Lesson 12: Physical and Facility Security Architecture

Lesson 13/28 | Study Time: 15 Min

Lesson Twelve

Physical and Facility Security Architecture

SierraTec Secure CISSP Certification Preparation Course


Lesson Overview

Cybersecurity is not exclusively digital.

An organization may deploy:

  • strong encryption;

  • multifactor authentication;

  • network segmentation;

  • endpoint protection;

  • Zero Trust;

  • security monitoring;

yet still suffer catastrophic loss if an unauthorized person can physically reach:

  • a server;

  • a network switch;

  • a backup device;

  • a wiring closet;

  • an evidence locker;

  • a building-control system;

  • a critical power source.

Physical and environmental security protects the people, facilities, information systems, infrastructure, media, and supporting services required for organizational operations.

The current CISSP Examination Outline places these topics under Domain 3 β€” Security Architecture and Engineering, specifically:

Objective 3.8

Apply security principles to site and facility design.

Objective 3.9

Design site and facility security controls, including:

  • wiring closets/intermediate distribution facilities;

  • server rooms/data centers;

  • media storage;

  • evidence storage;

  • restricted and work areas;

  • utilities and HVAC;

  • natural and human-caused environmental threats;

  • fire prevention, detection, and suppression;

  • redundant and backup power.

Physical security also directly supports:

  • availability;

  • confidentiality;

  • integrity;

  • safety;

  • business continuity;

  • incident response.

NIST similarly describes physical and environmental controls as protecting facilities, system resources, supporting services, and access to information-system locations; current NIST guidance includes physical-access control, monitoring, environmental controls, fire protection, water-damage protection, and supporting utilities.

The central Lesson Twelve question is:

How should facilities be designed so people, systems, information, communications infrastructure, media, and evidence remain protected against unauthorized access, environmental hazards, utility failures, fire, and other physical threats?


CISSP Exam Objective Alignment

Lesson TopicPrimary Alignment
Site-selection principlesDomain 3.8
Secure facility designDomain 3.8
Layered physical securityDomain 3.8 / 3.9
Perimeter securityDomain 3.8 / 3.9
Fences and barriersDomain 3.8
Gates and bollardsDomain 3.8
LightingDomain 3.8
GuardsDomain 3.8
CCTV/video surveillanceDomain 3.8 / 3.9
Physical intrusion detectionDomain 3.9
Access-control vestibules/mantrapsDomain 3.9
BadgesDomain 3.9
LocksDomain 3.9
BiometricsDomain 3.9 / Domain 5 bridge
TailgatingDomain 3.9
Visitor managementDomain 3.9
Wiring closets/IDFsDomain 3.9
Server rooms/data centersDomain 3.9
Media-storage facilitiesDomain 3.9
Evidence storageDomain 3.9
Restricted areasDomain 3.9
Work-area securityDomain 3.9
UtilitiesDomain 3.9
HVACDomain 3.9
Temperature/humidityDomain 3.9
Water protectionDomain 3.9
Natural disastersDomain 3.9
Human-caused threatsDomain 3.9
Fire preventionDomain 3.9
Fire detectionDomain 3.9
Fire suppressionDomain 3.9
UPSDomain 3.9
GeneratorsDomain 3.9
Redundant powerDomain 3.9
Facility life safetyDomain 3 architecture foundation

Learning Objectives

After completing this lesson, you should be able to:

  1. Explain the relationship between physical security and cybersecurity.

  2. Explain why human life safety has priority during physical emergencies.

  3. Describe risk-based site selection.

  4. Identify physical, environmental, utility, and geographic threats.

  5. Explain layered physical defense.

  6. Distinguish deterrent, preventive, detective, corrective, and recovery physical controls.

  7. Explain the purpose of fences.

  8. Explain gates, barriers, and bollards.

  9. Explain security lighting.

  10. Explain guard-force functions.

  11. Explain CCTV/video-surveillance functions and limitations.

  12. Explain physical intrusion-detection systems.

  13. Describe doors and lock technologies conceptually.

  14. Explain badge and credential systems.

  15. Explain access-control vestibules.

  16. Distinguish tailgating from piggybacking.

  17. Explain visitor-control requirements.

  18. Explain secure loading and delivery areas.

  19. Explain secure wiring-closet design.

  20. Explain secure server-room and data-center design.

  21. Explain media-storage security.

  22. Explain evidence-storage security.

  23. Explain restricted-area controls.

  24. Explain workspace and clean-desk considerations.

  25. Explain facility utility dependencies.

  26. Explain HVAC's role in system availability.

  27. Explain temperature and humidity risks.

  28. Explain static-electricity risks.

  29. Explain water-damage risks.

  30. Explain environmental monitoring.

  31. Identify major natural-disaster threats.

  32. Identify major human-caused physical threats.

  33. Explain the fire triangle.

  34. Explain fire classes A, B, C, D, and K.

  35. Explain why extinguishing agents must match fire type.

  36. Explain smoke and heat detection concepts.

  37. Compare major sprinkler approaches conceptually.

  38. Explain clean-agent suppression.

  39. Explain why electrical fires require special consideration.

  40. Explain the role of Emergency Power Off controls.

  41. Explain UPS.

  42. Explain backup generators.

  43. Explain redundant utility feeds.

  44. Distinguish short-term from long-term power protection.

  45. Explain surge protection and power conditioning.

  46. Explain emergency lighting.

  47. Explain how physical security supports business continuity.

  48. Apply CISSP professional judgment to facility-security scenarios.

  49. Recognize common physical-security examination traps.


Part I β€” Physical Security Is Cybersecurity

1. Why Physical Security Matters

Consider a data center protected by:

  • strong passwords;

  • MFA;

  • firewalls;

  • encryption;

  • SIEM monitoring.

If an unauthorized person can walk into the server room and remove a storage device, logical controls may no longer be sufficient.

Physical access may permit an attacker to:

  • steal equipment;

  • install unauthorized devices;

  • connect to internal networks;

  • reset systems;

  • destroy equipment;

  • disrupt utilities;

  • remove backup media.


2. Physical Security Objectives

Physical security supports:

             PHYSICAL SECURITY
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β–Ό β–Ό β–Ό
CONFIDENTIALITY INTEGRITY AVAILABILITY
β”‚ β”‚ β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β–Ό
SAFETY

3. People Before Equipment

A fundamental CISSP mindset is:

Human life and safety generally take priority over protecting information systems and equipment.

During a building fire, the first objective is not:

Save the server.

It is:

Protect people and safely manage the emergency.


4. Security Versus Safety

Security attempts to prevent:

  • unauthorized access;

  • theft;

  • sabotage.

Safety attempts to protect people from:

  • fire;

  • electrical hazards;

  • toxic conditions;

  • structural failure;

  • other dangerous conditions.

Good facility architecture supports both.


Part II β€” Physical Security as Defense in Depth

5. Layered Physical Security

A secure facility should not depend on one locked door.

                PUBLIC AREA
β”‚
β–Ό
PROPERTY BOUNDARY
β”‚
β–Ό
PERIMETER CONTROL
β”‚
β–Ό
BUILDING ENTRY
β”‚
β–Ό
CONTROLLED AREA
β”‚
β–Ό
RESTRICTED AREA
β”‚
β–Ό
SERVER ROOM
β”‚
β–Ό
SERVER / RACK
β”‚
β–Ό
DATA

An attacker should encounter progressively stronger controls.


6. Concentric Security Zones

Think of physical protection as security rings:

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ PUBLIC SPACE β”‚
β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚ β”‚ PROPERTY PERIMETER β”‚ β”‚
β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚
β”‚ β”‚ β”‚ BUILDING β”‚ β”‚ β”‚
β”‚ β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚ β”‚
β”‚ β”‚ β”‚ β”‚ RESTRICTED AREA β”‚ β”‚ β”‚ β”‚
β”‚ β”‚ β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚ β”‚ β”‚
β”‚ β”‚ β”‚ β”‚ β”‚ DATA CENTER β”‚ β”‚ β”‚ β”‚ β”‚
β”‚ β”‚ β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚ β”‚ β”‚
β”‚ β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚ β”‚
β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚
β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

7. Control Functions

Physical controls can perform different functions.

FunctionExample
DeterrentWarning sign, visible guard
PreventiveLocked door, fence
DetectiveCamera, motion sensor
CorrectiveRepair damaged barrier
RecoveryBackup facility, generator
CompensatingGuard posted where electronic control fails

Remember:

One control may serve more than one function.


Part III β€” Site Selection

8. Security Starts Before Construction

A poorly selected site can impose long-term risks that cannot easily be solved with technology.

