TechKnowSurge
VideoSecurityFree

Physical Access Control

Physical security controls are a critical layer of network defense, preventing adversaries from bypassing logical protections through direct hardware access. This content covers access control types, detection methods, and the equipment security measures used to protect IT infrastructure.

Complete this video to capture a CTF flag worth 1 point.

About this video

Logical security measures such as firewalls, authentication, and access control lists can be rendered ineffective if an adversary gains physical access to network equipment. A straightforward example illustrates this: the standard password recovery process on a Cisco switch, while useful for legitimate administrators, also gives anyone with physical access a path to bypass credentials and reach full device configuration. This reality makes physical access control not a secondary concern, but a foundational layer of any complete security posture. To frame physical security systematically, the content introduces the standard taxonomy of security controls. Preventative controls stop incidents before they occur, deterrents reduce the likelihood of an attempt, detective controls support investigation after an event, corrective controls address damage once something has happened, recovery addresses restoration following correction, compensating controls reduce impact when a primary control is absent, and directive controls reflect legally or organizationally mandated requirements. These categories are not mutually exclusive — a surveillance camera, for instance, functions simultaneously as a deterrent and a detective control. With that framework established, the content surveys the practical mechanisms used across three areas: controlling physical access to spaces, detecting unauthorized entry, and securing equipment itself. Access control covers everything from architectural measures like signal-blocking materials and reflective glass to entry points secured by key fobs, smart cards, RFID, biometrics, and access control vestibules. Detection draws on security personnel, alarm systems, lighting, and a range of sensors including infrared, pressure plates, microwave, and ultrasonic. Equipment security addresses laptop locks, locking cabinets and racks, smart lockers, safes, and asset tagging for inventory tracking.

What you'll learn

What's covered

Physical Security Controls

Key terms

Access Control
A security mechanism that restricts access to resources based on policies, roles, or identity.
Biometrics
Authentication methods that use unique physical or behavioral characteristics such as fingerprints or retinal scans.
Asset
Any resource of value to an organization, including hardware, software, data, and personnel.
Preventative Control
A security control designed to stop a threat or incident from occurring in the first place. Firewalls, encryption, and access control policies are common examples of preventative controls.
Deterrent Control
A security control that discourages threat actors from attempting an attack by making the environment appear more difficult or risky to compromise. Warning banners, visible cameras, and security signage are common deterrent controls.
Detective Control
A security control that identifies and alerts on security incidents or anomalous activity as they occur or after the fact. Intrusion detection systems, security logs, and audit trails are examples of detective controls.
Corrective Control
A security control that addresses and remediates a security incident after it has been identified — such as restoring systems from backup, patching a exploited vulnerability, or blocking an attacker's IP address.
Recovery Control
A security control designed to restore systems, data, and normal operations after a security incident has been identified and contained. Backup restoration, disaster recovery procedures, and system reimaging are examples of recovery controls.
Compensating Control
An alternative security measure implemented to offset a known risk or vulnerability when a primary control cannot be fully applied. A compensating control must provide an equivalent or greater level of protection.
Directive Control
A security control mandated by laws, regulations, or customer requirements that an organization must implement with no discretion. Examples include legally required data retention policies and mandatory breach notification procedures.
Physical Access Control
Security measures that restrict and manage physical entry to facilities, equipment, and IT infrastructure to prevent unauthorized access.

Topics

Physical Security Access Control Security Controls Network Infrastructure Cybersecurity

Transcript

Why Physical Access Control Matters

We can spend a lot of time trying to control access into our networks, trying to control people remoting into our equipment and trying to lock those down. But if we don't have physical security, if we don't have physical access controls in place, then there are a lot of things an adversary can do to gain access into our equipment and into our networks. So we've got to maintain some sort of physical access control.

This is a Cisco switch, and we could put a lot of time and effort into locking down this switch. Let's say we forget our password. Well, that's okay, because there's a way that we can get in here and reset that password without losing all those configurations. But there's a catch to this. That means that if somebody has physical access to the switch right here, they can actually reboot this, bypass that password, and get in and see all the configurations, have management access to the switch. That can be very problematic. So we really need to control access into our equipment, because if an adversary has direct access to it there are ways that they can get around some of the things that we put into place guarding this piece of equipment.

Types of Controls

We haven't talked about this too much, but every time we put something into place that helps protect our network, we call it a control. A control is something that we put into place to help mitigate a problem. And there are several different types of controls. We're briefly going to go over this just so we have an understanding of what this is.

  • Preventative. This will stop something from happening. So maybe we put a firewall in place and that's going to stop people from gaining access into our network.
  • A deterrent, like a fence. You can climb over the fence, but it's probably less likely — fewer people are going to climb over a fence. So it makes it less likely for somebody to do something.
  • Detective. Detective means that we can go and investigate afterwards. So there are signs, there are things like surveillance tape that we can go back and look at to see what has happened on there.
  • Corrective action. If something were to happen, then we could correct for it. A good example of this might be if we cut our hand and we stop the bleeding by putting a band-aid on it. That's corrective action.
  • Recovery. That band-aid still needs to heal. We have that also within cyber security: there are things that we do to correct some sort of issue that's taken place, but then there's a recovery that happens after that. Even though we've made the correction, we still need to go through a recovery process.
  • Compensating. That means that we haven't really done away with the problem, but maybe we've taken out extra insurance or we've done something so that if it occurs, it won't be as devastating.
  • Directive. This just means that somebody has directed that we're doing this and we really have no choice. So think laws and regulations might be an example of this.

These are not exclusive. There are certain things that can happen that can fill multiple needs. So a video surveillance camera can be a deterrent, because people are less likely to break into a building if they see a camera there. It also could be a detective, where we can go back and see what has happened. So you can fill more than one category here.

What We Want to Do Physically

Some of the things that we want to do are control access into a building or a door. We also want to detect if somebody has crossed those lines, has entered in somewhere where they shouldn't have. So we do things like use surveillance to be able to survey or look at or see what's happening, and we'll have sensors and stuff that will do that. And then we also are going to want to secure equipment and make sure that equipment is not going to walk off, or that people aren't going to have access to that equipment. And then also we have a bunch of assets and we're going to want to track those assets.

Examples of building access would be bollards, or at least an area access there, or fencing. Even within the architect there are some ways to block signals like radio signals, or have reflective glass, or there's even some building camouflage, and we'll talk about that.

There's also access into the building — so like access control vestibules, or magnetometers. Maybe you have to go through some sort of metal detector to get into a building.

There's also the door access. We've got keys, key fobs, battery, smart cards, swipe cards, RFID, biometrics. There are ways that we can control the access through a door.

If somebody were to pass one of those entry points, get into the building or into a doorway, then we have some ways that we can detect that, like security guards or security escorts. Maybe we use lighting, guard dogs, tamper detection, alarm systems, and surveillance.

When it comes to surveillance, there are a lot of different types of surveillance: video surveillance, wireless surveillance, electronic surveillance, detectors and sensors like infrared or pressure plates or microwave or ultrasonic.

And even just securing the laptops themselves — even if they're behind locked doors, maybe we use some sort of laptop or equipment locks for them, smart lockers, safes, locking cabinets, locking racks, and asset tags to track that equipment.

I actually broke these down into a bunch of little videos, and a lot of them you might want to just skip because they're going to be pretty basic. I mean, what can I really say about keys or fencing? But some of them I have a few things to say about. So what you can do is choose to go through all of them, or just go through the ones that you want to have a little bit of a story behind, and we'll discuss each one of these.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →