Physical security controls protect the tangible assets of an organisation—people, equipment, facilities—from unauthorised access, theft, damage and environmental hazards. Environmental controls ensure that the operating environment—power, temperature, humidity, fire suppression—remains stable so that systems can run safely and reliably. For a CISSP candidate, mastering these is vital because a single unsecured door or a failed cooling unit can bypass the strongest logical controls and cause a catastrophic outage.
Jump to a section
A simple way to picture Physical Security and Environmental Controls
A major international airport is a masterclass in layered physical security and environmental controls. The kerb-side bollards and vehicle checkpoints deter car bombs, just as perimeter fencing and mantraps deter unauthorised entry to a data centre. Inside, passengers must present a boarding pass and passport at check-in—a preventive identification control, much like a badge reader combined with a PIN. The security screening lane adds a detective layer: X-ray machines and metal detectors catch prohibited items, exactly how CCTV and intrusion alarms spot anomalous behaviour. At the boarding gate, the final credential check ensures only the right person boards the right flight, mirroring biometric verification at a server room door.
But the airport also functions as a massive environmental control system. Powerful air-handling units manage temperature, humidity and pressurisation to keep thousands of people comfortable and electronics cool—comparable to the precision HVAC in a server farm. Fire detection loops, smoke management systems and gaseous suppression in equipment rooms protect against fire without soaking the baggage belts, just as pre-action dry-pipe systems shield data racks. Even backup generators and redundant power feeds guarantee that the runway lights and security systems never go dark, just as a UPS and emergency generator keep critical servers running through a blackout. Every element works together so that one failed sensor or open door never compromises the whole operation.
Physical security and environmental controls form the foundation of every security programme. They protect the physical perimeter, the building, the secure areas inside and the equipment itself. Without them, all logical controls—firewalls, encryption, identity management—become irrelevant. An attacker who can simply walk into a server room does not need to hack a firewall.
Physical security controls are typically grouped into types by their purpose. The most common classification includes:
Deterrent controls: These discourage an attacker from even attempting to breach security. Examples are warning signs, well-lit entrances, highly visible security guards and perimeter fencing.
Preventive controls: These physically stop an intrusion before it happens. A locked door, a mantrap (a small interlocking room that only opens the inner door once the outer door has closed and access has been authenticated), a turnstile and a badge reader that enforces access rules are all preventive.
Detective controls: These discover that a breach has occurred or is in progress. Motion detectors, CCTV cameras, glass-break sensors and intrusion alarm systems belong to this group.
Corrective controls: These help you recover from an incident. An example is a fire suppression system that extinguishes a blaze, or a procedure to revoke a lost access badge.
Recovery controls: These restore normal operations after an incident. They include backups, disaster recovery plans and the rebuilding of damaged facilities.
Compensating controls: These fill a gap when the primary control is too expensive or impractical. For instance, if you cannot install a permanent mantrap at a temporary site, a security guard posted at the door acts as a compensating control.
These controls must be applied in layers—a concept known as defence in depth. A typical data centre defence-in-depth physical security strategy looks like this: a perimeter fence or bollards (deterrent), a guard station and vehicle barrier (preventive), access-controlled doors with badge readers and PIN pads (preventive), a mantrap (preventive), biometric authentication at the inner door (preventive/detective), CCTV covering every aisle (detective), and finally environmental sensors and fire suppression (corrective/recovery). If one layer fails, the next is there to stop the attacker.
Environmental controls are just as crucial because IT equipment is sensitive to temperature, humidity, power quality and fire. The key environmental systems include:
Heating, Ventilation and Air Conditioning (HVAC): Servers generate enormous heat. If the temperature in a data centre rises above about 27°C for a prolonged period, hardware can fail. HVAC systems maintain a stable temperature, often between 18°C and 24°C. They also control humidity: too much causes condensation and corrosion; too little increases static electricity, which can damage chips. The ideal relative humidity range is 45–55%.
Fire suppression: In a room full of electronics, water can destroy as much as fire. Therefore, fire protection in data centres typically avoids soaking the equipment. Common systems are:
Wet pipe sprinklers: Always filled with water. They are cheap but deadly for electronics if discharged accidentally. Used in offices, not in data centres.