Before selecting a facility, evaluate:

  • geographic risk;

  • environmental risk;

  • infrastructure;

  • utility availability;

  • crime;

  • transportation;

  • neighboring facilities;

  • emergency response;

  • business continuity requirements.


9. Site-Risk Categories

SITE RISK
β”‚
β”œβ”€β”€ Natural
β”œβ”€β”€ Human-caused
β”œβ”€β”€ Utility
β”œβ”€β”€ Infrastructure
β”œβ”€β”€ Transportation
└── Security environment

10. Natural Threats

Possible natural hazards include:

  • flooding;

  • hurricanes;

  • tornadoes;

  • earthquakes;

  • wildfires;

  • lightning;

  • extreme temperatures;

  • landslides.


11. Human-Caused Threats

Examples include:

  • crime;

  • vandalism;

  • terrorism;

  • civil unrest;

  • vehicle impacts;

  • sabotage;

  • nearby hazardous industrial activity.


12. Infrastructure Dependencies

A data center may depend on:

  • commercial electrical power;

  • telecommunications;

  • water;

  • fuel delivery;

  • road access;

  • emergency services.

These dependencies should be considered before the facility is selected.


13. Neighboring Hazards

Potential neighboring risks include:

  • chemical plants;

  • fuel-storage facilities;

  • rail lines;

  • airports;

  • high-traffic roads;

  • flood-control infrastructure.

The important CISSP concept is:

Site selection should reflect the organization's threat and business-impact analysis.


14. Geographic Redundancy

Two backup facilities may not provide meaningful geographic resilience if they are:

  • on the same floodplain;

  • on the same electrical grid segment;

  • dependent on the same telecommunications route.

Redundancy should consider:

Common-mode failure.


Part IV β€” Perimeter Security

15. Perimeter

A physical perimeter establishes a controlled boundary around a facility or area.

Possible controls include:

  • fencing;

  • walls;

  • gates;

  • bollards;

  • landscaping;

  • guards;

  • lighting;

  • surveillance.


16. Perimeter Objectives

The perimeter should help:

  1. define private property;

  2. channel people toward authorized entry points;

  3. deter casual intrusion;

  4. delay attackers;

  5. provide detection opportunities.


17. Delay Is Valuable

Physical barriers may not stop a determined attacker forever.

They can:

Increase the time required to reach the target.

That time allows:

  • detection;

  • assessment;

  • response.


18. Physical Security Equation

Conceptually:

DETER
+
DELAY
+
DETECT
+
RESPOND
=
PHYSICAL PROTECTION

Part V β€” Fences

19. Purpose of Fencing

Fences can:

  • define boundaries;

  • deter intrusion;

  • channel entry;

  • delay access.


20. Fence Limitations

A fence alone does not:

  • authenticate a user;

  • detect every intrusion;

  • guarantee prevention.

It should normally be part of layered controls.


21. Clear Zones

Areas near perimeter fencing may be kept sufficiently visible to support:

  • patrol;

  • cameras;

  • intrusion detection;

  • observation.

Dense uncontrolled vegetation may create concealment.


Part VI β€” Bollards and Vehicle Barriers

22. Bollards

Bollards are strong posts or barriers used to help control vehicle movement.

They may protect:

  • entrances;

  • pedestrian areas;

  • critical infrastructure;

  • building walls.


23. Vehicle Risk

Vehicles can be used for:

  • accidental collision;

  • forced entry;

  • delivery of hazardous material.

Vehicle barriers should therefore be risk based.


Part VII β€” Gates and Entry Control

24. Gates

Gates create controlled points through perimeter barriers.

Controls may include:

  • guards;

  • card readers;

  • cameras;

  • vehicle inspection.


25. Minimize Uncontrolled Entrances

More entrances generally create:

  • more monitoring points;

  • more access-control systems;

  • more opportunities for bypass.

This reflects the architecture principle:

Keep security boundaries understandable and manageable.


Part VIII β€” Security Lighting

26. Purpose of Lighting

Security lighting can:

  • deter intruders;

  • improve guard visibility;

  • support cameras;

  • reduce concealment.


27. Poor Lighting

Poor lighting can create:

  • blind spots;

  • shadows;

  • surveillance problems.


28. Too Much Lighting

Excessive or poorly designed lighting can also:

  • create glare;

  • reduce camera image quality;

  • interfere with observation.

The goal is appropriate illuminationβ€”not merely maximum brightness.


Part IX β€” Security Guards

29. Human Security Controls

Guards can provide:

  • identity verification;

  • observation;

  • visitor control;

  • patrol;

  • emergency response;

  • judgment.

Unlike a fixed sensor, a trained guard can interpret context.


30. Guard Limitations

Guard effectiveness depends on:

  • training;

  • staffing;

  • procedures;

  • supervision;

  • communications.

Human controls can suffer from:

  • fatigue;

  • distraction;

  • social engineering.


31. Guard + Technology

A strong model combines:

CAMERA / SENSOR
β”‚
β–Ό
ALERT
β”‚
β–Ό
SECURITY PERSONNEL
β”‚
β–Ό
ASSESS
β”‚
β–Ό
RESPOND

Part X β€” CCTV and Video Surveillance

32. CCTV

Video surveillance supports:

  • deterrence;

  • detection;

  • investigation;

  • evidence.

NIST recognizes video surveillance among mechanisms for monitoring physical access.


33. CCTV Does Not Physically Stop Intrusion

A camera generally:

Detects or records.

A locked barrier:

Prevents or delays.

Do not confuse detective and preventive controls.


34. Camera Design Factors

Consider:

  • coverage;

  • blind spots;

  • lighting;

  • image quality;

  • storage;

  • monitoring;

  • retention;

  • privacy;

  • tamper resistance.


35. Recorded Versus Monitored

A recorded camera may provide:

Evidence after an incident.

A live-monitored camera may also support:

Immediate response.


Part XI β€” Physical Intrusion Detection

36. Intrusion Detection

Physical intrusion systems may detect:

  • door opening;

  • glass break;

  • motion;

  • fence disturbance;

  • unauthorized entry.


37. Sensor Types

Conceptually, sensors may detect:

  • movement;

  • pressure;

  • sound;

  • contact changes;

  • infrared changes.

The exact technology is less important than understanding:

Detection must connect to a response capability.


38. Alert Without Response

INTRUSION SENSOR
β”‚
β–Ό
ALARM
β”‚
β–Ό
NO ONE RESPONDS

is not an effective security program.


Part XII β€” Doors and Locks

39. Door Security

Controlled doors should be considered as complete systems:

  • frame;

  • hinges;

  • lock;

  • credential reader;

  • emergency release;

  • monitoring.

A strong lock on a weak doorframe provides limited protection.


40. Mechanical Locks

Mechanical locks remain common.

Risks include:

  • copied keys;

  • lost keys;

  • difficult revocation.


41. Electronic Locks

Electronic access-control systems may provide:

  • centralized authorization;

  • logging;

  • rapid credential revocation;

  • time-based access.


42. Combination Locks

Combination locks avoid distributing physical keys but require:

  • combination protection;

  • periodic changes;

  • controlled disclosure.


43. Lock Selection

The correct lock depends on:

  • asset value;

  • facility risk;

  • life-safety requirements;

  • emergency access.


Part XIII β€” Badges and Physical Credentials

44. Identification Badge

A badge can identify an authorized person.

It may also function as an electronic access credential.


45. Badge Controls

Good practices may include:

  • unique assignment;

  • visible identification where appropriate;

  • rapid reporting of loss;

  • immediate deactivation upon termination;

  • periodic access review.


46. Badge Alone Is Not Proof of Identity

An attacker can:

  • steal;

  • borrow;

  • duplicate

a badge.

Higher-risk areas may require stronger authentication.


Part XIV β€” Biometrics

47. Physical Biometrics

Biometric controls may use:

  • fingerprints;

  • facial characteristics;

  • iris features;

  • other physical characteristics.

Detailed biometric performance measures will be covered under Domain 5.


48. Multi-Factor Physical Access

High-security areas may require:

BADGE
Something you have
+
PIN
Something you know
+
BIOMETRIC
Something you are

according to risk.


Part XV β€” Access-Control Vestibules

49. Access-Control Vestibule

An access-control vestibule is a controlled space with sequential doors that limits movement through an entry point.

It is sometimes informally called a:

mantrap.


50. Basic Design

PUBLIC AREA
β”‚
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ DOOR A β”‚
β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ CONTROLLED β”‚
β”‚ VESTIBULE β”‚
β”‚ Identity checked β”‚
β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ DOOR B β”‚
β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜
β–Ό
RESTRICTED AREA

Typically, both doors should not permit uncontrolled simultaneous passage.


