Domain 5: Physical And Environmental Security Flashcards
List some controls that have been implemented for physical security.
Security guards, CCTV, surveillance, intrusion detction, system, requirement for employees to hqv a higher level of security awareness.
CCTV =
Closed circuit TV
Layered defense model
physical security controls should work together with tiered archicture. `if one fails, the other will protect it.
Thecompany’s most sensitive assets would be placed in the innermost contolled zone of the environment.
How does the AIC triad apply to physical security?
- Availability of company resources
- Integrity of the assets and environment
- Confidentiality of the data and business processes.
Examples of natural enivornmental threas
Flods, earthquakes, storms and tornadoes, fires, extreme termperature conditions
Examples of Supply system threats
power distributions outages, communications interruptions, interruption of other resources such as water, gas, air filtration, etc.
Examples of manmade threats
Unauthorized access, both external and internal, explosions, damage by disgruntled employees, employee errors and accidents, vandalism, fraud, themft and others
Examples of politically motivated threats
strikes, riots, civil disobedience, terrorist attacks, bombings and so forth
What is the priority in physical security
Life safety goals. Protecting human life.
Physical security is a combination of:
people, processes, procedures, technology, and equipment, all to protect resources.
First thing an organization must do in the planning process is
define the vulnerabilities, threats, threat agents, and targets
What is collusion? Is it an internal or external threat?
An internal and external threat, where two or more people work together to carry ut fraudulent activity. Many criminal cases have uncovered insiders working with outsiders to defraud or damage a company.
What are some controls for collusion?
procedural protection mechanisms, access contrl, like separation of duties, preemployment background checks, rotations of duties, supervision
Physical security goals: drime and disruption prevention through deterrence. Provide examples
fences
security guards
warning signs
Physical security program goals - reduction of damage through the use of delaying mechanisms. Provide examples
layers of defense that slow down the adversary
•locks
•security personnel
barriers
physical security program goals address: creme or disruption detection. Provide examples
- smoke detectors
- motion detectors
- CCTV
Physical security program goals should address: incident assessment
- Response of security guards to detected incidents
* Determination of damage level
Physical Security Program goals should address: Response Procedures. Provide examples:
- Fire suppression mechanisms
- Emergency response processes
- Law enforcement notification
- Consultation with outside security professionals
What is a performance based approach for physical security.
A method tto determine how beneficial and affective your physical security program is.
Devise measurements and metrics to gauge the effectiveness of your countermeasures.
Management can make informed decisions
Name some performance metrics that could be used in performance based approache
- # of successful crimes
- # of successful disruptions
- # of unsuccessful crimes
- time between detection, assessment, and recovery steps
- # false positive detection alerts
- financial loss of successful disruption or crime
Physical security design will contorporate controls required for these five categories:
1- deterrence 2 - delaying 3 - detection 4 - assessment 5 - response
CPTED
Crime Prevention through Environmental Design
A discipline that outlines how the proper design of a physical environment can reduce crime by directly affecting human behavior. Provides guidance in loss and crime prevention through proper facility construction and environmental components and procedures.
Physical security target hardening focuses on
denying access through physical and artificial barriers likes alarms, locks, fences
You want to protect a side door. Describe the target hardening approach and the CPTED approach.
Target hardening: locks, alarms, cameras on the door; access control mechanism like proximity reader; security guards to monitor
CPTED: no sidewalk leading to the door, no tall trees or bushes to offer seclusion.
What are the 3 main strategies that CPTED brings together the physical environment with social behavior to increase overall protection?
1 - Natural Access Control
2 - Natural Surveillance
3 - Natural Territorial Reinforcement
What is natural access control?
Guidance of people entering and leaving a space by the placement of doors, fences, lighting, landscaping.
Principles of natural surveillance
Natural surveillance strategies include straight lines of sight, low landscaping, raised entrances.
Goal: make criminals feel uncomfortable by providing many ways observers could potentially see them and to make other people feel safe and comfortable by providing an open and well-designed enviornment.
Natural Territorial Reinforcement
Creates physical designs that emphaiszeor extend the company’s physical sphere of influence so that leginitimate users feel a sense ovf ownership of that space.
Every organization should have a facility safety officer. What is their main job?
- Understand all the components that make up the facility and what the company needs to do to protect its assets and stay within compliance.
- Oversee facility management duties day in and day out
- Be heavily involved with the team that has been organized to evaluate the organizations physical security program
What is a physical security program?
- A collection of controls that are implemented and maintained to provide the protection levels necessary to be in compliance with the physical security policy.
- Should embody all regulations and laws
- Should sett the risk level the company is willing ot accept.
What are some issues with selecting a facility site? (4)
- Visibility (surrounding terrain, building markings and signs, types of neighbors, population of the area)
- Surrounding area and external entities (crime rate, riots, terrorism attacks. Proximity to police, medical, and fire stations. Possible hazards from surrounding area)
- Accessibility (road acces. Traffic. Proximity to airports, train stations, highways).
- Natural disaster (likelihood of floods, tornadoes, earthquakes, or hurricanes. Hazardous terrain like mudlides, falling rock, excessive snow/rain).
When designing and buliding a facility, what needs to be addressed from a physical security point of view with the walls?
- combustibility of material (wood, steel, concrete)
- fire rating
- reinforcements for secured areas
When desigining and builidng a fcility, what needs to be addressed from a physical security point of view with the doors?
- combustibility of material (wood, pressed board, aluminum)
- fire rating
- resistance to forcibile entry
- emergency marking
- placement
- locked or controlled entrance
- alarms
- secure hinges
- directional openings
- electic door locks that revert to an unlocked state for safe evacuation in power outages
- type of glass - shatterproof or bulletproof glass requirements
When desigining and building a facility, what needs to be addressed from a physical security point of view for the ceilings?
- combustibility of material (wood, steel, concrete)
- fire rating
- weight-bearing rating
- drop ceiling considerations
When designing and bulidng a facility, what needs to be addressed from a physical sec POV for the windows?
- translucent or opaque requirements
- shatterproof
- alarms
- placement
- accessibility to intruders