Physical Security for IT

Security needs to be an ongoing concern. You should not fall into complacency once your physical IT security plan and procedures are documented and your employees have been trained. Maintaining security procedures is a constant and continuous process. This process can be simplified by employing three techniques: auditing compliance with procedures; periodically testing procedures and groups of related procedures; and training IT, security staff, department supervisors and managers to embed ongoing monitoring and reporting practices in their daily routines.
The process of developing procedures described in Chapter 5 is designed to help you quickly develop and document a wide variety of physical IT security procedures. However, to ensure that your procedures can be effective over a long period, it is advisable to audit and test those procedures on a regular basis. This process will help you adjust procedures when the physical layout of offices or facilities is modified, when new equipment is installed, or when new and improved security systems are installed. This chapter presents auditing and testing techniques designed to help keep your physical IT procedures current and effective.
There are several steps that should be followed to audit and test physical IT security procedures. The auditing process involves reviewing procedures to ensure that they are current and monitoring compliance with procedures. Neither of these methods is complex. They do, however, require time and attention to detail.
Auditing procedures to make sure they are current primarily involves reviewing and examining procedures to...