51. Purpose

The vestibule helps reduce:

  • tailgating;

  • unauthorized entry;

  • rapid forced passage.


52. Life-Safety Requirement

Physical access controls must not create unacceptable danger during:

  • fire;

  • evacuation;

  • emergency.

Again:

Life safety comes first.


Part XVI β€” Tailgating and Piggybacking

53. Tailgating

Tailgating occurs when an unauthorized person follows an authorized person through a controlled entry without proper authorization.

Example:

Employee badges in.
Unknown person follows closely behind.


54. Piggybacking

Terminology varies, but many security training contexts use piggybacking for situations in which an authorized person knowingly permits another person to enter using their access.


55. Countermeasures

Controls may include:

  • awareness;

  • guards;

  • access-control vestibules;

  • turnstiles;

  • anti-passback systems;

  • badge enforcement.


56. Social Pressure

Tailgating succeeds partly because people often want to be polite.

CISSP thinking:

Security culture should allow employees to challenge or refer uncredentialed individuals appropriately.


Part XVII β€” Visitor Management

57. Visitors

Visitors should not automatically receive the same physical access as employees.

Controls may include:

  • registration;

  • identity verification;

  • temporary badge;

  • escort;

  • restricted access;

  • sign-in/out;

  • badge return.

NIST physical-access guidance explicitly calls for visitor controls and escorting where required.


58. Visitor Lifecycle

VISITOR ARRIVES
β”‚
β–Ό
IDENTITY VERIFIED
β”‚
β–Ό
PURPOSE CONFIRMED
β”‚
β–Ό
TEMPORARY CREDENTIAL
β”‚
β–Ό
ESCORT / RESTRICTED ACCESS
β”‚
β–Ό
VISIT COMPLETED
β”‚
β–Ό
BADGE RETURNED
β”‚
β–Ό
ACCESS CLOSED

59. Visitor Logs

Logs may support:

  • investigations;

  • accountability;

  • emergency response.

Retention should follow policy and privacy requirements.


Part XVIII β€” Delivery and Loading Areas

60. Deliveries Create Access Paths

Loading docks may introduce:

  • people;

  • vehicles;

  • packages;

  • equipment

into the facility.

They should be controlled separately from highly restricted operational areas where possible.


61. Delivery Controls

Possible controls include:

  • designated receiving areas;

  • inspection;

  • logging;

  • escort;

  • separation from sensitive infrastructure.


Part XIX β€” Wiring Closets and Intermediate Distribution Facilities

62. Why Wiring Closets Matter

ISC2 explicitly identifies wiring closets and intermediate distribution facilities under Objective 3.9.

A wiring closet may contain:

  • switches;

  • patch panels;

  • fiber connections;

  • telecommunications equipment.

Compromise could permit:

  • network interception;

  • disconnection;

  • unauthorized devices;

  • service disruption.


63. Wiring-Closet Security

Controls may include:

  • locked doors;

  • restricted access;

  • inventory;

  • environmental protection;

  • monitoring.


64. Do Not Use Wiring Closets as General Storage

Combining critical network equipment with:

  • cleaning supplies;

  • unrelated materials;

  • excessive combustibles

can increase:

  • fire;

  • damage;

  • access

risk.


Part XX β€” Server Rooms and Data Centers

65. Critical Facilities

A data center concentrates high-value resources.

Controls should therefore be stronger than for ordinary office areas.


66. Data Center Zones

BUILDING ENTRY
β”‚
β–Ό
CONTROLLED EMPLOYEE AREA
β”‚
β–Ό
RESTRICTED TECHNOLOGY AREA
β”‚
β–Ό
DATA CENTER ENTRY
β”‚
β–Ό
SERVER AISLE / CAGE
β”‚
β–Ό
LOCKED RACK

67. Data Center Controls

Examples:

  • strong authentication;

  • access logging;

  • surveillance;

  • environmental monitoring;

  • redundant power;

  • fire detection;

  • suppression;

  • restricted visitor access.


68. Rack Security

Even after entering the data center, access to certain systems may be further restricted through:

  • locking racks;

  • cages;

  • segmented physical zones.


69. Avoid External Identification

Highly sensitive facilities may avoid unnecessary external markings that advertise:

β€œCritical Data Center.”

Security should avoid revealing unnecessary targeting information.


Part XXI β€” Media Storage

70. Media Storage Facilities

ISC2 explicitly includes media-storage facilities in Objective 3.9.

Media can include:

  • backup tapes;

  • removable drives;

  • archival media;

  • paper records.


71. Media Controls

Protection should reflect:

  • classification;

  • retention;

  • environmental requirements;

  • unauthorized-removal risk.


72. Media Storage Model

MEDIA CREATED
β”‚
β–Ό
CLASSIFIED
β”‚
β–Ό
INVENTORIED
β”‚
β–Ό
SECURE STORAGE
β”‚
β–Ό
AUTHORIZED CHECKOUT
β”‚
β–Ό
RETURN / RETENTION
β”‚
β–Ό
SANITIZATION / DESTRUCTION

73. Off-Site Media

Off-site backups should not simply be moved to another location without considering:

  • encryption;

  • chain of custody;

  • transportation;

  • geographic separation;

  • environmental risk.


Part XXII β€” Evidence Storage

74. Evidence Storage

ISC2 specifically identifies evidence storage as a facility-security topic.

Evidence requires stronger accountability because unauthorized access or alteration can undermine an investigation.


75. Evidence Controls

Possible controls include:

  • restricted access;

  • tamper-evident packaging;

  • documented chain of custody;

  • access logging;

  • surveillance;

  • controlled environmental storage.


76. Evidence Room

AUTHORIZED INVESTIGATOR
β”‚
β–Ό
ACCESS CONTROL
β”‚
β–Ό
ACCESS LOG
β”‚
β–Ό
EVIDENCE STORAGE
β”‚
β–Ό
CHAIN-OF-CUSTODY RECORD

77. Principle

Evidence security emphasizes:

Integrity + Accountability


Part XXIII β€” Restricted Areas

78. Restricted Area

A restricted area is a location where access is limited based on:

  • job responsibility;

  • security requirement;

  • safety;

  • information sensitivity.


79. Need to Know Applies Physically

Just because a person is an employee does not mean the person requires physical access to:

  • the data center;

  • evidence storage;

  • executive offices;

  • network rooms.


80. Physical Least Privilege

Apply:

Least privilege to physical access.

Grant only the access necessary for authorized duties.


Part XXIV β€” Work Area Security

81. Office Areas

Sensitive information may be exposed through:

  • printed documents;

  • unlocked screens;

  • whiteboards;

  • removable media;

  • unattended devices.


82. Clean Desk

A clean-desk approach reduces unattended sensitive information.

It may require:

  • documents secured;

  • removable media stored;

  • passwords not displayed;

  • sensitive notes removed.


83. Screen Protection

Controls may include:

  • automatic screen lock;

  • workstation positioning;

  • privacy screens where appropriate.


Part XXV β€” Utilities

84. Supporting Utilities

Information systems depend on more than servers.

Supporting utilities include:

  • electricity;

  • cooling;

  • water;

  • telecommunications;

  • fuel.

NIST physical-security guidance emphasizes the importance of supporting utilities because their failure can interrupt system operations.


85. Utility Dependency Model

                INFORMATION SYSTEM
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β–Ό β–Ό β–Ό
POWER HVAC TELECOMMUNICATION
β”‚ β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜
β–Ό
FACILITY

If supporting infrastructure fails, information systems may fail even when no cyberattack occurs.


Part XXVI β€” Electrical Power

86. Power Problems

Electrical systems may experience:

  • complete outage;

  • voltage sag;

  • surge;

  • spike;

  • frequency variation;

  • electrical noise.


87. Power Risk

Poor power quality can:

  • crash systems;

  • damage components;

  • corrupt data;

  • reduce equipment life.


88. Layered Power Protection

UTILITY POWER
β”‚
β–Ό
SURGE / CONDITIONING
β”‚
β–Ό
UPS
β”‚
β–Ό
CRITICAL LOAD
β”‚
β–²
β”‚
BACKUP GENERATOR

Part XXVII β€” UPS

89. Uninterruptible Power Supply

A UPS supplies short-term power when normal electrical service fails or becomes unstable.


90. UPS Purpose

A UPS can provide time to:

  • bridge a short outage;

  • start generators;

  • perform controlled shutdown.


91. UPS Is Not Normally Long-Term Power

Exam trap:

UPS β‰  long-duration backup generator.

Battery runtime is finite.


92. UPS Functions

Depending on design, a UPS may also help provide:

  • voltage regulation;

  • power conditioning.


