36 MAC Pt. 1, R. 13.1

Physical Protection

Year: 2026Length: 483 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 13.1

Physical Protection A. Each agency must limit physical access to agency systems, equipment, and the respective operating environments to authorized individuals. Limiting physical access requires the implementation of physical security controls to restrict an individual’s ability to interface with a given device. 1. Limiting physical access should be applied to all individuals who enter its facility or perimeter. This includes, but is not limited to staff, visitors, and other third parties which retain access credentials. 2. Develop and maintain documented processes which describe the methods in which they restrict access and enforce physical access authorizations, to include the location of mission critical devices and systems, their applicable physical security control, and how access is delegated and removed from users. i. Limiting physical access to equipment may include placing equipment in locked rooms or other secured areas and allowing access to authorized individuals only; and placing equipment in locations that can be monitored by organizational personnel. Computing devices, external disk drives, networking devices, monitors, printers, copiers, scanners, facsimile machines, and audio devices are examples of equipment. B. Each agency must protect and monitor the physical facility and support infrastructure for agency systems. Known or observed vulnerabilities or gaps in the physical security of an organization’s perimeter or facility must be addressed immediately. C. Each agency must escort visitors and monitor and control visitor activity. 1. Individuals with permanent physical access authorization credentials are not considered visitors. Audit logs can be used to monitor visitor activity. D. Each agency must maintain and audit logs of physical access. 1. Audit logs can be procedural (e.g., a written log of individuals accessing the facility), automated (e.g., capturing ID provided by an access card/badge), or some combination thereof. Physical access points can include facility access points, interior access points to systems or system components requiring supplemental access controls, or both. System components (e.g., workstations, notebook computers) may be in areas designated as publicly accessible with organizations safeguarding access to such devices. 2. ITS recommends that agencies review physical access logs monthly and upon occurrence of detected and/or suspected physical security incidents/violations. E. Each agency must control and manage physical access devices. 1. Physical access devices include but are not limited to keys, locks, combinations, biometric readers, and card readers. These devices must be secured when not in use. 2. Document the location in which access devices and keys are stored as well as individuals which are granted access to them. 3. Inventory physical access devices at least annually. 4. Change physical access devices (e.g., combinations and keys) at minimum yearly and/or when keys are lost, combinations compromised, or when individuals possessing the keys or combinations retire, leave, and/or are transferred or terminated and/or access is no longer needed. F. Each agency must ensure protections for agency systems are in place for alternate work sites. 1. Alternate work sites may include government facilities or the private residences of employees.
36 MAC Pt. 1, R. 13.1: Physical Protection | Justis AI