Dry pipe systems: The pipes are filled with pressurised air. When a sprinkler head opens due to heat, the air is released, water flows in and then out. The delay reduces accidental flooding but still eventually releases water.
Pre-action systems: A dry pipe system with an additional safeguard. Two independent triggers must occur before water enters the pipes: typically a smoke or heat detector alarm and then the opening of a sprinkler. This is the gold standard for data centres because it virtually eliminates accidental discharge.
Gaseous (clean agent) systems: Instead of water, they discharge an inert gas or chemical agent that suppresses fire without leaving residue. Agents like FM-200 (HFC-227ea) or NOVEC 1230 are used in server rooms because they are safe for occupied spaces—unlike CO₂, which depletes oxygen and can kill people.
Power management: IT equipment cannot tolerate sudden power loss or even brief brownouts. An Uninterruptible Power Supply (UPS) provides battery backup for a few minutes until a diesel or natural gas generator can start and take over the load. Power distribution units (PDUs) inside each rack condition the power further. Power arrives from two separate utility feeds if possible, and automatic transfer switches ensure seamless failover.
Water leak detection: Raised floors often hide chilled-water pipes for cooling; a leak can short-circuit entire rows of cabinets. Water detection cables placed under the floor raise an alarm the moment moisture touches them.
Positive air pressure: Data centres often maintain slightly positive air pressure relative to the outside so that when a door opens, clean, conditioned air rushes out rather than dusty, humid air rushing in.
In practice, all these systems must be monitored by a central building management system (BMS) or security operations centre (SOC) that collects alarms, temperature readings and power status. The BMS can be integrated with the logical security infrastructure so that, for example, a fire alarm can trigger an emergency shutdown of all servers after a short delay to avoid data corruption.
Conduct a physical security risk assessment
Identify assets (server rooms, cabling, supply closets), threats (theft, natural disasters, tailgating) and existing controls. This step defines what needs protection and prioritises mitigations, guiding all subsequent design decisions.
Design layered perimeter and building controls
Start from the outer boundary and work inwards: fencing, bollards, vehicle barriers, external lighting, door hardening and alarm contacts. Each layer must be independently effective so that defeating one does not grant access to the next.
Implement access control and visitor management
Deploy badge readers, PIN pads and biometrics at every sensitive entry point. Integrate a mantrap or turnstile to stop piggybacking. Set up a visitor log, temporary badges and escort policy. Ensure roles and permissions match the least-privilege principle so that a marketing badge does not open the server room.
Install environmental monitoring and fire suppression
Place temperature, humidity and water leak sensors under raised floors and in each rack row. Choose an appropriate fire suppression system (pre-action dry-pipe or clean agent). Link all sensors to the building management system with automated alerts so that a spike in humidity or a tiny water leak triggers an immediate response.
Configure power protection and test failover
Install an online UPS with enough battery runtime to bridge the gap until the generator starts. Wire dual power supplies from separate distribution paths. Conduct full-load generator tests monthly and simulate a total utility failure quarterly to verify that automatic transfer switches and cooling systems behave as designed.
Continuously audit, maintain and improve
Review physical access logs regularly, conduct semi-annual red-team walkthroughs, recalibrate biometric sensors, service HVAC and fire suppression systems per manufacturer schedules, and update the physical security plan when the floor layout or equipment changes. This ensures the controls stay effective and compliant over time.
An IT operations manager at a medium-sized financial services company is tasked with securing the new on-premises data centre. The board has approved the budget, but the manager must translate the security framework into a rock-solid physical and environmental design.
The first step is a site survey and physical security risk assessment. The team maps out natural threats (flood zone, seismic activity), neighbourhood crime rates and proximity to fire stations. They then design a layered physical security perimeter. The outer layer is a 2.4-metre welded-mesh fence topped with anti-climb razor wire, complemented by automatic gate controls that require both an access badge and a vehicle registration plate recognition. This provides deterrence and preventive control at the boundary.
At the building entrance, the team installs a full-height turnstile and a mantrap. Every employee must swipe a smart badge and enter a PIN, then stand inside the mantrap until the inner door unlocks after weight sensors confirm a single person is present. This prevents both tailgating (an authorised person holds the door for an unauthorised one) and piggybacking (the unauthorised person slips through behind the authorised one unnoticed). A reception desk with a security guard acts as a compensating detective control for visitors, who are issued temporary badges and escorted at all times.
