Sunday, July 15

Physical Security

The environment has enormous influence on the security of a computer system.
a. Location :
The location where computers are kept determines many of the risks that affect it. Any such location (site) is subject to many natural risk such as stability of ground and weather conditions. Thus, the risk inherent in the computer location  need to be assessed. The other factors or conditions affecting the location are :
Weather
Wind, rain, snow, ice
Floods
Lightening
Land slip

b. Electric Power Supply :
No computer can operate without power supply. Computer needs 220 Volts (A.C.) to 240 Volts (A.C.) supply as the input voltage to its Power Supply Unit. The frequency of A.C.(Alternating Current) supply should be 49.5 Hz to 50 Hz.
An uninterrupted power supply (U.P.S.) is one which provides uninterrupted supply of power in case of failure of regular supply to the computer system.When ever there is power cut or supply problem, automatic switching takes place between regular supply line and the UPS and without interruption, a continuous or constant  supply to the computer is maintained. Hence, data or program loss or any electric damages to any unit or circuit will not take place. The City line (Public supply) may fail due to various reasons, including accidental damage to supply lines or substations, load shedding at peak periods, lightening etc. Hence, provision should be made for uninterrupted power supply to the computer.
A stand by  generator with battery supported UPS can maintain supply. Such a generator need very high capital cost.
A stand by emergency lighting is always necessary to escape in case of supply line failure. Large electric torches or lanterns should be kept near the reception desk.

c. Air Conditioning :
Large computers dissipate so much heat, so ventilation is needed to maintain the temperature. For a mainframe computer, certain environment is needed. Humidity and temperature must be controlled, and a dust-free atmosphere is to be maintained which i possible with air conditioning plants.
A typical air conducting plant recirculates some of the air and introduces a continuous supply of clean filtered air at the correct temperature and humidity. Some air is exhausted to the outside.
The temperature of 21 degree Celsius +-2 degree Celsius (70 Degree Fahrenheit +- 3 Degree Fahrenheit) and the relative humidity of 50% +- 5% are necessary. Rise temperature inside the computer room leads to over heating of components (i.e. I.C. chip, Transistor etc), moisture precipitation.
If air condition plant is not working properly, dust can be introduced, problem on magnetic tape and disk arises. Staff working inside the computer room can introduce    dust on shoes and clothing. Special mats and floor covering are to be kept properly. Smokes of any kind should be avoided, otherwise, insignificant amount of smoke can contaminate disk heads and result in head reading faults or problems.

d.Access Control :    
Unnecessary persons should not be allowed inside the computer room. The entry and exit point of the computer room should be controlled and monitored properly.
The commonly used access control methods are
(a) By using people (e.g. Security guard)
(b) By using mechanical locks (e.g. Door Lock)
(c) By using electronic system (e.g. Card Locks)

e. Building construction and design :            
Proper building or housing for the computer system makes an important contribution to the security of computers. The structure of the building should have  fire - resistance and sound construction. The facilities regarding the computer system should be located above the ground level to avoid danger from flooding. In multi- stored buildings, the floor above the computer must protect against spillage, or other water leakage. Sufficient space must be kept for expansion of the computer equipments. There should be as few doors as possible to the exterior The number of doors and windows should be less. Emergency doors and windows are to  be constructed.

f. People and organization :                
The people involved in a computer system are most important as far as security of computer is concerned. People like system analyst, mainframe engineers, programmers, operators, cleaners, users are responsible to maintain proper security.  

No comments:

Post a Comment