9.2.2 Physical and/or logical controls are implemented to restrict use of publicly accessible network jacks within the facility
Physical and/or logical controls are implemented to restrict use of publicly accessible network jacks within the facility.
5
artefacts
1
held by a system
2
at each review
hard
to go live
Physical access / facilities
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Configuration extract showing the ports in public areas are disabled or restricted · Physical access / facilities
periodic reviewEvidence produced at each review
- Evidence of the physical or logical controls restricting use of those jacks, such as disabled ports, port security or network access control · Physical access / facilities
- Test evidence that an unauthorised device connected in a public area cannot reach the network · Physical access / facilities
governing documentDocuments that govern the control
- Observation of publicly accessible areas within the facility and the locations of network jacks in them · Policy repository / GRC workspace
- Process for enabling a jack when legitimately required, and for disabling it afterwards · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Physical access / facilities on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Jacks disabled at one point in time with no process, so ports enabled for an event stay enabled
- Wireless access in public areas treated as out of scope of the same concern, providing the connection the jacks were meant to prevent
- Port security configured to log rather than block an unknown device
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet9.2.1.1 Individual physical access to sensitive areas within the CDE is monitored with either video cameras or physical access control mechanisms (or both) as follows: • Entry and exit points to/from sensitive areas within the · 9.2.3 Physical access to networking and telecommunications hardware restricted