We're creating a single website for everything to do with BIS but, while we do that, you'll find information in three places. > Find what you're looking for
One of the simplest but most effective means of protecting information assets is to use physical controls.
These range from the obvious, such as locking sensitive papers away in a drawer at the end of each working day, to more complex solutions such as integrating door access control systems with Closed Circuit Television Cameras (CCTV).
Methods used will depend on budget, the size and type of business, and the sensitivity of information. The following sections provide broad guidance on physical controls. Some may not be applicable to your organisation, but all are worth considering:
It is worthwhile performing a risk analysis exercise to understand the risks and requirements relating to physical security. This should help to decide the appropriate controls required.
If you use access control cards, all permanent staff and contractors should be issued with one. The card should remain the property of the company and be revocable at any time.
Entry cards should only be used by the person to whom they are issued, and should not be given to anyone else, even temporarily.
If you have front desk security staff, all badge holders should produce their ID or access token on request.
Review of access control rights on a regular basis, across all areas of the company, is essential.
It can be worth establishing a defined security perimeter around the company's premises.
This security perimeter should incorporate several layers, with consideration given to the following controls:
There are areas within the security perimeter that may require additional controls. These areas are known as secure areas. Examples include:
Only authorised personnel should be permitted to enter secure areas, and visitors to them should be supervised.
It is sensible to record the entry and departure of visitors to secure areas (for example, identities, dates, times), and visitors should be permitted access only for defined and authorised purposes.
All personnel within secure areas should wear visible identification, and staff should be encouraged to query unescorted strangers in secure areas.
As control lists tend to become out of date quite quickly, access rights to secure areas should be reviewed on a regular basis.
Many companies have limited choice when it comes to location. However, if possible, bear the following points in mind when deciding location and office organisation (data centres, computer rooms, etc):
The location exercise should also take account of:
If possible, isolate delivery and loading areas from main office work areas and information handling facilities. Access to holding and delivery areas should be restricted only to those who need it.
Holding areas should enable items to be loaded or unloaded without access being gained to other parts of the building. External doors should be secured when doors giving access to other parts of the building are open.
Deliveries to a holding area should be registered on entry to the site and inspected for hazards before movement to their point of use.
Hazardous or combustible material should be stored securely at a safe distance from normal premises. Computer supplies (such as stationery) should be stored away from computer rooms until needed.
The following controls are common-sense suggestions that should enhance the protection of your information assets:
For further information about security for remote working, please see our Physical Security and Remote Working section.Also, please see our useful Physical Security checklist.