| ๐ Back to Exam Syllabus | ๐บ RooCloud on YouTube | ๐ฏ Free CISSP Practice Test |
CISSP 10.1 - Apply Security Principles to Site & Facility Design
This episode of the ISC2 Certified Information Systems Security Professional (CISSP) exam prep series opens the physical security chapter of Domain 3, grounding every other control in the building itself โ from the choices made in walls, doors, and grounds to the way a thoughtfully shaped space can quietly steer how people behave inside it.
What this episode covers
- Why physical control comes first โ reaching the equipment beats even strong logical controls, so it underpins everything.
- The secure facility plan โ built from a risk assessment plus critical path analysis of every mission dependency.
- Technology convergence โ merged systems save money but create single points of failure and richer targets.
- Layered defense โ overlapping barriers in series that buy time and raise the odds of detection.
- Site selection โ security needs before cost, size, and location, with industrial camouflage as an option.
- Facility design and life safety โ protecting human life above all, judging walls, doors, floors, and utilities by risk.
- Environmental design (CPTED) โ first-generation principles for the physical space, plus second-generation social additions.
Watch the full episode above for the worked examples and detailed explanations of each concept.
Frequently Asked Questions
Why does physical control come before every other kind of security?
Because it sits underneath all of them. If an attacker can physically reach your equipment, they can destroy it, read it, or quietly alter it, no matter how strong your logical controls are. All the encryption in the world means nothing once someone is standing at the rack, so physical protection is the foundation the rest of your program stands on.
What goes into a secure facility plan?
It is a written map of what you must protect and how you intend to do it, built from two inputs. A risk assessment names your assets, threats, and weak spots, and critical path analysis traces every dependency that keeps the mission running โ like an online storeโs chain of internet links, servers, power, cooling, and storage โ so no hidden dependency surprises you later.
How does layered defense shape the entire design?
A secure facility is built on overlapping layers positioned in series rather than side by side, so an intruder has to defeat one barrier, then another, then another, like a medieval keep with an outer wall, a moat, and an inner wall before the treasure room. Each layer buys you time and raises the odds of detection, which is why security staff belong in the design conversation from the start.
What should drive where you put the facility?
Security needs come first, ahead of cost, size, and even location. Look hard at your neighbors, check proximity to emergency responders, confirm the structure can withstand local extreme weather and resist forced entry, and study every window, door, and hiding spot. Industrial camouflage can also hide a facilityโs true purpose behind a convincing front, so a data center might wear the face of a plain food-packing plant.
How can the environment itself quietly steer behavior?
Through crime prevention through environmental design: shape a space thoughtfully, and people behave differently inside it, so crime and even the fear of crime drop. Small moves reinforce this, like short planters that cannot be hidden behind, cameras mounted in plain view, few and well-watched entrances, and a data center placed at the buildingโs core. None of it replaces real hardening โ you still need locks, guards, fences, and bollards alongside good design.
๐ Master the ISC2 CISSP Exam!
Reinforce this lesson with real practice. The RooCloud CISSP Practice Pack gives you 6,000+ exam-style questions, 366 section-wise practice tests and 40 full-length adaptive (CAT) tests across all 8 CISSP domains, with full explanations. Start with a FREE full-length adaptive CISSP test โ
Reference: This article is based on concepts discussed in CISSP 10.1 - Apply Security Principles to Site & Facility Design.