To safeguard information and associated assets, organizations should establish and utilize physical security perimeters for information processing facilities. They serve to prevent unauthorized physical entry and protect against potential damage or interference to the organization's valuable assets. External structures like roofs, walls, ceilings, and flooring should be sturdy, and external doors should be secured with control mechanisms such as bars, alarms, and locks.
Secure areas of the organization cannot be accessed unnoticed. The premises are protected by appropriate access control. Only authorized persons have access to the secure areas.
Organisation's premises and the operating environments of the equipment are actively protected by security.
Access to areas where confidential information is handled or stored should be restricted to authorized individuals through appropriate access control, e.g. using a two-step authentication mechanism such as an access card and a passcode.
Security personnel use camera surveillance to verify unauthorized access, sabotage, or other alarms at the organization's premises.