Part XXVIII β€” Backup Generators

93. Generator

A generator provides longer-duration backup power than a typical UPS.


94. Generator Transition

COMMERCIAL POWER FAILS
β”‚
β–Ό
UPS SUPPORTS LOAD
β”‚
β–Ό
GENERATOR STARTS
β”‚
β–Ό
GENERATOR STABILIZES
β”‚
β–Ό
LOAD TRANSFERS

95. Generator Dependencies

A generator requires:

  • fuel;

  • maintenance;

  • testing;

  • suitable capacity.

A generator that has never been tested may fail when needed most.


96. Fuel

Long-duration outage planning must consider:

  • fuel storage;

  • fuel quality;

  • refueling contracts;

  • supply-chain disruption.


Part XXIX β€” Redundant Power

97. Redundancy

ISC2 specifically includes redundant and backup power under Objective 3.9.

Redundant power may include:

  • multiple utility feeds;

  • UPS systems;

  • generators;

  • independent distribution paths.


98. Redundancy Must Reduce Shared Failure

Two power supplies connected to the same failed upstream circuit may provide limited resilience.

Ask:

Are the redundant paths truly independent?


Part XXX β€” Emergency Power Off

99. Emergency Power Off

An Emergency Power Off mechanism may allow authorized personnel to rapidly disconnect electrical power during a serious emergency.


100. Security Consideration

EPO controls should be protected against:

  • accidental activation;

  • unauthorized activation.

Otherwise, the safety mechanism itself could become an availability attack.


Part XXXI β€” Emergency Lighting

101. Emergency Lighting

Loss of utility power should not create unsafe evacuation conditions.

Emergency lighting supports:

  • safe evacuation;

  • emergency response;

  • continuity of physical-security operations.


Part XXXII β€” HVAC

102. Why HVAC Is a Security Control

Computing equipment generates heat.

Without adequate cooling:

  • temperature rises;

  • equipment may throttle;

  • hardware may fail.

ISC2 explicitly includes HVAC in Objective 3.9.

NIST physical/environmental controls call for maintaining and monitoring environmental conditions such as temperature and humidity at acceptable levels.


103. HVAC Objectives

HVAC supports:

  • temperature;

  • humidity;

  • airflow;

  • equipment availability.


104. Cooling Failure

HVAC FAILURE
β”‚
β–Ό
TEMPERATURE RISES
β”‚
β–Ό
EQUIPMENT OVERHEATS
β”‚
β–Ό
SYSTEM SHUTDOWN /
HARDWARE DAMAGE
β”‚
β–Ό
AVAILABILITY LOSS

Part XXXIII β€” Temperature

105. Temperature

Excessive heat can damage systems.

Excessively low temperatures or rapid environmental changes may also create operational problems.

The organization should use:

  • equipment requirements;

  • facility engineering standards;

  • environmental monitoring

rather than memorize one universal temperature for every data center.


Part XXXIV β€” Humidity

106. Low Humidity

Very dry conditions can increase:

Static electricity

risk.


107. High Humidity

Excessive humidity can contribute to:

  • condensation;

  • corrosion;

  • equipment damage.


108. Environmental Balance

TOO DRY
β”‚
β–Ό
STATIC RISK

ACCEPTABLE RANGE
β”‚
β–Ό
STABLE OPERATIONS

TOO HUMID
β”‚
β–Ό
CONDENSATION /
CORROSION

Part XXXV β€” Static Electricity

109. Electrostatic Discharge

Electrostatic discharge can damage sensitive electronic components.

Controls may include:

  • environmental control;

  • grounding;

  • appropriate flooring;

  • antistatic practices.


Part XXXVI β€” Water Damage

110. Water Is a Major Data-Center Threat

Water can come from:

  • plumbing;

  • roof leaks;

  • fire suppression;

  • flooding;

  • condensation.

Current NIST controls specifically address protection against water leakage and recommend accessible water-isolation/shutoff mechanisms where applicable.


111. Facility Design

Organizations should understand:

  • nearby plumbing;

  • drainage;

  • leak detection;

  • flood risk.


112. Placement

Avoid unnecessarily locating critical equipment where foreseeable water hazards are concentrated.


Part XXXVII β€” Environmental Monitoring

113. Monitor the Environment

Sensors may monitor:

  • temperature;

  • humidity;

  • water leakage;

  • smoke;

  • power;

  • physical access.


114. Monitoring Flow

ENVIRONMENTAL SENSOR
β”‚
β–Ό
THRESHOLD EXCEEDED
β”‚
β–Ό
ALERT
β”‚
β–Ό
FACILITY / SECURITY TEAM
β”‚
β–Ό
RESPONSE

NIST's current environmental-control guidance includes alarms or notifications for harmful environmental changes.


Part XXXVIII β€” Natural Disasters

115. Natural Disaster Planning

ISC2 explicitly includes natural disasters in facility-security design.

Possible hazards include:

  • flood;

  • earthquake;

  • wildfire;

  • hurricane;

  • tornado;

  • severe winter weather.


116. Risk Is Location Specific

A flood-control strategy appropriate for one facility may be irrelevant to another.

Physical security should be:

Risk based.


Part XXXIX β€” Human-Caused Environmental Threats

117. Human-Caused Events

Examples include:

  • arson;

  • sabotage;

  • vehicle collision;

  • construction damage;

  • chemical release;

  • civil disturbance.


118. Construction Threat

Nearby excavation can damage:

  • power lines;

  • fiber;

  • water lines.

Not every major outage is the result of malicious cyber activity.


Part XL β€” Fire Fundamentals

119. Fire as a Security Threat

Fire can cause:

  • human injury;

  • equipment destruction;

  • smoke contamination;

  • water damage;

  • prolonged outage.

NIST treats fire protection as a core physical/environmental control for facilities containing concentrated information-system resources.


120. Fire Triangle

Traditional fire education describes three elements necessary for combustion:

             HEAT
/\
/ \
/ \
/ FIRE \
/ \
/__________\
FUEL OXYGEN

Remove an element and combustion can be interrupted.


121. Fire Tetrahedron

A more complete model adds:

Chemical chain reaction.

HEAT
+
FUEL
+
OXYGEN
+
CHAIN REACTION
=
FIRE

Different suppression systems interfere with different parts of this process.


Part XLI β€” Fire Classes

122. Why Fire Classes Matter

Not every extinguishing agent is appropriate for every type of fire.

NFPA recognizes five major portable-extinguisher fire classes: A, B, C, D, and K.


123. Class A

Ordinary Combustibles

Examples:

  • paper;

  • wood;

  • cloth;

  • many ordinary solid materials.


124. Class B

Flammable Liquids

Examples include combustible or flammable liquid hazards.


125. Class C

Energized Electrical Equipment

Examples:

  • energized computing equipment;

  • energized electrical panels.

NFPA notes that Class C refers to fires involving energized electrical equipment, while OSHA warns against using water extinguishers on energized electrical fires because of shock risk.


126. Class D

Combustible Metals

Examples can include:

  • magnesium;

  • sodium;

  • other reactive combustible metals.

Special extinguishing agents may be necessary.


127. Class K

Cooking Oils and Fats

This class is typically associated with:

  • commercial kitchens;

  • cooking oils;

  • fats.


128. Fire Class Table

Fire ClassGeneral Material
AOrdinary combustibles
BFlammable liquids
CEnergized electrical equipment
DCombustible metals
KCooking oils/fats

129. CISSP Exam Principle

Do not assume:

Water should be used on every fire.

OSHA explicitly warns against using water extinguishers on energized electrical fires and flammable-liquid fires.


Part XLII β€” Fire Prevention

130. Prevention Comes Before Suppression

Good facility design reduces the chance of fire through:

  • electrical maintenance;

  • housekeeping;

  • appropriate storage;

  • equipment inspections;

  • limiting combustibles.


Part XLIII β€” Fire Detection

131. Detection Technologies

Fire detection may use:

  • smoke;

  • heat;

  • flame

detection methods.


132. Smoke Detection

Smoke detectors may identify fire before significant heat develops.

Early detection can reduce response time.


133. Heat Detection

Heat detectors respond when:

  • temperature reaches a threshold;

  • or temperature rises unusually quickly,

depending on design.


134. Detection Should Trigger Response

FIRE DETECTOR
β”‚
β–Ό
ALARM
β”‚
β”œβ”€β”€ Notify occupants
β”œβ”€β”€ Notify responders
└── Trigger configured facility actions

NIST fire-protection guidance includes automatic detection and notification to appropriate personnel/responders.


Part XLIV β€” Fire Suppression

135. Suppression Objective

A suppression system attempts to extinguish or control fire while balancing:

  • life safety;

  • equipment protection;

  • business continuity.


