Physical Security for IT

Erbschloe, Michael

In stock
Regular price 27.000 KD inc. VAT
License
Table of contents
  • Cover
  • Copyright Pageiv
  • Contentsvii
  • Prefacexiii
  • Acknowledgementsxv
  • Introductionxvii
  • Chapter 1. Physical Security Overview1
  • 1.1 Why Physical Security Is Important2
  • 1.2 The Relationship Between Physical and Cyber Security3
  • 1.3 Guard Against Disgruntled Employees and Angry Former Employees4
  • 1.4 How Activists and Corporate Foes Can Hurt You5
  • 1.5 Vandals Who Damage for Fun6
  • 1.6 Saboteurs Who Work for Profit7
  • 1.7 Thieves and Spies Are Everywhere9
  • 1.8 Domestic Terrorists Are Still a Threat10
  • 1.9 International Terrorist Are a Growing Threat12
  • 1.10 Physical Security for Natural Disasters14
  • 1.11 Physical Security for Random Incidents15
  • 1.12 Action Steps to Improve Physical IT Security16
  • Chapter 2. Establishing a Physical IT Security Function19
  • 2.1 Organizational Placement of the IT Physical Security Function20
  • 2.2 Interdepartmental Relationships for Physical Security22
  • 2.3 Evaluating Financial Resources23
  • 2.4 The Role of Corporate24
  • 2.5 The Role of IT Security25
  • 2.6 The Role of Network Security26
  • 2.7 Relationships with Law Enforcement27
  • 2.8 Relationships with Private Security Providers29
  • 2.9 Establishing and Utilizing an Alert System30
  • 2.10 Action Steps to Improve Physical IT Security32
  • Chapter 3. Developing an IT Physical Security Plan35
  • 3.1 Overview of the Planning Process36
  • 3.2 Developing the IT Physical Security Plan38
  • 3.3 Utilizing Existing Risk Exposure Analysis39
  • 3.4 Integrating Physical IT Security and Cyber Security Planning40
  • 3.5 Integrating Physical IT Security and Disaster Recovery Planning41
  • 3.6 Integrating Physical IT Security and Business Continuity Planning42
  • 3.7 Working with Your Insurance Company43
  • 3.8 Evaluating Regulatory Requirements44
  • 3.9 Action Steps to Improve Physical IT Security48
  • Chapter 4. Major Elements of a Physical IT Security Plan51
  • 4.1 Overview and Mission Statement54
  • 4.2 Organizational Responsibilities54
  • 4.3 Duty Officers55
  • 4.4 Contact Lists56
  • 4.5 Security Procedures for Data Centers56
  • 4.6 Security Procedures for Wiring and Cabling58
  • 4.7 Security Procedures for Remote Computers59
  • 4.8 Security Procedures for Desktops60
  • 4.9 Security Procedures for Department-Based Servers61
  • 4.10 Security Procedures for Telecom and Datacom Equipment62
  • 4.11 Security Procedures for Manufacturing Control Equipment63
  • 4.12 Security Procedures for Surveillance and Alarm Systems64
  • 4.13 Action Steps to Improve Physical IT Security65
  • Chapter 5. Developing and Documenting Methods and Procedures67
  • 5.1 The Process of Developing Methods and Procedures68
  • 5.2 Devising a Format for Documenting Procedures69
  • 5.3 Physical Security Procedures for Data Centers70
  • 5.4 Physical Security Procedures for Wiring and Cabling71
  • 5.5 Physical Security Procedures for Remote Computers72
  • 5.6 Physical Security Procedures for Desktops72
  • 5.7 Physical Security Procedures for Department-Based Servers73
  • 5.8 Physical Security Procedures for Telecom and Datacom Equipment74
  • 5.9 Physical Security Procedures for Manufacturing Control Equipment75
  • 5.10 Physical Security Procedures for Surveillance and Alarm Systems76
  • 5.11 Action Steps to Improve Physical IT Security77
  • Chapter 6. Auditing and Testing Procedures79
  • 6.1 How to Audit and Test Procedures79
  • 6.2 Auditing and Testing for Data Centers82
  • 6.3 Auditing and Testing Wiring and Cabling Security85
  • 6.4 Auditing and Testing Remote Computer Procedures86
  • 6.5 Auditing and Testing Desktop Procedures87
  • 6.6 Auditing and Testing Procedures for Department-Based Servers88
  • 6.7 Auditing and Testing Telecom and Datacom Equipment Security89
  • 6.8 Auditing and Testing Manufacturing Control Equipment Security90
  • 6.9 Auditing and Testing in Surveillance and Alarm System Security91
  • 6.10 Action Steps to Improve Physical IT Security92
  • Chapter 7. The Role of the Incident Response Team95
  • 7.1 The First Report97
  • 7.2 The Confirmation Process99
  • 7.3 Mobilizing the Response Team99
  • 7.4 Notifying Management100
  • 7.5 Using the Alert System101
  • 7.6 The Preservation of Evidence102
  • 7.7 When to Call Law Enforcement103
  • 7.8 Returning to Normal Operations104
  • 7.9 Analyzing Lessons Learned105
  • 7.10 The Role of the Incident Response Team During Disasters107
  • 7.11 Action Steps to Improve Physical IT Security113
  • Chapter 8. Model Training Program for Organization Staff117
  • 8.1 Training for IT and Security Professionals118
  • 8.2 The Basics of Training119
  • 8.3 Building Awareness About Physical Security for IT Assets120
  • 8.4 How to Identify Potential Threats and Vulnerabilities124
  • 8.5 Reporting Suspicious Behavior or Security Violations135
  • 8.6 What to Expect from Different Departments136
  • 8.7 How the Internal Alert System Works138
  • 8.8 Performing the Administrative Aspects of a Training Program139
  • 8.9 Action Steps to Improve Physical IT Security140
  • Chapter 9. The Future of Physical Security for IT Assets143
  • 9.1 The Impact of National Security Plans144
  • 9.2 The Role of ISACS154
  • 9.3 Action Steps to Improve Physical IT Security168
  • Appendix A. Physical Computer Security Resources169
  • Appendix B. Physical Security Glossary and Acronyms177
  • Appendix C. Action Step Checklists191
  • Appendix D. Physical Security Planning Checklists199
  • Index217
Book details
  • Vendor Elsevier S & T
  • SKU 9781555583279
  • ISBN-13 9780080495903
  • Author Erbschloe, Michael
  • Category Computers
  • Subject Computer Science

