
  2. It is difficult to duplicate
  3. It can be used to given specific restrictions such as hour of the day or particular entries only.
  4. It can easily be deactivated
  5. Silent or audible alarms can be activated when unauthorized individuals try to access an area
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Physical Access Controls: ___,___ __, and _____ is an administrative process that must be carefully controlled (Electronic Door Locks)

A

Issuing, Accounting for, and Retrieving

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Physical Access Controls: The __ __ is an important item to retrieve when an employee leaves the firm.
(Electronic Door Locks)

A

card key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Physical Access Controls: is a physical control technique that uses a plastic card with a magnetic strip containing encoded data to provide
access to restricted or secure locations

A

swipe card

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Physical Access Controls: are activated by an individual’s unique body features, such as voice, retina,
fingerprint, hand geometry or signature

A

Biometric Door Locks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Physical Access Controls: This system is used in instances when extremely sensitive
facilities must be protected, such as in the military

A

Biometric Door Locks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Physical Access Controls: means all visitors are required to sign a visitor’s log indicating their name, the company they are representing, reason for visiting, person to see and date and time of entry and
departure

A

Manual Logging

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Physical Access Controls: Logging is typically done at the front reception desk and entrance to the computer room upon exit (T or F)

A

False. Logging must be done before entering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Physical Access Controls: In manual logging, before gaining access what must be provided?

A

A verification of identification or ID

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Physical Access Controls: is a feature of electronic and biometric security systems.

A

Electronic logging

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Physical Access Controls: (Electronic logging) All access is logged with successful attempts being highlighted (T or F)

A

False. unsuccesful attempts are highlighted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Physical Access Controls: What should be worn by ALL personnel

A

Identification Badges

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Physical Access Controls: Visitor badges should have similar IDs as employees (T or F)

A

False. They must have a different colored badge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Physical Access Controls: (IDs) IDs can also be used as electronic key cards (T or F)

A

True

22
Q

Physical Access Controls: Video Cameras must be located at ____ and monitored by ___ ___

A

Strategic points
Security Guards

23
Q

Physical Access Controls: Video Cameras must be retained for a short amount of time (T or F)

A

It depends, but it must be retained for possible future playback

24
Q

Physical Access Controls: Video Cameras must be recorded in a sufficient ___ to permit enlarging the image

A

Resolution

25
Q

Physical Access Controls: are very useful if supplemented by video cameras and locked doors.

A

Security Guards

26
Q

Physical Access Controls: Security guards from external agencies mus be?

A

Bonded

27
Q

Physical Access Controls: Controlled visitor access means all visitors should be?

A

Escorted by a responsible employee

28
Q

Physical Access Controls: visitors does not include friends (T or F)

A

False

29
Q

Physical Access Controls: Consultants may not need to be escorted (T or F)

A

True. Long terms consultants may be granted special gust access.

30
Q

Physical Access Controls: All __ ___ __, such as cleaning people and offsite storage services, should be
___ ___.

A

service contract personnel
bonded personnel

31
Q

Physical Access Controls: Having bonded personnel increases physical security (T or F)

A

False. It only limits financial exposure.

32
Q

Physical Access Controls: uses 2 doors found in entries to facilities

A

Deadman doors

33
Q

Physical Access Controls: Deadman doors are also referred to as?

A

Mantrap or airlock entrance

34
Q

Physical Access Controls: Deadman doors reduces the risk of what type?

A

Piggybacking

35
Q

Physical Access Controls: Computer workstation locks are usually employed in?

A

High-security workstations such as process payroll

36
Q

Physical Access Controls: A controlled single-entry point, monitored by a ____ , should be used by __ ___ ___.

A

receptionist

all incoming personnel

37
Q

Physical Access Controls: Emergency exists can be what for quick evacuation

A

wired to an alarmed panic bar

38
Q

Physical Access Controls: What should be the relationship between security personnel and alarm systems

A

The alarms must be heard by security personnel when activated

39
Q

Physical Access Controls: What should be the do’s and dont’s of Secured report/document distribution carts

A
  1. It must be locked
  2. It must not be left unattended
40
Q

Physical Access Controls: Directions to facilities must be clearly stated to guide the personnel (T or F)

A

False. There must be no directions.

41
Q

Physical Access Controls: Computer rooms can be visible from the outside through windows (T or F)

A

False. Computer rooms must not have windows nor should it be visible from the outside

42
Q

Physical Access Controls: The building or department directory should discreetly identify
only the specific location of the information processing facility (T or F)

A

False. only the general location

43
Q

Auditing Physical Access: What do you do to gain an overall understanding and perception of the installation being reveiwed

A

Touring the computer site

44
Q

Auditing Physical Access: If the site is owned by a third party what may be required?

A

A contractual right of audit

45
Q

Auditing Physical Access: A tour provides the opportunity to begin reviewing what?

A

Physical access restrictions

46
Q

Auditing Physical Access: The __ __ and ______ should be included in the tour

A

Computer site, any offsite storage facilities

47
Q

Auditing Physical Access: Much of the testing of physical safeguards can be achieved through visual inspection (T or F)

A

True

48
Q

Auditing Physical Access: What are the documents that assist you?

A
  1. Emergency evacuation procedures
  2. Inspection tags
  3. Fire suppression system test results
  4. Key lock log
49
Q

Auditing Physical Access: What are the other locations to test

A
  • Location of all operator consoles
  • Printer rooms
  • Computer storage rooms (this includes equipment, paper and supply rooms)
  • UPS/generator
  • Location of all communications equipment identified on the network diagram
  • Media storage
  • Offsite backup storage facility
50
Q

Auditing Physical Access: IS auditor should look above the ___ and below the ___ in the computer operations center

A

Above the ceiling panels and below the raised floors

51
Q

Auditing Physical Access: For ground-floor computer room, the IS auditor may consider?

A

walking around the outside of the room