Physical Security and Cloud Security
Physical Security
The outer layer of defense in depth:
Perimeter (fence/CCTV)
gate
building
data center
server room
rack
Physical access
Mantrap: two doors, a small room between. One door must close before the other opens. Stops piggybacking.
Tailgating / piggybacking: following an authorized person in. Needs awareness training, not just a badge reader.
Badge systems: smart card plus PIN.
Environment
Temperature / humidity: server rooms often targeted around 18–21°C and 45–55% RH.
Fire suppression: Halon is retired. FM-200 or Inergen-class gases replace it. Water on live electrical gear is forbidden.
UPS: ride through a short outage and shut down cleanly.
Cloud Security
Service models and shared responsibility
| Model | CSP | Customer |
|---|---|---|
| IaaS | Hardware, network | OS, apps, data, hardening |
| PaaS | Infra, OS, runtime | Apps, data |
| SaaS | Infra and app | Data, user access |
Deployment models
Public: AWS, Azure, GCP. Shared infra. Cheapest.
Private: dedicated. Higher isolation, higher cost.
Hybrid: sensitive data private, the rest public.
Multi-cloud: more than one CSP. Reduces lock-in.
CASB
A policy enforcement point between the organization and cloud services.
Visibility (including Shadow IT), DLP, threat protection, compliance.
Key Concept Cards
Mantrap ★★★★★
: Two-door lock. Stops piggybacking. High-security facilities.
Shared responsibility ★★★★★
: IaaS = customer from the OS up. PaaS = apps/data. SaaS = data/access. Data is always on the customer.
CASB ★★★★☆
: Visibility and policy on cloud use. Finds Shadow IT.
Practice Quiz
Q1. Fire in a server room. Which suppression is safe for the servers?
Gas systems (FM-200, Inergen). They starve oxygen or absorb heat without soaking electronics. Water is banned in that room.
Q2. Customer records sit in a SaaS CRM. Who owns data security?
Shared, but confidentiality and access control of those records sit with the customer. The vendor protects the platform. Who may see which field, and how the tenant is configured, is the customer’s job.
OIYO Editorial
Editorial DeskThe OIYO editorial desk researches money, law, lifestyle, and self-understanding topics against primary sources and public statistics. Every piece carries source notes and is reviewed on a regular cycle for accuracy and usefulness.