36 MAC Pt. 1, R. 13.1
Physical Protection
Cite as 36 Miss. Admin. Code Pt. 1, R. 13.1
Physical Protection
A. Each agency must limit physical access to agency systems, equipment, and the
respective operating environments to authorized individuals. Limiting physical access
requires the implementation of physical security controls to restrict an individual’s
ability to interface with a given device.
1. Limiting physical access should be applied to all individuals who enter its
facility or perimeter. This includes, but is not limited to staff, visitors, and
other third parties which retain access credentials.
2. Develop and maintain documented processes which describe the methods in
which they restrict access and enforce physical access authorizations, to
include the location of mission critical devices and systems, their applicable
physical security control, and how access is delegated and removed from
users.
i.
Limiting physical access to equipment may include placing equipment
in locked rooms or other secured areas and allowing access to
authorized individuals only; and placing equipment in locations that
can be monitored by organizational personnel. Computing devices,
external disk drives, networking devices, monitors, printers, copiers,
scanners, facsimile machines, and audio devices are examples of
equipment.
B. Each agency must protect and monitor the physical facility and support infrastructure
for agency systems. Known or observed vulnerabilities or gaps in the physical
security of an organization’s perimeter or facility must be addressed immediately.
C. Each agency must escort visitors and monitor and control visitor activity.
1. Individuals with permanent physical access authorization credentials are not
considered visitors. Audit logs can be used to monitor visitor activity.
D. Each agency must maintain and audit logs of physical access.
1. Audit logs can be procedural (e.g., a written log of individuals accessing the
facility), automated (e.g., capturing ID provided by an access card/badge), or
some combination thereof. Physical access points can include facility access
points, interior access points to systems or system components requiring
supplemental access controls, or both. System components (e.g., workstations,
notebook computers) may be in areas designated as publicly accessible with
organizations safeguarding access to such devices.
2. ITS recommends that agencies review physical access logs monthly and upon
occurrence of detected and/or suspected physical security incidents/violations.
E. Each agency must control and manage physical access devices.
1. Physical access devices include but are not limited to keys, locks,
combinations, biometric readers, and card readers. These devices must be
secured when not in use.
2. Document the location in which access devices and keys are stored as well as
individuals which are granted access to them.
3. Inventory physical access devices at least annually.
4. Change physical access devices (e.g., combinations and keys) at minimum
yearly and/or when keys are lost, combinations compromised, or when
individuals possessing the keys or combinations retire, leave, and/or are
transferred or terminated and/or access is no longer needed.
F. Each agency must ensure protections for agency systems are in place for alternate
work sites.
1. Alternate work sites may include government facilities or the private
residences of employees.