Memra

Physical security and threats from non-computing sources

◈ 4 cards

Fire, water, power, temperature and people. Three categories of physical threat, the numbers that earn marks, and prevention, mitigation and recovery kept distinct for each.

The CIA triad is threatened by things that are not attackers

Everything so far in this course has had an adversary in it. This lesson does not need one. A burst pipe destroys integrity and availability exactly as thoroughly as a worm does, and it does so without motivation, capability or a plan. Confidentiality, integrity and availability are properties of the asset, not statements about who is trying to break them, so a complete risk assessment has to cover the sources that are not attacking anybody.

That framing is worth stating explicitly in an answer, because it also tells you which facets are and are not in play. A flood does not breach confidentiality. It attacks availability, and — if data is partially written, or restored inconsistently from an untested backup — integrity. Saying which facets a non-computing threat touches, and which it leaves alone, is a mark that most answers do not collect.

Three elements, six names

Before the threats, the vocabulary, because the book gives three concepts six names and an exam can use any of them:

  • Logical security — protecting data from software- and communication-based threats. Everything in modules 1 to 12.
  • Physical security, also called infrastructure security — protecting the systems that hold the data, the supporting facilities (power, communications, environmental control), and the people who use, operate and maintain them; and preventing the physical access that would let someone bypass every logical control.
  • Premises security, also called corporate security or facilities security — protecting people and property across a whole site, usually mandated by law and by fiduciary obligation rather than chosen.

Two halves of physical security are examinable in their own right. Prevent damage to hardware, the facility, the supporting facilities and personnel. Prevent misuse of the physical infrastructure — vandalism, theft of equipment, theft by copying, theft of services, unauthorised entry. Note that personnel are part of the physical infrastructure, which is the half learners omit, and that theft by copying is a physical-security concern too: nothing was carried out of the building, and the loss is complete.

The three categories of physical threat

Environmental, of which natural disasters are the prime but not the only source. Technical — power and electromagnetic emission. Human-caused. Learners default almost entirely to the deliberate-human quadrant and lose most of the marks in a question that is explicitly about the other two.

### Environmental

Fire is the most feared, and its indirect threats matter as much as flame: heat, toxic fumes (a serious threat to people and a corrosion threat to equipment), smoke — which is an abrasive — and water damage from the suppression system itself. The sprinkler system is therefore a threat as well as a control, which is a genuinely counterintuitive point worth making.

Water threatens from above as well as below. Plumbing leaks and suppression discharge two floors up will reach the equipment room, so a room chosen for being above the flood plain is not thereby safe. The classic control is a set of water sensors on the floor and beneath any raised floor, wired to cut power automatically — because the damage water does to running equipment is largely electrical.

Temperature and humidity carry the numbers that separate a good answer from a vague one. Damage thresholds for sustained ambient temperature run in a memorable order, and the media die long before the hardware does: magnetic media at about 38 °C, optical media at 49 °C, hard-disk media at 66 °C, computer equipment at 79 °C, wire insulation at 125 °C, paper at 177 °C. So an air-conditioning failure is a security event, and it is one that destroys your backups before it destroys the server that made them. Relative humidity should sit between 40% and 60%. Too high brings corrosion, condensation, and a galvanic effect that can electroplate one connector onto its mate. Too low brings static discharge — as little as 10 V damages sensitive circuits, while a human walking across a carpet routinely carries thousands.

Also in this category: dust, which is abrasive and conductive in the wrong mix, and infestation by insects and rodents, which is a real cause of cable failure and is invariably left off student answers.

### Technical

Three power problems and one emission problem.

Undervoltage — less voltage than the equipment needs. The spectrum runs from momentary dips through a brownout (prolonged undervoltage) to a full outage. The quantitative facts: most computers tolerate a sustained reduction of about 20% without shutting down or erring, and dips deeper than that, lasting more than a few milliseconds, trigger shutdown. Crucially, undervoltage generally causes no damage — only interruption of service.

Overvoltage — a utility anomaly, a building wiring fault, or lightning. Far more serious: a sufficient surge destroys silicon components, processors and memory included, and the damage is a function of intensity, duration and how good the surge protection was.

Undervoltage interrupts; overvoltage destroys. Learners consistently assume the two are equally destructive, and that single sentence collects the mark.

Noise — spurious signals that survive the power supply's filtering and interfere with signals inside devices, producing logical errors rather than physical damage. Electromagnetic interference (EMI) comes from motors, fans, heavy equipment, nearby computers, broadcast transmitters and microwave relays, and — the detail that makes it hard to defend against — it travels through space and along nearby power lines.

