preventions
- ID: PV095
- Created: 01st August 2026
- Updated: 01st August 2026
- Contributor: The ITM Team
Physical Access Zoning for Critical Infrastructure
Physical access zoning separates critical infrastructure environments into distinct restricted areas, with access granted according to the subject’s specific operational responsibilities.
General building access should not automatically permit entry into data centers, communications rooms, network distribution areas, control rooms, equipment cages, or individual server racks. Each area should have a separate access boundary, ensuring that subjects can only enter the locations required for their role.
Organizations should use controls such as badge-restricted doors, locked cages, secured cabinets, rack-level locks, and time-limited access permissions to prevent unauthorized movement between zones. Permissions should be regularly reviewed and removed when they are no longer operationally necessary.
This approach limits physical access to high-impact systems, reduces opportunities for unauthorized interference or sabotage, and provides clearer access records during an investigation.
Sections
| ID | Name | Description |
|---|---|---|
| IF031 | Unauthorized Presence in Restricted Physical Areas | A subject deliberately enters or remains within a physical area as a trespasser, knowing they are not authorized to be present, where that presence alone creates a credible risk of harm to the organization.
|
| IF031.006 | Remaining in a Restricted Area Outside Authorized Hours | A subject knowingly remains within a restricted physical area after their authorized access period has ended, or enters the area during a time when their role, assignment, escort approval, or access authorization does not permit their presence.
The subject may have legitimate daytime or task-based access to the location, but that authority does not extend to the time at which the presence occurs. Relevant behaviors include remaining after a shift or escorted visit, entering during a closed period, concealing continued presence after other personnel depart, or returning outside an approved access window.
The infringement is distinguished from accidental overstay by evidence that the subject understood the temporal restriction and deliberately remained or entered regardless. |
| IF031.005 | Unauthorized Presence in Records or Evidence Storage Areas | A subject deliberately enters or remains within an area used to store physical records, legal files, personnel documents, investigative material, evidential items, archived media, regulated records, or chain-of-custody material without authorization.
Unauthorized presence may expose confidential information or provide an opportunity to inspect, remove, substitute, contaminate, damage, or interfere with stored material. The infringement applies where the subject knowingly enters the controlled area, even where subsequent access to a specific record or evidential item cannot be established. |
| IF031.004 | Unauthorized Presence in Research, Laboratory, or Production Areas | A subject deliberately enters or remains within a restricted research facility, laboratory, prototype area, test environment, manufacturing floor, production line, formulation area, engineering workspace, or other location containing sensitive development or operational activity without authorization.
The area may expose unreleased intellectual property, prototypes, formulas, samples, research data, specialized equipment, manufacturing methods, safety-critical processes, or regulated materials. The subject’s presence may create risks to confidentiality, product integrity, safety, regulatory compliance, or operational continuity even where no additional action is observed. |
| IF031.001 | Unauthorized Presence in Data Center or Communications Areas | A subject deliberately enters or remains within a data center, server room, network operations area, telecommunications room, cable distribution area, or other restricted environment containing critical information technology or communications infrastructure without authorization to be present.
The subject’s proximity may provide direct access to servers, storage systems, network appliances, cabling, console interfaces, removable media, environmental controls, or out-of-band management equipment. The infringement applies where the subject knowingly crosses an established physical boundary, regardless of whether they subsequently interact with the equipment. |