Data Centre Security Checklist
Auditors, insurers and businesses storing data on your servers all ask the same thing from a facility, that you have evidence that your physical security works as it should.
We’ve written about the standards of physical security in data centres, but this should serve as a quick checklist that you can use to assess any data centre facility from a physical security standpoint.
Physical Security Checklist For A Data Centre
Physical security for a data centre works in layers (as we’ve talked about in our blog on data centre physical access controls). Your perimeter security controls who gets through the gate and delays intruders.
Building entry points enforce stricter access control and provide extra delays against intrusion if guards need to escalate an incident or ask for a security response. But all the hardware and security systems only work when you have experienced security guards in place who make sure everything is working as it should and can respond when things go wrong.
Perimeter Security & Approach Routes
Your first line of defence is the perimeter. But it’s also one of the more neglected areas of your security outside of installing fencing.
Security technology is essential for securing the perimeter of your data centre, whether it’s AI-powered CCTV, intruder alarms and sensors, along with mobile patrols to identify suspicious activity or deter potential threats.
As a minimum, you’ll need:
- A fence line, gates and bollards specified to recognised industry ratings (LPS 1175 for security fencing, PAS 68 or IWA 14 for vehicle barriers).
- Routes designed to slow vehicles down before they reach a gatehouse.
- Lighting that removes shadows along your fence line or entry points that can be used as cover.
- Intrusion detection monitored 24/7 by a staffed control room (which we offer through our National Operations Centre)
Entry Points & Access Control
Every door, gate, loading bay, plant room or even roof hatch is a potential entry point for criminals. Access control needs to be tightly managed for role-based access, short-term access for contractors and every approved access logged.
This should also take into account surveillance of people in your facility once they’ve been granted access.
- Access cards issued by role, with any rights reviewed regularly to make sure entry can be revoked as needed.
- Biometric scanning for a multi-factor authentication system for areas housing critical data.
- Anti-tailgating at your main entrance, like security portals or mantraps.
- Any visitor or contractor entry approved in advance, logged and limited to specific zones.
- Temporary contractor access granted as needed, but managed with expiry dates and always requiring an escort once inside.
- All deliveries authorised, logged and received by specific people with access limited to loading bays.
Data Halls & Restricted Access
Data centre security often assumes anyone who gets past a certain barrier is authorised to be there and can be trusted. That’s not always the case and critical areas need to be highly restricted. This is particularly true in multi-tenant sites, where you can’t have one engineer being able to get near a rack that isn’t theirs.
- Zone segmentation between reception, corridors, plant rooms and data halls
- Rack-level or cage-level locking and micro segmentation in shared environments
- Escorted access for anyone granted temporary access
- Separate authorisation for Meet Me Rooms and cross-connect areas
CCTV Coverage, Monitoring & Video Retention
One of the more overlooked aspects of surveillance in data centre CCTV systems is whether the system has continuous monitoring, or is just recording video that can be used as evidence after the fact.
Our CCTV installation and monitoring packages come as standard with 24/7 oversight from our National Operations Centre, with SIA licensed security guards keeping watch at all times and able to react instantly to suspicious behaviour or a live security event.
- Coverage across entry points, loading bays, plant rooms and aisles in data halls
- A standard time period to retain video or images (90 days, for example)
- A set process for who can release footage
- Confirmation whether cameras are actively watched at all times (including out of hours)
Security Personnel & On Site Response
Ultimately, any security systems are only going to work properly with the right people and security provider behind them who can deter incidents and respond quickly when something happens. We’re known for the quality of our manned guarding and this is something we already work with live data centres on.
- SIA licensed security guards on site with hours and shift patterns designed to match your requirements
- BS7858 vetting on all personnel and SC clearance where your site carries Government data
- Documented patrol schedules, covering your entire perimeter and critical areas (we include RFID tags so you can see when patrols have logged in to specific areas)
- Key holding and alarm response so you have SIA-licensed security officers responding to incidents at any time of the day or night
- Escalation procedures in the event of a critical incident or attempted breach, including escalation to the emergency services
Verified Data Centre Security Measures With ProFM Group
ProFM Group is the security partner for major UK data facilities, including TATA Communications, covering 12,000 square metres and NTT data centre at Hemel Hempstead. Our officers are SIA licensed and BS7858 vetted alongside right-to-work checks, with additional clearances – like SC clearance – available as needed.
All CCTV work is NSI Gold standard approved while our National Operations Centre watches CCTV systems, raises alarms and coordinates manned guarding contracts around the clock so you’re always fully supported.
If you want to know more about our data centre security services, get in touch for an initial call and site risk assessment.