136. Suppression Technologies

Possible systems include:

  • portable extinguishers;

  • sprinklers;

  • clean-agent systems;

  • specialized systems for specific hazards.


Part XLV β€” Water Sprinkler Systems

137. Wet-Pipe Concept

In a typical wet-pipe system:

Water is already present in the sprinkler piping.

When a sprinkler head activates due to sufficient heat, water is released from the activated head.


138. Dry-Pipe Concept

In a dry-pipe system:

Piping normally contains pressurized air rather than water.

When the system activates, water enters the piping.

These systems may be used where freezing is a concern.


139. Preaction Concept

A preaction system requires an additional detection/activation condition before water enters the sprinkler piping.

This can reduce the chance that a simple pipe or sprinkler-head problem immediately releases water into a sensitive technology area.


140. Data Center Exam Focus

Preaction systems are often discussed in CISSP training because data centers need to balance:

  • fire control;

  • accidental water-discharge risk.


Part XLVI β€” Clean-Agent Systems

141. Clean Agent

A clean-agent fire-suppression system uses an agent designed to suppress fire without leaving the same kind of residue associated with many conventional extinguishing materials.

This can be useful around:

  • electronic equipment;

  • critical computing systems.


142. People Still Matter

Even when a clean-agent system protects technology, facility design must consider:

  • occupant safety;

  • evacuation;

  • alarms;

  • applicable fire codes.


143. Historical Halon Note

Halon systems are frequently encountered in older cybersecurity study materials because they were historically used around sensitive electronics.

For examination reasoning:

Treat Halon primarily as a legacy/historical suppression technology, not as the default recommendation for a modern facility.


Part XLVII β€” Suppression Selection

144. Choose Based on Hazard

The correct suppression system depends on:

  • fire type;

  • occupancy;

  • equipment;

  • regulatory requirements;

  • life safety.


145. Suppression Decision

FIRE HAZARD IDENTIFIED
β”‚
β–Ό
WHAT IS BURNING?
β”‚
β–Ό
ARE PEOPLE PRESENT?
β”‚
β–Ό
WHAT EQUIPMENT IS PRESENT?
β”‚
β–Ό
SELECT APPROVED
SUPPRESSION METHOD

Part XLVIII β€” Fire Control and Life Safety

146. Never Sacrifice People for Systems

If a suppression choice creates unacceptable danger to people:

The architecture is wrong.

The CISSP professional prioritizes life safety.


Part XLIX β€” Data Center Integrated Environmental Design

147. Integrated Protection

                    DATA CENTER
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β–Ό β–Ό β–Ό
PHYSICAL ACCESS POWER HVAC
β”‚ β”‚ β”‚
β–Ό β–Ό β–Ό
BADGE/BIOMETRIC UPS/GENERATOR TEMP/HUMIDITY
β”‚ β”‚ β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β–Ό β–Ό
FIRE DETECTION WATER
β”‚ DETECTION
β–Ό β”‚
FIRE SUPPRESSION β”‚
β””β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”˜
β–Ό
MONITORING

Part L β€” Facility Security and Business Continuity

148. Physical Security Supports Continuity

A facility may experience:

  • power loss;

  • flooding;

  • fire;

  • civil disturbance;

  • HVAC failure.

Business continuity asks:

How does the organization continue its essential mission?


149. Layered Resilience

PREVENT
β”‚
β–Ό
DETECT
β”‚
β–Ό
RESPOND
β”‚
β–Ό
RECOVER

Physical security participates in every phase.


Part LI β€” Physical Access Logging

150. Access Logs

Physical access systems can record:

  • identity;

  • location;

  • date/time;

  • entry/exit events.

NIST guidance calls for maintaining physical-access audit logs and monitoring access to sensitive facilities.


151. Log Review

Merely collecting logs is insufficient.

Review can detect:

  • access outside expected hours;

  • repeated denied entry;

  • abnormal activity.


Part LII β€” Anti-Passback

152. Anti-Passback Concept

An electronic access-control system can prevent the same credential from being used repeatedly to admit multiple people in ways inconsistent with expected entry/exit sequence.


153. Benefit

Anti-passback can reduce:

  • badge sharing;

  • some forms of tailgating.


Part LIII β€” Physical Key Management

154. Keys Are Credentials

Physical keys should be treated as access credentials.

Control:

  • issuance;

  • inventory;

  • return;

  • duplication;

  • loss.


155. Employee Departure

When someone leaves:

  • badges should be disabled;

  • keys should be returned;

  • access lists should be updated.

This connects physical access with IAM lifecycle management.


Part LIV β€” Facility Security Zones

156. Zone Model

A practical facility model may use:

ZoneAccess Level
PublicGeneral visitors
ControlledEmployees/approved visitors
RestrictedSpecific authorized personnel
High SecurityHighly limited privileged access

157. Progressive Control

Controls should generally become stronger as asset criticality increases.


Part LV β€” Physical Security and Privacy

158. Surveillance Has Privacy Implications

Cameras and access logs can contain information about:

  • employees;

  • visitors;

  • movements.

Therefore:

  • collection;

  • use;

  • retention;

  • access

should follow applicable privacy requirements.


Part LVI β€” Physical Security Testing

159. Controls Need Testing

Test:

  • door alarms;

  • backup power;

  • generators;

  • environmental alerts;

  • emergency procedures.

A control that exists only on paper may fail during a real event.


160. Generator Test Example

Weak:

β€œWe own a generator.”

Stronger:

β€œThe generator is maintained, load-tested, fueled, monitored, and integrated with documented transfer procedures.”


Part LVII β€” Common Failure Scenarios

161. Access Control Failure

Electronic badge readers fail.

Possible compensating measure:

Post trained security personnel according to emergency access procedures.


162. HVAC Failure

Cooling fails.

Correct response may involve:

  • alert;

  • workload reduction;

  • controlled shutdown;

  • migration,

depending on design.


163. Water Leak

Water detected near equipment.

Response may require:

  • leak isolation;

  • equipment protection;

  • facility emergency procedures.


164. Power Failure

Utility power fails.

Expected sequence:

UTILITY LOSS
β”‚
β–Ό
UPS
β”‚
β–Ό
GENERATOR
β”‚
β–Ό
CONTINUED OPERATION
OR
CONTROLLED SHUTDOWN

Part LVIII β€” SierraTec Secure PHYSICAL Model

165. PHYSICAL Framework

Use the SierraTec Secure PHYSICAL model for facility questions.

P β€” Protect People

Life safety comes first.

H β€” Hazards

Identify natural, human, environmental, and utility threats.

Y β€” Your Perimeter

Establish layered physical boundaries.

S β€” Secure Critical Areas

Protect server rooms, wiring closets, media, and evidence.

I β€” Infrastructure Resilience

Protect power, HVAC, water, and communications.

C β€” Control Entry

Authenticate, authorize, monitor, and log physical access.

A β€” Alarm and Detect

Use surveillance, sensors, and environmental monitoring.

L β€” Limit Failure and Recover

Use redundancy, backup power, fire protection, and recovery planning.


166. PHYSICAL Diagram

P
PROTECT PEOPLE
β”‚
β–Ό
H
HAZARDS
β”‚
β–Ό
Y
YOUR PERIMETER
β”‚
β–Ό
S
SECURE CRITICAL AREAS
β”‚
β–Ό
I
INFRASTRUCTURE RESILIENCE
β”‚
β–Ό
C
CONTROL ENTRY
β”‚
β–Ό
A
ALARM & DETECT
β”‚
β–Ό
L
LIMIT FAILURE & RECOVER

Part LIX β€” Worked CISSP Scenarios

167. Scenario 1 β€” Facility Fire

A fire is detected in a server room while employees are still inside the facility.

What is the PRIMARY consideration?

A. Preserve the servers.

B. Human life and safe evacuation.

C. Preserve camera recordings first.

D. Save backup media.

Correct Answer

B

Life safety takes priority.


168. Scenario 2 β€” Wiring Closet

A building's network wiring closet is unlocked and routinely used for storing cleaning supplies.

What is the BEST security recommendation?

A. Restrict access and use the space appropriately for communications infrastructure.

B. Add more cleaning supplies.

C. Disable all logging.

D. Give visitors keys.

Correct Answer

A


169. Scenario 3 β€” Visitor

A vendor technician needs temporary access to a restricted data-center area.

What is the BEST approach?

A. Give the technician permanent unrestricted access.

B. Verify authorization, issue appropriate temporary access, and escort/monitor as required.

C. Allow entry without recording the visit.

D. Borrow another employee's badge.

Correct Answer

B


170. Scenario 4 β€” Tailgating

An employee badges into a secure area and an unknown person follows before the door closes.

