Physical access control and biometrics

Listen to this lesson

Episode 28 · 33:23

Every episode of this course is also a podcast: listen on Spotify.

This episode is a study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.

Objective 3.2 · Security and disaster recovery · 24% of the exam

Why this matters

Almost every software security control assumes that an attacker cannot touch the hardware. Someone standing in front of a server can remove its disks, boot it from their own media, plug a device into a spare port, or simply switch it off. Encryption helps with some of that, as the previous lessons explained, but nothing on the server itself stops a person with physical access from doing damage.

So the first security control for any server is the building around it. This lesson covers how physical security is layered, the controls used at each layer, how biometric systems are tuned, locking the racks themselves, and the records that show who went where.

The lesson

Layers: perimeter, building, room and rack

Physical security works in layers, an approach often called defence in depth. Each layer is a separate barrier, so an intruder who gets past one still faces the next, and each layer admits fewer people than the one outside it.

  • Perimeter: fences, gates, barriers against vehicles, lighting, and signs. The perimeter defines the site and deters casual intrusion.
  • Building: locked entrances, reception, and controlled doors. Everyone who enters should be identified here.
  • Room: the server room or data centre, restricted to the people whose work requires it. It should have no windows onto public areas, a solid door, and walls that run from the true floor to the true ceiling, so nobody can enter by lifting a ceiling tile or through a raised floor.
  • Rack: locked cabinets inside the room, the final barrier, covered later in this lesson.

The principle of least privilege applies physically as well as to accounts. A developer may need building access but not the server room; a network engineer may need the room but only certain racks; a cleaner should never be in the server room unescorted.

Locks, badges, access control vestibules and guards

Each layer is enforced with a mix of controls.

Locks range from traditional keyed locks to electronic locks. Keys are hard to manage: they can be copied, are not returned when people leave, and leave no record of who used them. Electronic access control, using badges, key cards or fobs, solves those problems. Each badge can be given access to specific doors at specific times, can be revoked instantly when someone leaves or loses it, and every use is logged. Badges are often combined with a PIN, so a stolen badge alone is not enough.

The best-known weakness of any controlled door is tailgating or piggybacking: an unauthorised person following an authorised one through the door, often helped by courtesy. An access control vestibule, formerly called a mantrap, defeats it. It is a small space with two doors, where the second will not open until the first has closed, and sensors or a guard can confirm that only one person is inside.

Security guards add judgement that no electronic system has. They can check identification, challenge people, escort visitors, respond to alarms, and notice behaviour that seems wrong. Staff also have a role: they should be trained to challenge or report unfamiliar people and never to hold secure doors open for others.

Biometrics, and the trade-off between false accepts and false rejects

Biometric controls identify people by physical characteristics, such as fingerprints, hand geometry, facial recognition, iris or retina scans, or voice. They are something you are, which cannot be lent to a colleague or left in a drawer as a badge can.

No biometric system is perfect, and every one makes two kinds of error:

  • A false acceptance is when the system admits someone it should not. The false acceptance rate (FAR) measures how often this happens, and it is the more serious error for security.
  • A false rejection is when the system refuses someone it should admit. The false rejection rate (FRR) measures this, and it is the error users notice, complain about, and find ways around.

The two are linked by the system's sensitivity. Making the system stricter lowers false acceptances and raises false rejections; relaxing it does the opposite. The point at which the two rates are equal is the crossover error rate (CER), also called the equal error rate. It is used to compare systems: the lower the CER, the more accurate the system overall.

Where to set the sensitivity depends on what is being protected. A data centre holding restricted data may accept more false rejections to keep false acceptances very low. Biometrics are usually combined with a badge or PIN, giving multifactor physical access, a principle the MFA lesson later in this domain applies to logons.

Locked racks and cases

The last physical barrier is the rack. Many people may have legitimate access to a server room, including staff from other teams, contractors and, in a shared data centre, other customers. Locking the racks limits each of them to the equipment they are responsible for.

  • Rack doors, front and rear, should be locked, and side panels fitted so equipment cannot be reached from a neighbouring rack.
  • Rack locks may be keyed, combination or electronic. Electronic rack locks record who opened which rack and when, extending the audit trail of the room door down to individual cabinets.
  • In colocation data centres, customers often rent locked cabinets or fenced cages within a shared room.
  • Individual servers may also have locking bezels covering their drive bays, and chassis intrusion detection, a switch that records in the server's logs and management controller when the case has been opened.

Keys to racks need the same management as any other key: recorded, issued to named people, and recovered when they leave.

Visitor logs and camera coverage

Controls prevent access; records show what happened. Both are needed, because an incident is investigated with the records.

Visitor logs record everyone who enters without their own access: their name, organisation, the person they are visiting, the purpose, and times in and out. Visitors should show identification, wear a visible visitor badge, and be escorted at all times in secure areas. Electronic visitor management systems print badges and keep the records automatically. Logs are reviewed afterwards, not merely filed.

Video surveillance, historically called CCTV, both deters intruders and records evidence. Cameras should cover entrances, the server room door, the room itself and the rack aisles, with no blind spots at the places that matter. Recordings must be kept for a set period, in line with the retention policy from the previous lesson, and stored where an intruder cannot delete them.

Together with the badge system's logs, these records let an investigator answer who entered, when, what they touched, and whether they were supposed to.

Practise what you just read

1. An unauthorised person follows an employee through a badge-controlled door. Which control is designed to stop this?

Select one

  1. An access control vestibule (mantrap)
  2. A visitor log (sign-in book) at reception
  3. A CCTV camera (video surveillance) on the door
  4. A longer badge PIN that only the holder knows
Show answer

A. A vestibule has two doors, and the second will not open until the first has closed, so only one person passes at a time. Cameras record tailgating but do not prevent it.

2. A biometric system's sensitivity is increased. What happens to its error rates?

Select one

  1. Both rates fall, as the system becomes more accurate
  2. False acceptances rise and false rejections fall
  3. Neither rate changes, only the scan time does
  4. False acceptances fall and false rejections rise
Show answer

D. Making the system stricter admits fewer impostors but refuses more genuine users. The two rates trade against each other, and sensitivity only moves errors from one to the other.

3. What is the crossover error rate (CER) of a biometric system?

Select one

  1. The rate at which the system crashes and needs restarting under heavy use
  2. The point where false acceptance and false rejection rates are equal
  3. The percentage of users who refuse to enrol when the system is deployed
  4. The time it takes to scan a fingerprint and match it against the template
Show answer

B. The CER, or equal error rate, is where the FAR and FRR curves cross. A lower CER means a more accurate system overall, so it is used to compare biometric products.

7 more questions on this objective are part of the full course.

Practise the full question bank in the exam simulator

Hands-on labs

All hands-on labs

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.