The organization has defined different levels of areas required for the physical protection of confidential information (administrative area, security area, and technical security area). A designated responsible person ensures that the protective practices corresponding to each protection level are applied in these areas.
An area may include, for example, a room, equipment room, storage, archive, a combination of such spaces, or another part of a building. Buildings and premises may contain several areas belonging to different security zones.
Information of protection levels IV–II may be processed in a security area. Such information may also be processed in an administrative area, provided that unauthorized access is prevented. Information of protection level IV may be stored in an administrative area, while information of protection levels III–II must be stored in a security area.