Do you have questions about this book?

Ask an expert!

The physical security of IT, network, and telecommunications assets is equally as important as cyber security. We justifiably fear the hacker, the virus writer and the cyber terrorist. But the disgruntled employee, the thief, the vandal, the corporate foe, and yes, the terrorist can easily cripple an organization by doing physical damage to IT assets. In many cases such damage can be far more difficult to recover from than a hack attack or malicious code incident. It does little good to have great computer security if wiring closets are easily accessible or individuals can readily walk into an office and sit down at a computer and gain access to systems and applications.

Even though the skill level required to hack systems and write viruses is becoming widespread, the skill required to wield an ax, hammer, or fire hose and do thousands of dollars in damage is even more common. Although many books cover computer security from one perspective or another, they do not thoroughly address physical security. This book shows organizations how to design and implement physical security plans. It provides practical, easy-to-understand and readily usable advice to help organizations to improve physical security for IT, network, and telecommunications assets.

* Expert advice on identifying physical security needs
* Guidance on how to design and implement security plans to prevent the physical destruction of, or tampering with computers, network equipment, and telecommunications systems
* Explanation of the processes for establishing a physical IT security function
* Step-by-step instructions on how to accomplish physical security objectives
* Illustrations of the major elements of a physical IT security plan
* Specific guidance on how to develop and document physical security methods and procedures