CISSP - Security Operations - Section 7.14

Implement and manage physical security including perimeter and internal security controls.

Implement physical security controls for both perimeter and internal zones, including barriers, guards, locks, mantraps, and access logs. Distinguish between perimeter controls designed to deter and detect external intrusion and internal controls that enforce separation between security zones within a facility.

perimeter securityinternal security controlsphysical accessguards and locks

Practice question for this objective

Free sampleSecurity Operationsmedium

A pharmaceutical company has finished fitting out a new research wing that contains laboratories, a controlled-substance store, and open-plan offices. The facilities manager has proposed a single physical access control scheme for the whole wing: badge readers on the main wing entrance and on every individual door, with all employees in the wing granted access to every door so that staff are never blocked from collaborating. As the security manager asked to approve the scheme before go-live, what is the BEST recommendation?

  • AApprove the scheme as proposed because uniform access across the wing maximises collaboration and the badge readers already provide an auditable record of who entered which room.
  • BRestructure the scheme into security zones with role-based access so that the controlled-substance store and laboratories require additional authorisation beyond the wing entrance. Correct
  • CApprove the scheme but add CCTV coverage inside the controlled-substance store and the laboratories so that any misuse can be investigated after the fact.
  • DApprove the scheme but require two-person rule procedures whenever staff enter the controlled-substance store, documented through a paper sign-in log kept at the door.
Design internal physical access using zoned, role-based controls so that sensitive areas enforce least privilege rather than relying on uniform access plus monitoring. Defence in depth for internal physical security calls for dividing a facility into zones whose access requirements scale with the sensitivity of the assets inside. Controlled-substance stores and research laboratories carry regulatory, safety, and intellectual-property exposures that demand least-privilege access, typically enforced by additional badge groups, separate readers, or supplementary authentication. Granting every employee access to every door, even with auditing and cameras, fails this principle because detective controls cannot substitute for preventive ones at the access decision point.

Why A is wrong: Uniform access is operationally convenient and the audit trail is real, which makes this tempting, but granting every employee access to the controlled-substance store and labs ignores least privilege and regulatory expectations. An auditable record of an inappropriate entry does not justify granting that entry in the first place.

Why B is correct: Internal physical controls should reflect the sensitivity of what each space contains, which is the principle of zoned defence in depth. Segmenting the wing into zones, with role-based access to the controlled-substance store and labs, enforces least privilege and aligns with regulatory and safety expectations for pharmaceutical environments.

Why C is wrong: Camera coverage is a useful detective and deterrent control and is reasonable to add, but relying on it to compensate for unrestricted access inverts the control hierarchy. Preventive access controls aligned to sensitivity should come first, with monitoring layered on top, not the other way around.

Why D is wrong: A two-person rule is a recognised control for high-sensitivity areas and is appealing here, but layering it on top of universal badge access and a paper log leaves the technical control over-permissive and the audit trail weaker than the badge system already provides. The access scheme itself needs to be tightened, not patched with manual process.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Security Operations objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.