Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-14-1
Cybersecurity requirements for physical protection of information and technology assets must be defined, documented and approved.
Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-14-2
The cybersecurity requirements for physical protection of information and technology assets must be implemented.
Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-14-3
- The cybersecurity requirements for physical protection of information and technology assets must include at least the following:
- Authorized access to sensitive areas within the organization (e.g., data center, disaster recovery center, sensitive information processing facilities, security surveillance center, network cabinets).
- Facility entry/exit records and CCTV monitoring.
- Protection of facility entry/exit and surveillance records.
- Secure destruction and re-use of physical assets that hold classified information (including documents and storage media).
- Security of devices and equipment inside and outside the organization’s facilities.
Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-14-4
The cybersecurity requirements for physical protection of information and technology assets must be reviewed periodically.