### Human-caused

Four, and the first one is a gateway to the other three. Unauthorised physical access, which enables everything else and is why server rooms are limited to a small number of named people. Theft — of equipment, of data by copying, and by eavesdropping and wiretapping; by outsiders and by insiders. Vandalism — destruction of equipment and data. Misuse — improper use by authorised people, and any use at all by unauthorised ones.

Human threats are harder to defend against than environmental and technical ones for two reasons worth stating: they are less predictable, and they are specifically designed to defeat the prevention measures and to seek the most vulnerable point.

Prevention, mitigation and recovery — keep them apart

These three are separate stages and merging them is the commonest structural fault in an answer.

Prevention stops the event: siting away from flood plains and industrial hazards; common walls rated at at least one hour for fire; ducts routed so they do not spread fire; housekeeping that keeps combustible clutter out of equipment rooms; environmental monitoring with alarms; access control at the door.

Mitigation limits the harm when it happens anyway: marked and tested extinguishers; detectors that alarm internally and externally and trigger suppression after a delay that permits human intervention — because a false alarm that discharges suppression is itself an incident; a clearly marked power-off switch; water sensors that cut power; a UPS per critical device for brief interruptions and an emergency generator for long ones; redundancy and off-site replication; compartmentation so one event does not take everything.

Recovery restores service afterwards: a documented disaster-recovery plan, records for file reconstruction stored off the premises, a contingency plan for using equipment elsewhere, an alternate site, and restores that have actually been tested.

One sentence separates a strong answer here: redundancy recovers from loss, but not from disclosure. A second copy does nothing about data that has been stolen, which is why the recovery stage cannot be the whole plan. And note that bolting equipment down deters theft but not vandalism, unauthorised access, or misuse.

Worked example — Coldstream's basement records room

Same asset as every lesson in this module: Coldstream's personal and financial records. This time the threat sources are not attackers.

The records room is in a basement, chosen years ago because it was cheap, cool and windowless. Environmental: it sits below the water table's seasonal range, and the building's main risers pass through the ceiling void — so water threatens from below and from two floors above. Technical: it shares a distribution board with the catering kitchen, whose compressors cause voltage dips; there is a UPS on the servers but not on the network switch feeding them, which means a dip takes the service down while leaving the servers running and confused. Human-caused: the door is on the general staff card group because the room also holds stationery.

Measures at all three stages. Prevention: move the stationery out and reduce the card group to four named people; separate the distribution board from the kitchen; fit a one-hour-rated door. Mitigation: water sensors on the slab and under the raised floor, wired to cut power; a UPS on the switch as well as the servers; environmental monitoring alarming on temperature above 27 °C and humidity outside 40–60%, escalating to a person rather than to a log. Recovery: nightly replication to a second campus, an off-site copy of the reconstruction records, a documented plan for running the records service from the library's teaching lab, and a restore tested each quarter.

Which facets were at risk? Availability throughout, integrity where a dip corrupts a write in progress, and confidentiality only in the human-caused category — the flood and the brownout cannot disclose anything. Say that, and the answer is doing what the question asked.

Physical threatsEnvironmentalfire, water, heatTechnicalpower, noise, EMIHuman-causedtheft, misuse
Environmental covers fire, water, temperature, humidity, dust and infestation; technical covers undervoltage, overvoltage, noise and EMI; human-caused covers unauthorised access, theft (including theft by copying), vandalism and misuse. Learners default to the third branch and lose the marks in the first two.
ThreatPreventionMitigationRecoveryFireone-hour ratedwalls; ducts thatdo not spread it;housekeepingdetectors alarminginside and out;suppression after ahuman-interventiondelayoff-premisesreconstructionrecords; alternatesiteWatersite above floodlevel; know whatruns through theceiling voidfloor and sub-floorsensors wired tocut powerreplication to asecond site; testedrestorePowerseparate the boardfrom heavy plant;surge protectionUPS per criticaldevice — includingthe switchemergencygenerator;documented restartorderTemperature /humidityenvironmentalcontrol sized forthe loadmonitoring thatalarms to a person,not to a logmove the workload;replace mediabefore hardwareHuman-causedsmall named cardgroup; lockedenclosures; boltedequipmentalarms;compartmentation;supervisionredundancy recoversloss, neverdisclosureCover wiring, power, HVAC, comms lines, backup media and documents — not just computers.
Three stages, kept apart on purpose. Merging prevention with mitigation is the commonest structural fault in an answer to this question — and recovery by redundancy answers loss, never disclosure.
NORMAL ~/memra/learn/comp-400/physical-security-and-threats-from-non-computing-sources utf-8 LF