๐Ÿ  Back to Exam Syllabus ๐Ÿ“บ RooCloud on YouTube ๐ŸŽฏ Free CISSP Practice Test

CISSP 10.2 - Implement Site & Facility Security Controls (Part 1 of 4)

This episode of the ISC2 Certified Information Systems Security Professional (CISSP) exam prep series starts turning facility design into working controls, continuing Domain 3 โ€” the mix of policy, technology, and physical barriers you specify, buy, and audit so access stays controlled without grinding daily work to a halt.

What this episode covers

Watch the full episode above for the worked examples and detailed explanations of each concept.

Frequently Asked Questions

What order should physical controls act in when someone tries to break in?

The functional sequence is deter, deny, detect, delay, determine, and decide. First you deter with visible boundaries, then deny direct access with barriers like a locked vault door, detect the intrusion with sensors, and delay the intruder long enough for help to arrive, perhaps with a cable lock tethering the asset. Finally, staff determine what is actually happening and decide how to respond, whether that means detaining the intruder or preserving evidence.

How do you plan for equipment that will eventually fail?

Match your preparation to how critical the asset is: knowing where to buy a replacement may suffice for low-stakes gear, while critical systems justify on-site spares or a service-level agreement that pins down vendor response times. Plan around three lifetime numbers โ€” mean time to failure, mean time to repair, and mean time between failures โ€” and always have a backup unit ready, because waiting for total failure before replacing anything is unacceptable.

Why does the wiring closet deserve serious protection?

Because it is the nervous system of the buildingโ€™s network, part of the cable plant that runs from the entrance facility through the equipment room, backbone, and horizontal runs. A protected distribution system guards the cables with sealed conduits, tamper-evident connections, and regular inspections. An intruder who reaches a closet could steal gear, cut lines, or plant a listening device, so lock it tight, never treat it as a storage room, log every entry, and restrict keys to the administrator.

What makes a server room different from an ordinary room?

It is built for the equipment, not for people โ€” a restricted, enclosed space, often run lights-out and kept cool, sometimes with gas-based fire suppression and fire-rated walls. Place it at the core of the building, avoiding the ground floor, top floor, basement, and anywhere near water, gas, or sewage lines. Whether you run your own room or lease colocation or cloud space, physical access is managed with layered technical controls, from smart cards and proximity readers to biometrics.

How do proximity devices decide who gets in?

The device is worn or carried, and when it passes a reader, the reader confirms identity and access rights. A passive device has no electronics, just a small magnet that alters the readerโ€™s electromagnetic field; a field-powered device draws its power from that field, like the everyday card you wave at a door; and a transponder is self-powered and actively transmits, like a garage remote or key fob. Automatic request to exit uses motion sensors or pressure mats to unlock a door as someone approaches from inside.

๐Ÿ“š Master the ISC2 CISSP Exam!

Reinforce this lesson with real practice. The RooCloud CISSP Practice Pack gives you 6,000+ exam-style questions, 366 section-wise practice tests and 40 full-length adaptive (CAT) tests across all 8 CISSP domains, with full explanations. Start with a FREE full-length adaptive CISSP test โ†’


Reference: This article is based on concepts discussed in CISSP 10.2 - Implement Site & Facility Security Controls (Part 1 of 4).