What occurred?

A. Tailgating.

B. Hash collision.

C. Cryptographic downgrade.

D. Data remanence.

Correct Answer

A


171. Scenario 5 β€” Camera

An organization deploys cameras but has no process to monitor alerts or review recordings.

What is the PRIMARY weakness?

A. Detection is not integrated with effective response.

B. Cameras are always preventive controls.

C. Lighting is unnecessary.

D. Badge access is automatically replaced.

Correct Answer

A


172. Scenario 6 β€” Power

Utility power is lost. Management needs systems to continue running while generators start.

Which control is MOST directly designed for this gap?

A. UPS.

B. CCTV.

C. Fence.

D. Fire extinguisher.

Correct Answer

A


173. Scenario 7 β€” Long Power Failure

A site must continue operating through an extended commercial-power outage.

Which control is MOST important beyond short-duration UPS capability?

A. Backup generator and fuel strategy.

B. Additional badges.

C. Data masking.

D. Stronger hashing.

Correct Answer

A


174. Scenario 8 β€” Cooling

A data center experiences an HVAC failure.

What security objective is MOST immediately threatened?

A. Availability.

B. Nonrepudiation.

C. Copyright.

D. Authentication.

Correct Answer

A


175. Scenario 9 β€” Humidity

A data center's air becomes excessively dry.

Which physical risk increases?

A. Electrostatic discharge.

B. Flooding.

C. Certificate expiration.

D. Tailgating.

Correct Answer

A


176. Scenario 10 β€” Electrical Fire

An energized electrical cabinet catches fire.

Which principle is MOST important?

A. Use an extinguishing approach appropriate for energized electrical equipment.

B. Immediately throw water onto it regardless of conditions.

C. Ignore electrical shock risk.

D. Treat every fire identically.

Correct Answer

A

Class C considerations apply while equipment remains energized.


Part LX β€” More CISSP Scenarios

177. Scenario 11 β€” Evidence

An evidence room is unlocked during normal working hours because β€œonly employees are in the building.”

What is the PRIMARY concern?

A. Evidence integrity and chain-of-custody risk.

B. Excessive encryption.

C. Too much availability.

D. Data classification.

Correct Answer

A


178. Scenario 12 β€” Redundant Power

A data center has two UPS units, but both receive power from exactly the same upstream electrical distribution point with no alternate path.

What is the PRIMARY weakness?

A. Common-mode failure.

B. Too much redundancy.

C. Excessive authentication.

D. Certificate revocation.

Correct Answer

A


179. Scenario 13 β€” Root Cause

A critical server room repeatedly overheats even though every server has redundant power supplies.

Which principle is MOST relevant?

A. Supporting environmental systems such as HVAC are part of availability architecture.

B. More server passwords are required.

C. Encryption should be removed.

D. Visitor logs will solve the problem.

Correct Answer

A


180. Scenario 14 β€” Water

Critical servers are located immediately below plumbing without leak detection.

What is the PRIMARY physical-design concern?

A. Water-damage exposure.

B. Cryptographic attack.

C. Excessive CPU utilization.

D. Data minimization.

Correct Answer

A


181. Scenario 15 β€” Access Failure

The electronic entry system for a restricted facility fails.

What is the BEST response?

A. Follow documented contingency procedures and use appropriate compensating access controls.

B. Prop every restricted door open.

C. Stop logging all access permanently.

D. Allow anyone who claims to work there inside.

Correct Answer

A


Part LXI β€” Common CISSP Exam Traps

182. Trap β€” Physical Security Is Not Cybersecurity

Incorrect.

Physical compromise can directly undermine logical security.


183. Trap β€” Protect Servers Before People

Incorrect.

Life safety has priority during emergencies.


184. Trap β€” Cameras Prevent Intrusion

Cameras primarily provide:

  • deterrence;

  • detection;

  • evidence.

They do not physically prevent entry by themselves.


185. Trap β€” More Doors Mean Better Security

More uncontrolled entry points may increase attack surface.


186. Trap β€” A Fence Must Stop Every Intruder

A fence may primarily:

  • deter;

  • channel;

  • delay.

Defense in depth completes the protection strategy.


187. Trap β€” Employee Badge Means Access Everywhere

Apply physical least privilege.


188. Trap β€” UPS Provides Unlimited Backup Power

No.

UPS systems generally provide short-duration support.


189. Trap β€” Generator Starts Instantly

Generators require startup and stabilization time.

UPS can bridge that gap.


190. Trap β€” Redundant Means Independent

Two components sharing a common dependency can still fail together.


191. Trap β€” HVAC Is a Comfort System Only

For data centers, HVAC is an availability control.


192. Trap β€” Water Is Appropriate for Every Fire

No.

Extinguishing method must match the hazard. OSHA specifically warns against water extinguishers on energized electrical and flammable-liquid fires.


193. Trap β€” Clean Agent Means Ignore Evacuation

No.

Life safety remains primary.


194. Trap β€” Fire Suppression Is Enough

A complete strategy includes:

  • prevention;

  • detection;

  • suppression;

  • response.


195. Trap β€” Evidence Storage Is Just Ordinary File Storage

Evidence requires stronger:

  • integrity;

  • accountability;

  • chain-of-custody

controls.


196. Trap β€” Security Controls Can Block Emergency Exit

Physical security design must comply with life-safety requirements.


Part LXII β€” Knowledge Check

197. Knowledge Check

Question 1

What is the PRIMARY concern during a facility emergency?

A. Human safety.

B. Server uptime at any cost.

C. Protecting office furniture.

D. Certificate renewal.

Correct Answer

A


Question 2

Which physical-security approach uses multiple concentric protection layers?

A. Defense in depth.

B. Hashing.

C. Data masking.

D. Tokenization.

Correct Answer

A


Question 3

Which control primarily defines and delays crossing a property boundary?

A. Fence.

B. HMAC.

C. DLP.

D. Certificate.

Correct Answer

A


Question 4

Which control is commonly used to restrict vehicle approach?

A. Bollard.

B. Hash.

C. RAID.

D. CASB.

Correct Answer

A


Question 5

Which is primarily a detective physical control?

A. CCTV.

B. Wall.

C. Locked door.

D. Bollard.

Correct Answer

A


Question 6

What is tailgating?

A. Unauthorized person following an authorized person through a controlled entry.

B. Brute-forcing a password.

C. Encrypting a file.

D. Renewing a certificate.

Correct Answer

A


Question 7

What physical-security principle should be applied to server-room access?

A. Least privilege.

B. Public access.

C. Anonymous access.

D. Maximum employee convenience regardless of risk.

Correct Answer

A


Question 8

Why should wiring closets be protected?

A. They contain critical communications infrastructure.

B. They contain no technology.

C. They are always public spaces.

D. They replace data centers.

Correct Answer

A


Question 9

Which area requires particularly strong integrity and accountability controls?

A. Evidence storage.

B. Public lobby.

C. Cafeteria.

D. Public parking.

Correct Answer

A


Question 10

Which control is designed primarily to bridge short electrical outages?

A. UPS.

B. Generator fuel tank alone.

C. CCTV.

D. Fence.

Correct Answer

A


Question 11

Which system is generally intended for longer-duration emergency electrical generation?

A. Backup generator.

B. Door lock.

C. Smoke detector.

D. Biometrics.

Correct Answer

A


Question 12

Why is HVAC important to information security?

A. It maintains environmental conditions necessary for equipment operation.

B. It performs hashing.

C. It issues certificates.

D. It authenticates users.

Correct Answer

A


Question 13

Excessively dry conditions increase which risk?

A. Static electricity.

B. Flooding.

C. Certificate revocation.

D. Tailgating.

Correct Answer

A


Question 14

Excessive humidity can increase the risk of:

A. Condensation and corrosion.

B. Brute-force attacks.

C. Certificate expiry.

D. Pass-the-hash.

Correct Answer

A


Question 15

Class A fires generally involve:

A. Ordinary combustibles.

B. Energized electrical equipment only.

C. Combustible metals.

D. Cooking oils only.

Correct Answer

A


Question 16

Class C applies to:

A. Energized electrical equipment.

B. Ordinary paper only.

C. Combustible metal only.

D. Cooking oil only.

Correct Answer

A


Question 17

Class D involves:

A. Combustible metals.

B. Office paper.

C. Server passwords.

D. Cooking fats.

Correct Answer

A


Question 18

Class K primarily involves:

A. Cooking oils and fats.

B. Electrical wiring.

C. Wood.

D. Sodium metal.

Correct Answer

A


Question 19

Which technology may be selected to reduce water-discharge risk in a sensitive technology environment while still retaining sprinkler protection?