Inside the server room, a second biometric layer uses iris scanners because the organisation handles payment card data and needs strong multifactor authentication—something you have (badge), something you know (PIN) and something you are (iris pattern). All server racks are locked, and access to each rack is logged by proximity card readers on the cabinet doors. A CCTV system with motion detection and six-month retention covers every aisle, the loading dock and all perimeter doors. Cameras are positioned to avoid blind spots, and the video feed is monitored 24/7 by an external security operations centre that also receives intrusion alarms.
Environmental controls begin with precision cooling. The data centre uses in-row cooling units that blow cold air directly into the cold aisle, sealed with containment panels to prevent hot air recirculation. Temperature sensors placed at the top, middle and bottom of each rack feed into the BMS; if any reading exceeds 26°C, an alert goes to the infrastructure team. Humidity is kept at 50% ±5% using dehumidifiers and humidifiers managed by the HVAC controller.
For fire suppression, the manager selects a pre-action dry-pipe system for the main server rooms and a clean agent NOVEC 1230 gas system for the high-density storage area, because those areas are staffed only occasionally and the gas is safe for occupied spaces. VESDA (Very Early Smoke Detection Apparatus) units sample the air continuously and can detect a smouldering wire insulation before it bursts into flame. A fire pump and a 20,000-litre on-site water tank guarantee supply even if the municipal main fails.
Power resilience is designed with an N+1 configuration: two separate utility feeds enter from different substations, each feeding an automatic transfer switch. A modular online UPS with lithium-ion batteries provides 10 minutes of runtime at full load, which is enough for the standby diesel generator to start and synchronise. The generator is tested under load every month and is fuelled by an underground tank with enough diesel for 48 hours of operation. All power circuits are routed overhead through cable trays to keep them away from any potential water under the raised floor.
Finally, the manager schedules an independent red-team physical penetration test. The testers attempt to bypass the mantrap, walk in without a badge and breach the loading dock. Any gaps found are logged and remediated before the data centre goes live. Once operational, the company institutes a formal audit cycle: quarterly reviews of access logs, annual maintenance on the UPS and generator, and a half-yearly fire system inspection by a certified contractor. This continuous improvement loop keeps the physical and environmental controls effective as threats evolve.
The CISSP exam treats physical security as a domain where practical, common-sense answers beat overly technical solutions. Expect questions that force you to choose between control types and fire system designs, and to prioritise human life safety above all else.
The most tested concepts and patterns include:
The six control categories: you will be given a scenario (a broken CCTV, a guard at a desk) and asked to classify it as deterrent, preventive, detective, corrective, recovery or compensating. The trap is mixing up deterrent (discourages) with preventive (stops). A sign is deterrent; a locked door is preventive.
Tailgating versus piggybacking: know that piggybacking happens with the card holder's consent (they knowingly allow the person through) and tailgating happens without consent (the unauthorised person slips in behind). CISSP wants you to recommend mantrap or turnstile to counter both.
Fire classes and suppression: memorise at least Class A (ordinary combustibles: water), Class B (flammable liquids: foam, CO₂, dry chemical), Class C (energised electrical equipment: non-conductive clean agents or CO₂), Class D (combustible metals: dry powder) and Class K (cooking oils: wet chemical). A common exam question pairs a server room fire (Class C) with water—the wrong answer—because water is conductive and dangerous.
Dry pipe versus pre-action: the CISSP loves this. A dry pipe system releases water when a single sprinkler head opens. A pre-action system needs two triggers before water enters the pipes: typically a smoke/heat detector alarm and then a sprinkler activation. Pre-action is preferred in data centres to avoid accidental water damage. If a question mentions “preventing accidental discharge” or “requires two independent signals”, the answer is pre-action.
Gas suppression and occupied spaces: CO₂ systems extinguish fire by oxygen displacement and can kill people. Clean agents like FM-200 or NOVEC 1230 are safe for occupied rooms. Any question that mentions “occupied data centre” and “oxygen depletion” is testing your understanding that you never choose CO₂ for staffed areas.
Power redundancy: know the difference between off-line (standby) UPS, line-interactive UPS and online double-conversion UPS. Online UPS provides the cleanest power and zero transfer time, which is what a data centre needs. Generators supplement UPS systems but cannot switch on instantly; they take 10–15 seconds to start.
