Physical and Environmental Controls: How to Audit Them
Locks, fire, water, power and heat. Easy to under-prepare, and still examinable.
Physical controls keep unauthorised people away from IT equipment; environmental controls keep the equipment alive through fire, flood, power cuts and heat. Neither is technical in the way network security is, which is why CAs tend to under-prepare them, and why they remain fair game in the exam.
DISA Module 5 covers both and how to audit them. NIST's Cybersecurity Framework 2.0 states the same outcomes plainly: physical access to assets is managed, monitored and enforced according to risk, assets are protected from environmental threats, and the physical environment is monitored for adverse events.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
Physical Access Controls
Site location and signage
What it does
Server room away from public areas, not on a basement or top floor exposed to flooding or leaks, and not signposted
Audit evidence
Walkthrough, site plan
Access cards or biometrics
What it does
Restrict entry to authorised staff and record each entry
Audit evidence
Access list reviewed against current staff; entry logs
Mantrap
What it does
Two interlocked doors, only one open at a time, to stop tailgating (an unauthorised person following someone in)
Audit evidence
Observation
Visitor management
What it does
Visitors registered, escorted and badged
Audit evidence
Visitor register matched to escort records
CCTV and guards
What it does
Deter and record; footage supports investigations
Audit evidence
Camera coverage, footage retention per policy
Equipment security
What it does
Locked racks, asset tags, controlled removal and disposal of media
Audit evidence
Gate passes, disposal and sanitisation certificates
| Control | What it does | Audit evidence |
|---|---|---|
| Site location and signage | Server room away from public areas, not on a basement or top floor exposed to flooding or leaks, and not signposted | Walkthrough, site plan |
| Access cards or biometrics | Restrict entry to authorised staff and record each entry | Access list reviewed against current staff; entry logs |
| Mantrap | Two interlocked doors, only one open at a time, to stop tailgating (an unauthorised person following someone in) | Observation |
| Visitor management | Visitors registered, escorted and badged | Visitor register matched to escort records |
| CCTV and guards | Deter and record; footage supports investigations | Camera coverage, footage retention per policy |
| Equipment security | Locked racks, asset tags, controlled removal and disposal of media | Gate passes, disposal and sanitisation certificates |
Environmental Controls
- Smoke and heat detectors
- Detect fire early. Detection must be linked to an alarm someone responds to, and tested.
- Wet pipe sprinkler
- Pipes always full of water; fires quickly but risks water damage from a leak or accidental trigger.
- Dry pipe sprinkler
- Pipes hold air until a fire is detected, then fill with water. Lower leakage risk, slightly slower to discharge.
- Pre-action system
- A dry pipe system that needs a detection signal before water enters, plus sprinkler head activation before discharge. Common in data centres.
- Gas-based suppression
- Clean agents that put out fire without water damage to equipment. Halon, the older agent, damages the ozone layer and has been phased out.
- UPS and generator
- The UPS bridges the gap between a power failure and the generator starting; it is not meant to run the site for long.
- HVAC and humidity control
- Heating, ventilation and air-conditioning keep temperature and humidity within the equipment's limits.
- Water leakage detectors
- Sensors under raised floors and near pipes and AC units, raising an alarm before water reaches equipment.
Quick practice on audit concepts. No signup.
How an IS Auditor Audits Them
- 1
Walk the site
Observation is primary evidence here. Note door controls, propped-open doors, combustible material in the server room, and whether the visitor process is actually followed.
- 2
Test access lists
Compare the list of people with server room access to current staff and job roles. Former employees and vendors with active cards are findings.
- 3
Inspect maintenance records
Fire extinguishers, suppression systems, UPS batteries, generators and AC units should have dated service records and test results.
- 4
Check monitoring
Temperature, humidity and leakage alarms should reach someone 24x7, with evidence of response to past alerts.
- 5
Link to continuity
Check that a failure of power, cooling or the site itself is covered by the business continuity and disaster recovery plan.
How the DISA Assessment Test Tests This
Expect short definitional MCQs (which control stops tailgating, which sprinkler type limits accidental water damage) and "best evidence" questions. The answer to "best evidence that physical controls operate" is usually the auditor's own observation and system-generated entry logs, not a policy document or management's representation.
A frequent trap: options that list a UPS as the answer to a prolonged power outage. A UPS covers the switchover; a generator (or a DR site) covers the outage.
FAQs
What is a mantrap in physical security?expand_more
An entry with two interlocked doors where only one can open at a time, so a person can be verified between them. It stops tailgating and piggybacking.
What is the difference between wet pipe and dry pipe sprinklers?expand_more
Wet pipe systems hold water in the pipes at all times; dry pipe systems hold air and fill with water only when triggered, which lowers the risk of leaks damaging equipment.
Why is halon not used in data centres any more?expand_more
Halon damages the ozone layer and has been phased out. Data centres now use other clean-agent gases or water-based systems such as pre-action sprinklers.
What is the best evidence that physical access controls are working?expand_more
Direct observation by the auditor plus system-generated access logs reconciled to an approved access list. Policies show design, not operation.
Next steps
Take a full DISA mock testAssessment Test format, timed and scored.
