Protect entry points using appropriate physical controls that mitigate the risk of unauthorised access to secure areas where you are processing personal and special category information.
Options to consider:
- Identify and risk assess areas that may require an increased level of security.
- Regularly test physical controls to gain assurances of their effectiveness.
- Ensure entry points include a mixture of controls to maximise security (eg perimeter security and electronic access control systems).
- Keep a record of the physical access rights assigned to staff.
- Monitor the granting of visitor and guest access.
- Include the removal of physical access rights in the leavers’ checklist.
- Audit the record of physical access rights to ensure you revoke access when you should.
Implement controls to protect against external threats in secure areas, such as server rooms.
Options to consider:
- Conduct risk assessments of secure areas and the equipment in them.
- Implement controls such as fire detection and suppression systems, humidity sensors and physical access detection systems.
- Maintain a log of all attempts to access secure areas to assess whether they are authorised.
- Use additional electronic controls in secure areas, such as CCTV.