Water detection and positive pressure: these are small but testable details. Water leak detection cables are placed under raised floors to catch chilled-water leaks before they fry equipment. Positive pressure stops dust and contaminants from entering when doors open.
Mantrap design: a mantrap typically allows only one person at a time and uses weight sensors or infrared beams. It is a strong preventive control against unauthorised physical access. Questions may ask what technical control specifically addresses piggybacking, and the answer is a mantrap.
Trap patterns to watch for:
Answers that propose a purely logical control when the question describes a physical gap—the CISSP expects a physical remedy.
Answers that violate the life-safety principle, such as recommending a CO₂ system for a continuously staffed network operations centre. Always choose the option that protects human life first, then the asset.
Confusing corrective and recovery: corrective controls fix the immediate problem (fire suppression stops the fire); recovery controls restore business operations (failover to a hot site).
Assuming that a single high-tech gadget replaces the need for layers: CISSP will mark you wrong if you discard basic deterrents like lighting and fencing.
Memorise these definitions crisply: deterrent discourages, preventive stops, detective notices, corrective eliminates the threat in progress, recovery restores, compensating plugs a gap. If you can slot any given physical control into exactly one of those buckets, you will answer a significant chunk of Domain 8 questions correctly.
Physical security controls must be organised into layers (defence in depth) so that the failure of any single barrier does not compromise the entire facility.
Deterrent controls (signs, lighting, fences) discourage attacks; preventive controls (locks, mantraps, turnstiles) physically stop them.
Pre-action fire suppression systems require two independent triggers before water enters the pipes, making them the safest choice for data centres to avoid accidental water damage.
In occupied spaces, always select a clean agent gas suppression system (FM-200 or NOVEC 1230) rather than CO₂, because CO₂ displaces oxygen and can be lethal to personnel.
Maintaining correct humidity (45–55%) inside a server room is just as critical as temperature control—too low causes static electricity, too high causes condensation and corrosion.
An online double-conversion UPS provides seamless battery power with zero transfer time and is essential for data centre equipment that cannot tolerate even a millisecond of interruption.
Tailgating (without the card holder's consent) and piggybacking (with consent) are both best countered by using a mantrap, which permits only one authenticated person at a time.
These come up on the exam all the time. Here's how to tell them apart.
Dry Pipe Suppression
Water held back by pressurised air; one sprinkler head opening releases water.
Can still accidentally discharge if a sprinkler head is damaged or a false heat trigger occurs.
Faster water delivery than pre-action because no confirmation step is required.
Pre-Action Suppression
Requires two independent triggers (e.g., smoke detector alarm plus sprinkler activation) before water enters pipes.
Virtually eliminates accidental discharge, making it safe for data centres.
Slightly slower to deliver water because the double trigger must be satisfied.
Deterrent Control
Discourages an attacker psychologically, e.g., warning signs, bright lights, visible cameras.
Does not physically block entry; only influences intent.
Often the outermost layer; cheapest to implement.
Preventive Control
Physically stops an action, e.g., locked doors, mantraps, turnstiles.
Directly prevents access even if the attacker is determined.
Typically more expensive and requires ongoing maintenance of mechanical components.
UPS (Uninterruptible Power Supply)
Provides instantaneous battery power the moment mains fails, with no transfer gap.
Runtime is limited to minutes (enough to gracefully shut down or bridge to generator start).
Also conditions power, filtering sags, surges and frequency variations.
Backup Generator
Provides long-duration power (hours to days) by burning fuel, but needs 10–15 seconds to start.
Cannot condition power; only replaces the mains once running.
Must be backed by a UPS so that equipment never sees the outage during the start-up gap.
Mantrap
A small room with interlocking doors that physically traps a person until authenticated.
Stops both tailgating and piggybacking by enforcing single-person passage.
Higher cost and space requirement; often used only at the most sensitive boundaries.
Turnstile
A rotating barrier that permits one person per credential but can be jumped or crawled over.
Prevents casual unauthorised entry but is less robust against determined tailgating.
Lower cost, fits into large reception areas and maintains high throughput.
Tailgating
An unauthorised person follows an authorised person through a secured door without their knowledge.
The badge holder is unaware, so no complicity is involved.
Best countered by turnstiles, optical sensors or a mantrap with presence detection.