A. Appropriately designed preaction system.

B. Open garden hose.

C. Badge reader.

D. UPS.

Correct Answer

A


Question 20

Which is the BEST definition of physical defense in depth?

A. Multiple complementary layers protecting an asset from perimeter to target.

B. One extremely strong door.

C. One camera.

D. One guard.

Correct Answer

A


Part LXIII β€” Original CISSP-Style Practice Questions

198. Practice Question 1

A security architect is selecting a new data-center location.

Which should be evaluated FIRST?

A. Business requirements and site-specific risks.

B. Paint color.

C. Camera brand.

D. Employee desk layout.

Correct Answer

A


199. Practice Question 2

An organization places its primary and disaster-recovery data centers in buildings next to one another.

What is the GREATEST concern?

A. A single regional or local event may affect both locations.

B. They may have too much redundancy.

C. Encryption will stop working.

D. Visitors will automatically gain access.

Correct Answer

A


200. Practice Question 3

A company wants to improve security against unauthorized individuals following employees into a restricted data center.

Which control is MOST directly relevant?

A. Access-control vestibule.

B. Hash function.

C. Backup generator.

D. Data classification.

Correct Answer

A


201. Practice Question 4

A facility has excellent perimeter fencing but no alarms, guards, or monitoring.

What is the GREATEST weakness?

A. The organization can delay intrusion but may not detect and respond effectively.

B. Fences eliminate all physical risk.

C. Access logging is unnecessary.

D. More encryption is the only answer.

Correct Answer

A


202. Practice Question 5

The main electrical utility fails. The UPS supports the load while the generator starts.

Which design principle is MOST clearly demonstrated?

A. Layered resilience.

B. Data hiding.

C. Hashing.

D. Nonrepudiation.

Correct Answer

A


203. Practice Question 6

A server room has redundant servers and storage but only one cooling unit.

What is the PRIMARY concern?

A. HVAC creates a single point of failure.

B. Too much redundancy.

C. Lack of digital signatures.

D. Employee training.

Correct Answer

A


204. Practice Question 7

An employee with no networking responsibilities can enter the telecommunications closet because all employee badges work on every door.

Which principle has been violated?

A. Least privilege.

B. Nonrepudiation.

C. Data minimization.

D. Cryptographic agility.

Correct Answer

A


205. Practice Question 8

A facility keeps backup tapes in an unlocked cabinet next to the production servers.

Which improvement would BEST increase resilience?

A. Store protected backup media in appropriately secured and geographically separated storage according to risk.

B. Remove encryption.

C. Let all employees use the tapes.

D. Eliminate media inventory.

Correct Answer

A


206. Practice Question 9

A fire breaks out in an occupied data center. Management orders staff to remain inside to shut down every server before evacuation.

What is the PRIMARY problem?

A. The response improperly prioritizes equipment over human safety.

B. The servers might remain available.

C. The facility has too many alarms.

D. The fire is automatically Class D.

Correct Answer

A


207. Practice Question 10

A data center owns a generator but has no documented maintenance, testing, or fuel-replenishment program.

What is the BEST conclusion?

A. The existence of the control does not establish its effectiveness.

B. The generator guarantees continuity.

C. Testing would weaken the generator.

D. The UPS is therefore unnecessary.

Correct Answer

A


Part LXIV β€” Facility Control Comparison

208. Control Matrix

ControlPrimary Function
FenceDeter/delay
BollardVehicle barrier
LockPrevent access
BadgeIdentify/authorize
VestibuleControl individual entry
CameraDetect/record
Motion sensorDetect
GuardDeter/detect/respond
UPSShort-term power resilience
GeneratorExtended backup power
HVACEnvironmental availability
Smoke detectorFire detection
SprinklerFire suppression
Clean agentFire suppression around suitable environments
Water sensorEnvironmental detection

Part LXV β€” Fire Memory Table

209. Fire Classes

ClassThink
AOrdinary combustibles
BFlammable liquids
CEnergized electrical equipment
DCombustible metals
KCooking oils/fats

These classifications are consistent with current NFPA and OSHA fire-extinguisher guidance.


Part LXVI β€” Power Memory Table

210. Power Controls

ControlMain Purpose
Surge protectionProtect from voltage spikes
Power conditioningImprove power quality
UPSImmediate/short-term backup
GeneratorLonger-duration backup
Redundant feedAlternate power path
Emergency lightingSupport safe evacuation/operations

Part LXVII β€” Key Terms

211. Key Terms

Physical Security

Protection of people, facilities, systems, and supporting infrastructure against physical threats.

Perimeter

Boundary defining or protecting a controlled physical area.

Bollard

Physical post/barrier designed to restrict vehicle movement.

CCTV

Video-surveillance system used for deterrence, monitoring, detection, and evidence.

Tailgating

Unauthorized following of an authorized person through a controlled entry.

Piggybacking

Common term for knowingly allowing another person to enter using one's authorized access.

Access-Control Vestibule

Controlled space using sequential doors to regulate entry.

Restricted Area

Area accessible only to specifically authorized individuals.

Wiring Closet / IDF

Area containing communications and network distribution equipment.

UPS

Uninterruptible Power Supply providing immediate short-duration electrical support.

Generator

Equipment providing longer-duration emergency electrical power.

HVAC

Heating, Ventilation, and Air Conditioning system supporting environmental conditions.

Electrostatic Discharge

Electrical discharge capable of damaging sensitive electronics.

Environmental Monitoring

Use of sensors and alarms to observe temperature, humidity, water, smoke, or related conditions.

Fire Detection

Mechanisms designed to detect signs of fire.

Fire Suppression

Systems or equipment intended to control or extinguish fire.

Wet-Pipe System

Sprinkler system with water normally present in the piping.

Dry-Pipe System

Sprinkler system in which piping normally contains pressurized air until activation.

Preaction System

Sprinkler design requiring detection/activation conditions before water fills appropriate piping.

Clean Agent

Fire-suppression agent intended to extinguish fire without leaving significant residue.

Class A Fire

Fire involving ordinary combustibles.

Class B Fire

Fire involving flammable liquids.

Class C Fire

Fire involving energized electrical equipment.

Class D Fire

Fire involving combustible metals.

Class K Fire

Fire involving cooking oils and fats.

Common-Mode Failure

One failure event that defeats multiple supposedly redundant components.

Physical Least Privilege

Restricting physical access to only what a person's duties require.


Part LXVIII β€” CISSP Exam Focus

212. Facility-Security Mindset

Remember:

PEOPLE
β”‚
β–Ό
SITE
β”‚
β–Ό
PERIMETER
β”‚
β–Ό
BUILDING
β”‚
β–Ό
RESTRICTED AREA
β”‚
β–Ό
CRITICAL SYSTEM
β”‚
β–Ό
SUPPORTING UTILITIES
β”‚
β–Ό
MONITOR / RESPOND / RECOVER

For CISSP questions:

  • Human safety comes before protecting equipment.

  • Site security begins with risk-based location selection.

  • Physical security uses defense in depth.

  • Perimeter controls often deter and delay.

  • Detective controls require a response process.

  • Cameras do not physically stop an intruder.

  • Guards provide judgment and response.

  • Tailgating bypasses normal access controls.

  • Visitor access should be controlled and appropriately logged.

  • Access-control vestibules can help prevent unauthorized following.

  • Apply least privilege to physical access.

  • Wiring closets contain critical infrastructure and require protection.

  • Data centers need physical, power, HVAC, fire, and environmental controls.

  • Media storage requires security matching the data classification.

  • Evidence storage emphasizes integrity and chain of custody.

  • Power, HVAC, and telecommunications are security dependencies.

  • UPS provides immediate short-duration power support.

  • Generators provide longer-duration backup.

  • Redundancy should avoid common-mode failure.

  • HVAC directly supports availability.

  • Low humidity can increase static risk.

  • High humidity can increase condensation/corrosion risk.

  • Water leakage requires planning and monitoring.

  • Natural and human-caused hazards must be addressed.

  • Fire security includes prevention, detection, and suppression.

  • Fire agents must match the hazard.

  • Class C involves energized electrical equipment.

  • Do not use water indiscriminately on energized electrical or flammable-liquid fires.

  • Physical controls should be tested, not merely installed.

  • Security should never create unacceptable life-safety risk.

The current ISC2 outline explicitly requires candidates to apply security principles to site/facility design and design controls for wiring closets, data centers, media/evidence storage, restricted areas, utilities/HVAC, environmental hazards, fire, and backup/redundant power.


