Skip to content
atlas

Physical security

Also known as: physical controls

Protecting buildings, rooms and equipment so that nobody can simply walk in, take, break or plug into them.

Draft - this entry has not been reviewed yet.

Formal

The controls that protect the physical surroundings of information - sites, server rooms, devices and paper - against entry by outsiders, theft, damage and dangers such as fire, water and power loss. ISO 27002 groups them as its physical controls.

In plain English

The best lock on a diary is no help if someone can simply pick up the whole diary and walk off with it.

In practice

At a regional hospital, a visitor follows a porter through a card-locked door, finds an empty meeting room and plugs a small device into a free network socket; a no-following rule and switched-off sockets would have stopped it.

Why it matters

Anyone with hands on a machine can often get around its digital protection, and fire or flooding can end availability as surely as any attack.

Technical deep dive

Physical security is the control domain that protects the tangible environment of information: sites, rooms, cabling, devices and paper. ISO/IEC 27002:2022 gathers it under clause 7 (Physical controls), which spans physical security perimeters, entry controls, securing offices and facilities, protection against physical and environmental threats, working in secure areas, clear desk and clear screen, equipment siting and protection, supporting utilities, cabling security, equipment maintenance, and secure disposal or re-use of equipment. These sit alongside the organisational, people and technological controls in the same standard, reflecting that a control failure in any one domain can undo the others.

In practice physical controls are layered in concentric rings - site fence, building, floor, room, cabinet - so that defeating one barrier does not grant access to the asset, a physical analogue of defence-in-depth. Deterrent, preventive, detective and corrective measures are combined: fencing and lighting deter, card readers and mantraps (interlocking double-door vestibules that defeat tailgating) prevent, CCTV and intrusion sensors detect, and guards or response procedures correct. A central threat is tailgating or piggybacking, where an unauthorised person follows an authorised one through a controlled door; anti-passback logic in the access system and mantraps are the standard countermeasures. Environmental protection is equally part of the domain: fire detection and suppression (VESDA aspirating detection, inert-gas or clean-agent systems rather than water in server rooms), redundant power via UPS and generators, and HVAC for temperature and humidity all defend availability, since a flood or overheating ends service as effectively as an intruder.

Data centres formalise this with tiered availability models: the Uptime Institute Tier I-IV classification (Tier IV being fault-tolerant with concurrently maintainable, redundant infrastructure) and the EN 50600 series in Europe define expected redundancy and physical protection. Access is typically logged and often gated by multi-factor physical authentication (card plus PIN or biometric), and racks themselves are locked so that colocation tenants cannot reach each other's hardware.

A key principle is that physical access frequently defeats logical controls: an attacker with hands on a device can boot from external media, extract disks, capture data from memory (cold-boot attacks), attach a hardware keylogger, or plant a rogue network implant, which is why full-disk encryption, disabled boot from removable media, port control and tamper-evident seals matter. A common misconception is that physical security is a facilities concern separate from cyber; NIS2 and ISO 27001 treat it as an integral part of information security precisely because so many logical protections assume the attacker is remote. Secure disposal is the frequently forgotten end of the lifecycle: drives and multifunction printers retain data and must be sanitised (per NIST SP 800-88 media-sanitisation guidance) or physically destroyed before disposal.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Asset
  3. →Physical security

Relationships

Requires
Asset
Mandated by
CER Directive

Sources & further reading

Standards & official texts

  • ISO/IEC 27002:2022 - clause 7, Physical controls · ISO/IEC

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.