Cybersecurity & Infrastructure Security Agency – Best Practices for Planning and Managing Physical Security Resources
3.10 3.10.5 Physical Protection
https://www.cisa.gov/sites/default/files/publications/isc-planning-managing-physical-security-resources-dec-2015-508.pdf
This agency guide is a comprehensive treatment on the control and management of physical access devices. The guide addresses cost-effectiveness, performance-measurement, and the planning and managing of physical security resources. Section 5.4 is a short section that addresses Operation and Maintenance of Physical Security Resources.
Federal Financial Institutions Examination Council IT Examination Handbook – Physical Security
3.10 3.10.5 Physical Protection
https://ithandbook.ffiec.gov/it-booklets/architecture-infrastructure-and-operations/v-infrastructure/ve-physical-access-controls/
This entry summarizes some of the preventive and detective controls for physical security and discusses some minimum physical security requirements.
Health and Human Services – Security Standards: Physical Safeguards
3.10 3.10.5 Physical Protection
https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/administrative/securityrule/physsafeguards.pdf
This link provides a sample policy checklist designed to examine compliance with Federal regulations that have not changed since that time. This standard speaks to EPHI data, but it can be adapted to other regulated data like CUI (see Section 4 – Maintenance Records).
Naval Facilities Engineering Service Center – User’s Guide on Controlling Locks, Keys and Access Cards
3.10 3.10.5 Physical Protection
https://apps.dtic.mil/sti/pdfs/ADA381740.pdf
This user guide provides information and recommended procedures for establishing key and lock programs.
North Carolina – Physical and Environmental Protection Policy
3.10 3.10.5 Physical Protection
https://it.nc.gov/documents/statewide-policies/scio-physical-and-environmental-protection/download?attachment
This policy provides a comprehensive example demonstrating how to protect the privacy and security of sensitive information and prevent the unauthorized use or misuse of data through the control and use of physical access devices (see Section PE-3).
https://www.sans.org/white-papers/37120/
This SANS whitepaper provides a broad overview of the importance of physical security as it intersects with cybersecurity.
SAPBW Consulting – 5 Physical Security Controls Your Business Needs
3.10 3.10.5 Physical Protection
https://www.sapbwconsulting.com/blog/5-physical-security-controls-your-business-needs
This article provides insight into protecting the physical infrastructure and describes five key areas where physical security controls need to be in place.