ExamChapter 72 min read

Physical Security and Cloud Security

O
OIYO EditorialContributor
7/8

Physical Security

The outer layer of defense in depth:

1

Perimeter (fence/CCTV)

2

gate

3

building

4

data center

5

server room

6

rack

Physical access

Mantrap: two doors, a small room between. One door must close before the other opens. Stops piggybacking.

Tailgating / piggybacking: following an authorized person in. Needs awareness training, not just a badge reader.

Badge systems: smart card plus PIN.

Environment

Temperature / humidity: server rooms often targeted around 18–21°C and 45–55% RH.

Fire suppression: Halon is retired. FM-200 or Inergen-class gases replace it. Water on live electrical gear is forbidden.

UPS: ride through a short outage and shut down cleanly.


Cloud Security

Service models and shared responsibility

ModelCSPCustomer
IaaSHardware, networkOS, apps, data, hardening
PaaSInfra, OS, runtimeApps, data
SaaSInfra and appData, user access

Deployment models

Public: AWS, Azure, GCP. Shared infra. Cheapest.

Private: dedicated. Higher isolation, higher cost.

Hybrid: sensitive data private, the rest public.

Multi-cloud: more than one CSP. Reduces lock-in.

CASB

A policy enforcement point between the organization and cloud services.

Visibility (including Shadow IT), DLP, threat protection, compliance.


Key Concept Cards

Mantrap ★★★★★
: Two-door lock. Stops piggybacking. High-security facilities.

Shared responsibility ★★★★★
: IaaS = customer from the OS up. PaaS = apps/data. SaaS = data/access. Data is always on the customer.

CASB ★★★★☆
: Visibility and policy on cloud use. Finds Shadow IT.


Practice Quiz

Q1. Fire in a server room. Which suppression is safe for the servers?

Gas systems (FM-200, Inergen). They starve oxygen or absorb heat without soaking electronics. Water is banned in that room.

Q2. Customer records sit in a SaaS CRM. Who owns data security?

Shared, but confidentiality and access control of those records sit with the customer. The vendor protects the platform. Who may see which field, and how the tenant is configured, is the customer’s job.

O

OIYO Editorial

Editorial Desk

The OIYO editorial desk researches money, law, lifestyle, and self-understanding topics against primary sources and public statistics. Every piece carries source notes and is reviewed on a regular cycle for accuracy and usefulness.