#1574 Consider explicit inclusion of physical security in Security operations (SCAD) change request accepted
The Security operations skill may benefit from explicit reference to the physical security of infrastructure.
To prevent unauthorized access to physical infrastructure (such as network routers) - even if it's owned by third parties
Proposed change applies to Security operations
Current status of this request: accepted
What we decided
Monitoring and responding to unauthorised physical access to technology infrastructure is a legitimate part of security operations, including where the infrastructure is hosted or owned by a third party.
The operational scope of Security operations will be clarified to make this explicit, scoped to the monitoring, evidencing and incident-response role. The delivery of physical access controls and management of the physical environment remains in Facilities management (DCMA), the framework of security controls (including physical controls) remains in Information security (SCTY), and the contractual assurance of controls over third-party-hosted equipment is covered by the supplier and contract management skills.