ISO 27001 Physical Security: What It Means For Your Data Centre Security


Handling sensitive data means complying with ISO 27001. But that doesn’t just cover cyber security and data protection. It also means hitting physical security requirements. You have to show your buildings, server rooms and storage areas meet these standards.

If you’ve ever tried to read the physical security guidance in ISO 27001 you might have come out more confused than when you started because it can sound complicated. It’s not really. The controls themselves are simple to deploy and manage:

  • Fences
  • Security doors
  • Locks
  • Entry and exit logs
  • CCTV monitoring
  • Alarm response

The challenge is finding the right data centre security provider who can deliver everything you need in a way that auditors accept.

 

Where Physical Security Fits In ISO 27001

 

ISO 27001 certifies a management system rather than a building. So its standard will never give you specific details for your security (like how high a perimeter fence needs to be, or what level of manned guarding you need). Annex A gives you 93 controls to look at to deal with risks you could find (we won’t be going through all 93 in this article). And you don’t necessarily need to hit them all. Instead, you assess your risk – or get a security company to run a security risk assessment for you – and decide which security measures you need. For a data centre, this will mean a range of physical security measures alongside cyber security because you have to manage physical access to your perimeter, buildings and individual server rooms.

 

The Main Data Centre Physical Controls You Need To Consider Under ISO 27001

 

7.1 Physical Security Perimeters

You need to define your boundaries (internal and external) for the areas holding sensitive data and protect them from intrusion.

7.2 Physical Entry

This is about controlling who can enter your boundaries using measures like access control systems (manned and digital), concierge security at reception (or a range of both).

7.3 Securing Offices, Rooms and Facilities

Design and apply security to the individual areas within your perimeter as an inner layer of security. This could be biometric access control for areas housing sensitive data.

7.4 Physical Security Monitoring

Put measures in place to continuously monitor for unauthorised access through 24/7 mobile patrols or static officers, or a technology security approach with CCTV monitoring.

7.5 Protecting Against Physical and Environmental Threats

Fire, flood, storms and deliberate damage can all compromise data inside your data centre so you have to show evidence that you’re protecting against it.

7.6 Working in Secure Areas

Are you setting rules for what people can do once they go into restricted areas? This could include not using phones or taking pictures. And how are you monitoring for compliance?

7.7 Clear Desk and Clear Screen

Are you enforcing policies to ensure nothing sensitive is left on desks or is showing on screens that can be seen by people without permission to see it and, again, what measures are in place to enforce it.

7.8 Equipment Position and Protection

Is equipment or hardware that houses sensitive data stored away securely where it can’t be reached or damaged?

7.9 Security of Assets Off Site

Laptops left in cars, equipment taken home or equipment left at client sites. You have to consider what security will be put in place to either stop equipment being taken off site, or have strict rules for keeping it safe once it has been.

7.10 Storage Media

How you handle, move or destroy anything that stores data.

7.11 Supporting Utilities

Do you have redundancies in place to handle failures in power, water or cooling, whether that’s remote monitoring, physical security or a smart system for alarms.

7.12 Cabling Security

Are you protecting power and data cabling from interception or damage? Whether that’s mobile patrols, canine security or alarm response or CCTV monitoring that oversees the areas where cables are located.

7.13 Equipment Maintenance

Is equipment being properly maintained and kept secure. You also have to consider the possibility that maintenance presents a security risk and have manned security or concierge guarding who ensure only authorised personnel get into your data centre and prevent risks like tailgating.

7.14 Secure Disposal or Re-use of Equipment

Do you have physical processes in place to make sure nothing leaves your building with data on it when it shouldn’t and that disposals or redeployment of equipment is handled properly.

 

What Your Security Provider Can Do, What Stays With You?

 

Of the physical security requirements you need to consider for your data centre, some can be outsourced to a professional security services company, and should be to ensure you’re delivering them to the highest standards with an accredited partner.

A provider like ProFM can cover you for areas like 7.1, 7.2, 7.3 and 7.4, which covers your perimeter security measures, access control, protecting internal areas and CCTV installation and monitoring for external and internal areas.

Realistically we’d recommend looking for a single provider that covers everything, because while the measures aren’t complicated, trying to manage multiple contractors across every security type is going to get messy.

This means a provider who can advise on:

  • Perimeter security, video, gates and barriers (and provide gatehouse security and mobile CCTV towers to cover them over a large footprint)
  • Access controls
  • Concierge reception security
  • Manned guarding where you need a physical deterrent – around cabling or remote areas continuously monitored CCTV and alarm response

 

Dealing With Physical Security Monitoring For Data Centres

 

Annex 7.4 requires your data centre to be monitored continuously for unauthorised physical access. This is a new addition to the regulations, added in 2022 to update the previous requirements first written in 2013. From a purely practical standpoint, this is going to mean a mix of manned security (a combination of static and mobile guarding) along with CCTV monitoring.

At ProFM all our CCTV installations include 24/7 monitoring from our National Operations Centre, which is manned and monitored at all times by SIA Licensed Officers. These officers are trained to identify suspicious behaviour and escalate a response, either by sending security guards to assess the situation, or escalating to the emergency services when the incident merits it.

Alongside this, alarm response ensures you have a physical response to any incident. Our average response time to incidents across all our contracts is just 30 minutes, so you can be sure to have a guard on site quickly. This covers you from an auditing standpoint, because what they’ll ask is how would an unauthorised entry be detected and what would your response be.

With ProFM you can answer this confidently because you’ll have:

  • A monitored CCTV feed
  • Real time detection
  • A defined response
  • An auditable record of the incident and the steps taken to mitigate the risks

As part of your security assessment we’ll take a detailed site risk audit and recommend the right level of monitored and manned security to cover you from threats, which will also satisfy any audits.

 

Dealing With Higher Risk Areas

 

For physical security in a data centre, server rooms, comms rooms and records stores carry much higher expectations for your physical security. Access needs to be strictly zoned so it’s layered from the boundary to the final destination. No one, under any circumstances, should be able to get from outside to any of these locations in one step. For your security this means a thorough assessment of the areas people go through to get to sensitive areas and could mean access control, CCTV and door security throughout your data centre.

Meet Me Rooms (MMRs) are an area you need to particularly pay attention to. These are the areas where visitors can become an uncontrolled risk when your security slips if they’re left alone.

We won’t go into it too much here because we’ve already written about the physical security standards for data centres, covering NPSA and NCSC guidance, perimeters and data halls in quite a lot of detail. Where we see the biggest security gaps in many facilities is access to the server rooms. In some cases these rooms are (rightly) classified as high risk, then protected with a keypad access control system that a cleaner still knows the code for after leaving because it’s not been changed for five years.

This is where advanced security like biometric access control and AI assisted CCTV (which can flag suspicious activity) should play a bigger role in modern data centre security and definitely as part of ISO 27001 requirements.

 

What To Ask Your Security Provider

 

Choosing your security provider for physical security in your data centre is one of the biggest decisions you’ll make. These are some of the key questions we’d recommend you ask when assessing any potential provider.

Is our CCTV monitored or just recorded?

If it’s monitored, who’s monitoring it, where from, at what times and what happens if an incident happens?

What happens when an alarm goes off out of regular hours?

You should have a named respondent along with a complete log of the response time and the patrol. We can install RFID tagging onsite that officers to need to swipe into as proof they attended.

How are security officers vetted?

For most ISO 27001 work, SIA licensing and BS7858 screening is the minimal you should expect. All manned security guarding should be delivered through an accredited contract.

Will you supply records to an auditor?

This is important as proof you’re taking the relevant steps to protect your data centre from physical threats. We provide transparent, auditable, reports of all our call outs and security services so you’re covered.

 

Audit-Ready Physical Security Monitoring With ProFM Group

 

Failure in ISO 27001 compliance doesn’t typically fall on hardware, it often comes down to the security personnel who make sure the processes and technology work as it should. That’s where ProFM Group excel. Our National Operations Centre monitors CCTV feeds and alarm activations round the clock, with a set and agreed response for incidents, plus a record of every activation on your site.

Our officers are SIA licensed and BS7858 screened and electronic security is delivered to NSI Gold standard. If you want to know more about our data centre security services, get in touch for a free assessment.