Skip to main content

Unit 2 · Topic 2.3

2.3 Protecting Physical Spaces

Once you know where a building is weak, you choose controls to fix it. This topic covers the managerial controls (training and workstation rules) and the physical and technical controls (fences, locks, card readers, vestibules, disabled USB ports, backup power) used to secure spaces, and how organizations decide which to pay for first.

Key terms

  • security awareness training
  • clean desk policy
  • privacy screen
  • uninterruptible power supply (UPS)
  • access control vestibule
  • bollard

Managerial controls: training and workstation rules

Security awareness training teaches employees how they help protect the organization, including how to spot social engineering like phishing, why they should never badge someone else into a restricted area, and how to prevent device theft.

A workstation security policy spells out how to protect a physical workspace. It can have tiers, with stricter rules for desks that handle more sensitive data. Typical requirements:

  • Lock your device before stepping away, so no one can use it while you're gone.
  • Clear sensitive papers off your desk before leaving it (a clean desk policy).
  • Use a privacy screen filter or other barrier so people nearby can't read your screen.
  • Plug devices into a surge protector or an uninterruptible power supply (UPS).

Physical and technical controls

To pick a control, think like the adversary: how would they use this weakness, and how could you prevent, detect or correct that attack? Common choices:

  • Fences, gates and bollards (short, sturdy posts that stop vehicles) around a building discourage people from trying to get close.
  • Locks on doors, server cabinets and computers keep devices from being accessed or carried off.
  • Card readers deny unauthorized badges and record which badge opened which door, and when.
  • Access control vestibules (two doors with a small space between, where the second won't open until the first closes) and turnstiles let only one person through at a time. They stop an employee from letting someone in on purpose or by accident.
  • Disabling USB ports, usually done in a computer's settings, keeps an external drive from loading malware.
  • A UPS is a battery that keeps a device running through a power outage. Generators provide backup power on a larger scale, for a whole building or a set of critical devices.

Deciding what to fix first

No organization can afford every control at once. They prioritize by comparing how severe each risk is with what the fix costs. Severe risks with cheap fixes go to the top of the list. A control is cost-effective when it costs less to install and maintain than the loss it's expected to prevent.

Match the control to the attack. A vestibule is great against piggybacking and tailgating but does nothing about a power outage; a UPS handles outages but not intruders. That's defense in depth in a building: several different controls, each covering a different threat.

Worked examples

Try each one yourself first, then open the solution.

  1. Example 1

    Matching controls to weaknesses

    At Riverside Robotics, (1) an assessor watched an employee hold the lab door for a stranger carrying boxes; (2) the receptionist's unlocked computer is left on while she's at lunch; (3) a brief power flicker last month crashed the server that runs the lab's 3D printers. Recommend one control for each and say whether it is physical, technical or managerial.

    Show the solution
    1. Step 1: (1) The attack is piggybacking. An access control vestibule or turnstile physically allows one person per badge (physical). Security awareness training on not letting others in also helps (managerial).
    2. Step 2: (2) The weakness is an unattended, unlocked device. A workstation policy requiring staff to lock screens before leaving fixes the behavior (managerial). An automatic screen lock after a few idle minutes backs it up (technical).
    3. Step 3: (3) The problem is availability during power loss. A UPS keeps the server running through flickers and short outages (physical).

    Answer: (1) Access control vestibule (physical), plus training (managerial). (2) Workstation policy requiring screen locks (managerial), backed by an auto-lock setting (technical). (3) UPS for the server (physical).

  2. Example 2

    Prioritizing with cost

    A clinic estimates these yearly figures. Risk A, a patient-record server in an unlocked room: expected loss $60,000 a year; a lock and card reader cost about $1,500 a year to install and maintain. Risk B, a lobby TV that visitors could unplug: expected loss $200 a year; a locked enclosure costs about $400 a year to install and maintain. Which risk should the clinic address first, and is each control cost-effective?

    Show the solution
    1. Step 1: Compare each control's yearly cost with the yearly loss it prevents. For A: $1,500 is far less than $60,000, so the lock and card reader are cost-effective.
    2. Step 2: For B: $400 a year is more than the $200 a year it protects, so the enclosure costs more than the loss it prevents. It isn't cost-effective.
    3. Step 3: Prioritize by severity and cost: Risk A is far more severe and cheap to fix, so it goes first. For Risk B, accepting the small residual risk is a reasonable choice.

    Answer: Fix Risk A first: the $1,500-a-year control protects against a $60,000-a-year loss, so it's cost-effective. The enclosure for Risk B costs $400 a year to prevent a $200-a-year loss, so it isn't cost-effective, and the clinic can reasonably accept that risk.

Common mistakes

  • Recommending a control that doesn't match the attack, like cameras to stop power outages. Name the attack first, then pick the control that blocks it.
  • Calling a workstation policy a technical control. A policy is a rule people follow, so it's managerial, even when a technical setting enforces it.
  • Thinking a card reader only blocks people. It also creates a record of which badge opened which door and when, which matters for detection.
  • Ignoring cost. On the exam, "the best recommendation" often means the one that handles a severe risk at a reasonable cost.

On the exam

  • You'll often be asked to recommend a control for a described weakness. A full answer names the control, says how it stops the specific attack, and, if asked, gives its category.
  • If a question asks which risk to address first, compare severity and cost: the severe risk with an affordable fix usually wins.

Connected topics

Videos

  • AP Cybersecurity Topic 2.3. - Protecting Physical Spaces - Explanations and MCQs!

    Dr_WuWatch on YouTube (opens in a new tab)

  • Physical Security - CompTIA SY0-701 Security+ - 1.2

    Professor MesserWatch on YouTube (opens in a new tab)

  • What is a UPS? (Uninterruptible Power Supply)

    RealParsWatch on YouTube (opens in a new tab)

  • User Training - CompTIA Security+ SY0-701 - 5.6

    Professor MesserWatch on YouTube (opens in a new tab)

  • Physical Security Part 1: Intro and Site Barriers

    Tom OlzakWatch on YouTube (opens in a new tab)

Check yourself: 2.3 Protecting Physical Spaces

4 questions on 2.3 Protecting Physical Spaces. Pick an answer to see if you got it, and why.

Excerpt from the workstation security policy of Brightwater Insurance, an invented company:

Rule 1: Employees must lock their computers before leaving them unattended.

Rule 2: Printed documents with customer information must be cleared from desks and locked away whenever the desk is unattended.

Rule 3: Workstations that display customer financial data must use a privacy screen filter.

Rule 4: All workstations must be connected to a surge protector or an uninterruptible power supply (UPS).

Invented policy excerpt

Question 1 of 4

Which attack does Rule 3 most directly defend against?

Question 2 of 4

Rule 2 is often called what?

Question 3 of 4

What is the main purpose of Rule 4?

Question 4 of 4

Which topic belongs in employee security awareness training about physical security?

0 of 4 answered