Piggybacking
An authorised person knowingly allows an unauthorised person to enter with them.
The badge holder is complicit, whether out of politeness or coercion.
Requires a combination of physical barriers (mantrap) and policy enforcement (sanctions for violation).
Mistake
CCTV cameras are a preventive control because they scare off burglars.
Correct
CCTV cameras are a detective control. They do not physically stop an intrusion; they record evidence for later investigation and may deter only if signs are posted, making the sign deterrent but the camera itself detective.
Beginners often equate ‘seeing something’ with preventing it because popular culture portrays cameras as crime-stoppers. In CISSP classification, a control’s primary function dictates its category, and a camera’s primary job is to detect and document.
Mistake
A server room must be protected by water sprinklers because water puts out any fire quickly and cheaply.
Correct
Water sprinklers can destroy live IT equipment just as thoroughly as a small fire, and water conducts electricity, creating a shock hazard. Data centres instead use pre-action dry-pipe or gaseous clean agent systems that protect hardware while suppressing fire.
Most people think of fire safety in terms of a typical office building, where water is the universal extinguisher. Without exposure to IT infrastructure, the idea that water can be the enemy is counter-intuitive.
Mistake
Installing a mantrap is enough to stop all unauthorised physical access.
Correct
A mantrap is a powerful preventive layer, but it must be part of layered security. A determined attacker can still tailgate an authorised user, a badge can be cloned, or a mantrap can be bypassed through a loading dock. Physical security demands multiple overlapping controls.
There is a natural desire to find a single ‘magic box’ solution. Media depictions of high-security rooms often show a single elaborate door, reinforcing the myth that one control solves everything.
Mistake
Environmental controls are only about keeping the server room cool.
Correct
Environmental controls also manage humidity (to prevent static electricity and condensation), fire detection and suppression, water leak detection, positive air pressure and power quality (UPS and generator). Neglecting any one of these can cripple operations.
When walking into a chilly data centre, the most noticeable feature is the air conditioning. That single sensory impression makes people overlook the less visible but equally critical systems working behind the scenes.
Mistake
Biometric readers are 100% accurate and cannot be fooled.
Correct
Biometrics have measurable False Acceptance Rates (FAR) and False Rejection Rates (FRR). They can be spoofed with gummy fingers, high-resolution photos or contact lens overlays. That is why they are best combined with a second factor such as a badge or PIN.
Movies depict iris and fingerprint scanners as infallible. In reality, all sensors trade off between security (reducing false accepts) and convenience (reducing false rejects), and no technology is unbeatable.
Reveal each answer, then mark whether you got it right. Score 60%+ to unlock the next chapter.
A dry pipe system uses pressurised air in the pipes; when a sprinkler head opens, air escapes, water flows in and then out through that single head. A pre-action system requires two independent triggers before water ever enters the pipes—typically a smoke/heat detector alarm and then a sprinkler activation—so accidental water discharge is virtually impossible.
Water conducts electricity and will irreparably damage live equipment even if the fire itself is tiny. A sprinkler head that opens accidentally due to a false alarm or physical bump can flood racks and cause a total outage, so IT environments use pre-action or clean agent systems instead.
A mantrap is a small interlocking room with two doors. Only one door can open at a time, and the inner door unlocks only after the outer door has closed and the person inside has been authenticated (badge, PIN, biometric). It stops tailgating and piggybacking by ensuring that only one authorised individual passes through at a time.
Generators should be test-run under at least 30% load monthly to ensure they start and transfer correctly. A full-load failure simulation, where the entire facility runs on generator power for an extended period, is typically performed quarterly or semi-annually, depending on the organisation's risk tolerance.
Use an extinguisher rated for Class C fires (energised electrical equipment), which typically contains a non-conductive clean agent like FM-200 or NOVEC 1230. Never use water or foam extinguishers, as they create an electrocution hazard and can destroy hardware.
No. Standard office air conditioning rarely provides the precise temperature and humidity control, the continuous 24/7 duty cycle, or the redundancy that IT equipment needs. For any room with more than a couple of servers, you should install a dedicated precision cooling unit with environmental monitoring and alerting.
You've finished Physical Security and Environmental Controls. Continue through the CISSP study guide to build a complete picture of the exam.
Done with this chapter?