213. Lesson Summary

Lesson Twelve established the physical and environmental foundation of secure systems.

The CISSP professional must understand that cybersecurity depends on much more than software.

A secure facility protects:

PEOPLE
↓
FACILITY
↓
POWER / HVAC / UTILITIES
↓
COMMUNICATIONS
↓
COMPUTING SYSTEMS
↓
MEDIA / EVIDENCE
↓
INFORMATION

You learned that facility protection starts with site selection and moves inward through layered security zones.

PUBLIC
↓
PERIMETER
↓
CONTROLLED BUILDING
↓
RESTRICTED AREA
↓
DATA CENTER
↓
LOCKED SYSTEM
↓
DATA

You examined:

  • fences;

  • bollards;

  • lighting;

  • guards;

  • CCTV;

  • intrusion detection;

  • locks;

  • badges;

  • biometrics;

  • access-control vestibules;

  • visitor controls.

Current NIST guidance similarly emphasizes verifying physical-access authorization, controlling ingress and egress, maintaining physical-access logs, monitoring facilities, and controlling visitors.

You then examined critical facility areas specifically named in the current CISSP outline:

  • wiring closets;

  • server rooms;

  • data centers;

  • media storage;

  • evidence storage;

  • restricted and work areas.

You learned that supporting infrastructure is itself a security dependency:

POWER
+
COOLING
+
TELECOMMUNICATIONS
+
ENVIRONMENTAL CONTROL
=
SYSTEM AVAILABILITY

Current NIST physical and environmental controls also recognize environmental monitoring, water-damage protection, fire protection, and supporting utility controls as important protections for information systems.

You studied power resilience:

UTILITY
↓
UPS
↓
GENERATOR
↓
CRITICAL SYSTEM

and learned that redundancy must account for common dependencies rather than merely duplicate components.

Finally, you studied fire prevention, detection, and suppression.

The current NFPA and OSHA frameworks recognize Class A, B, C, D, and K fire/extinguisher categories; extinguishing methods must be appropriate to the hazard.

The most important Lesson Twelve principle is:

Physical security must protect people first, then use layered barriers, controlled access, resilient utilities, environmental protection, fire safety, monitoring, and tested recovery capabilities to protect systems and information throughout the facility.


Exam Readiness Check

Before proceeding, make sure you can explain without reviewing the lesson:

  • Why physical security is part of cybersecurity.

  • Why life safety has priority.

  • How site selection affects security.

  • What common-mode failure means.

  • What layered physical security means.

  • How deterrent, preventive, and detective controls differ.

  • What fences accomplish.

  • What bollards accomplish.

  • Why security lighting matters.

  • What guards add that automated controls may not.

  • Why cameras are primarily detective/evidentiary controls.

  • Why alarm systems require response procedures.

  • What an access-control vestibule does.

  • What tailgating means.

  • What piggybacking means.

  • How visitor control should work.

  • Why loading areas require security.

  • Why wiring closets must be restricted.

  • Why server rooms require stronger controls than normal office areas.

  • Why media storage needs physical protection.

  • Why evidence storage requires strict accountability.

  • What physical least privilege means.

  • What clean-desk practices accomplish.

  • Why supporting utilities are part of cybersecurity architecture.

  • The difference between UPS and generator power.

  • Why generator fuel and testing matter.

  • Why redundant paths should be independent.

  • Why HVAC is a security control.

  • What low humidity can cause.

  • What high humidity can cause.

  • Why water detection matters.

  • Why environmental monitoring should generate alerts.

  • How natural and human-caused threats differ.

  • What the fire triangle represents.

  • What Class A fire means.

  • What Class B fire means.

  • What Class C fire means.

  • What Class D fire means.

  • What Class K fire means.

  • Why water should not be used indiscriminately on electrical fires.

  • The difference among wet-pipe, dry-pipe, and preaction concepts.

  • What clean-agent suppression accomplishes.

  • Why fire suppression never replaces evacuation and life-safety planning.

  • Why physical controls must be periodically tested.


Coming Next

Lesson Thirteen: Information System Lifecycle and Secure Engineering

The current CISSP Examination Outline now includes Domain 3.10 β€” Manage the information system lifecycle, which covers:

  • stakeholder needs and requirements;

  • requirements analysis;

  • architectural design;

  • development and implementation;

  • integration;

  • verification and validation;

  • transition and deployment;

  • operations and maintenance/sustainment;

  • retirement and disposal.

Lesson Thirteen will therefore complete Domain 3 before moving into Communication and Network Security.

It will cover:

  • system lifecycle concepts;

  • security requirements engineering;

  • stakeholder requirements;

  • functional versus security requirements;

  • security architecture;

  • security requirements traceability;

  • secure acquisition;

  • design reviews;

  • development;

  • implementation;

  • integration;

  • verification;

  • validation;

  • certification and authorization concepts;

  • configuration baselines;

  • secure deployment;

  • operations;

  • maintenance;

  • sustainment;

  • technology refresh;

  • End of Life;

  • End of Support;

  • retirement;

  • data disposition;

  • system disposal;

  • change management;

  • security engineering documentation;

  • original lifecycle diagrams;

  • CISSP scenario questions.

The central Lesson Thirteen question will be:

How should security requirements be defined, engineered, verified, maintained, and ultimately retired throughout the complete information-system lifecycle?


Publication and Independence Notice

This lesson is independently developed educational material for the SierraTec Secure CISSP Certification Preparation Course.

CISSP is administered by ISC2. SierraTec Secure's course is independent certification-preparation material and should not be represented as official ISC2 training unless separately authorized.

The current examination alignment was verified against the ISC2 CISSP Examination Outline. Objective 3.8 requires candidates to apply security principles to site and facility design, while Objective 3.9 includes wiring closets, data centers, media storage, evidence storage, restricted/work areas, utilities/HVAC, environmental threats, fire controls, and redundant/backup power.

Physical-access and environmental-control concepts were supplemented by current NIST guidance addressing physical access, visitor controls, surveillance, environmental monitoring, water damage, fire protection, utilities, temperature, and humidity.

Fire classifications were checked against current OSHA and NFPA material.

The SierraTec Secure PHYSICAL framework, diagrams, comparison tables, scenarios, knowledge checks, and practice questions are original instructional material. They are not actual, recalled, leaked, or official CISSP examination questions.

Sallieu Kanu

Sallieu Kanu

Product Designer
0
Best Seller
Faithful User
Expert Vendor
King Seller

Class Sessions

1- Introduction to CISSP 2- Thinking Like a CISSP: Security Principles, Risk, and Professional Decision-Making 3- Lesson 1 4- Lesson 3 5- Lesson 4: Risk Management, Risk Assessment, and Risk Treatment 6- Lesson 5: Threat Modeling, Supply-Chain Risk, and Third-Party Risk 7- Lesson 6: Legal, Regulatory, Privacy, Compliance, and Investigation Foundations 8- Lesson 7: Asset Security and Information Lifecycle Management 9- Lesson 8: Security Architecture Foundations and Protection Mechanisms 10- Lesson 9: Security Models, Trusted Systems, and Secure Design 11- Lesson 10: Cryptography and Cryptographic Solutions 12- Lesson 11: Cryptographic Attacks and Public Key Infrastructure 13- Lesson 12: Physical and Facility Security Architecture 14- Lesson 13: Information System Lifecycle and Secure Engineering 15- Lesson 14: Communication and Network Security Foundations 16- Lesson 15: Secure Network Components and Infrastructure Protection 17- Lesson 16: Secure Communication Channels, Remote Access, and Third-Party Connectivity 18- Lesson 17: Identity and Access Management Foundations 19- Lesson 18: Authentication Systems, Federation, SSO, and Identity Protocols 20- Lesson 19: Authorization Models and Access-Control Enforcement 21- Lesson 20: Identity Provisioning, Access Reviews, Privileged Access, and Account Lifecycle 22- Lesson 21: Security Assessment and Testing Foundations 23- Lesson 22: Advanced Security Control Testing and Vulnerability Management 24- Lesson 23: Security Metrics, Test Analysis, Reporting, and Audit Assurance 25- Lesson 24: Security Operations, Investigations, Evidence, and Logging Foundations 26- Lesson 25: Configuration Management, Resource Protection, Patch Management, and Change Control 27- Lesson 26: Incident Management and Operational Detection and Prevention 28- Lesson 27: Backup, Recovery Strategies, Disaster Recovery, and Business Continuity Operations

Join Us Today

We'll send the best deals and offers to your email. No spam, ever.

GDPR

When you visit any of our websites, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and manage your preferences. Please note, that blocking some types of cookies may impact your experience of the site and the services we are able to offer.