Physical Security Assessment
In today’s environment, analysis of the physical security of facilities and properties has become an even more critical aspect of an organisation’s information security and business continuity planning. We address this requirement with a team of skilled experts who are able to blend their experience and expertise to focus on the critical aspects of physical security that impact an organisation’s computing environment.
During an onsite assessment, our consultants perform physical inspections of facilities and operations. We begins each physical security review by gaining an understanding of the resources being protected and the perceived threat environment. Through interviews and limited reviews of local policies and procedures covering physical security operations, We will gain an understanding of the level of protection desired and needed in a given location. Armed with this understanding, We will then conduct the review of the facility. Key areas assessed include:
Facility Security
- Entry points
- Data centre
- User and sensitive environments
- Access control and monitoring devices
- Guard personnel
- Wiring closets
Internal Company Personnel
- Control and accountability
- Use of equipment
- Security procedure compliance
- Awareness
- Use of break areas and entry points
External Visitor and Contractor Personnel
- Control and accountability
- Use of equipment
- Security procedure compliance
- Use of break areas and entry points
Computer Systems and Equipment
- Workstations
- Servers
- Backup media
- PDAs
- Modems and physical access points (visual ID only)
Sensitive Information and Data
- Control
- Storage
- Destruction
GNS does not conduct sweeps of the electronic spectrum to identify and isolate covert listening or transmission devices. We have relationships with several highly reputable firms that can provide this specialised service if requested.
Through these highly reputable firms, we can expand on our overt assessment process through the use of covert red-team assessment techniques. These efforts include tactics such as social engineering, pretext entry, security systems bypass, device/Trojan planting, long range surveillance and other methods. Covert assessment is a secondary add-on package.
GNS’s physical security reviews are performed and analysed in the context of your organisation’s overall risk management strategy. The criticality of assets within the environment and the perceived threat environment directly affect the level of exposure that is classified as acceptable. By analysing the combined factors of assets, threat, and exposure, our physical security review provides much more than a list of actionable security recommendations. We prioritise exposures and make recommendations to align physical security with your overall risk management strategy. This holistic view enables you to protect the right assets with the right level of security.
|