A security team is categorising the controls used to protect a corporate office. Which example is best classified as a physical security control rather than a technical, managerial, or operational one?
- AA host-based firewall on every laptop that filters inbound and outbound network traffic.
- BA mantrap at the data centre entrance that prevents tailgating into the server hall. Correct
- CAn acceptable use policy that staff must read and sign before being issued an account.
- DA nightly user access review performed by team leads to remove unneeded permissions.
Why A is wrong: A host-based firewall is software enforcing rules on a computer, which makes it a technical control rather than a physical one, even though it protects the device.
Why B is correct: A mantrap is a tangible barrier in the environment that physically restricts who can enter a sensitive area, which is the defining trait of a physical control.
Why C is wrong: Signed policies guide behaviour and risk decisions, so they are managerial controls; they are tempting because they protect the office but they are not physical objects.
Why D is wrong: Recurring access reviews are an operational control performed by people as part of a process, not a physical barrier or device guarding a location.