🇬🇧 CISMP (Certificate in Information Security Management Principles) · subject
CISMP (Certificate in Information Security Management Principles) Physical, Environmental and Operational Security Syllabus
Every chapter and topic of Physical, Environmental and Operational Security examined in CISMP (Certificate in Information Security Management Principles) — 3 chapters, 10 topics and 14 sub-topics, plus 51 flashcards written against it.
Physical, Environmental and Operational Security syllabus — full chapter and topic list
Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Physical, Environmental and Operational Security in CISMP (Certificate in Information Security Management Principles), not a summary of it.
-
Physical and Environmental Security
3 topics- Secure areas and perimeters
- Physical entry controls
- Secure zones and clear desk policy
- Equipment security
- Siting and protection of equipment
- Secure disposal and reuse of media
- Environmental controls
- Power, fire and climate protection
- Secure areas and perimeters
-
Operational Security and Asset Management
4 topics- Asset management and classification
- Asset inventory and ownership
- Information classification and labelling
- Operational procedures and responsibilities
- Documented operating procedures
- Capacity and segregation of environments
- Backup and resilience
- Backup strategies and testing
- Media handling
- Secure transport and storage
- Asset management and classification
-
Security Monitoring and Vulnerability Management
3 topics- Security testing
- Vulnerability scanning
- Penetration testing
- Technical compliance checking
- Event and log monitoring
- Collecting and correlating events
- Security testing
Physical, Environmental and Operational Security flashcards for CISMP (Certificate in Information Security Management Principles)
25 of 51 cards from the Physical, Environmental and Operational Security deck — real questions with worked answers.
In physical security, what is the purpose of defining a 'security perimeter' for a secure area?
A security perimeter is a defined barrier (e.g. wall, fence, manned reception, card-controlled door) that establishes the boundary of an area containing information or information-processing facilities, so that access can be controlled and the contents protected.
What is 'defence in depth' (layered security) in the context of physical site protection?
The use of multiple, successive rings of physical controls (e.g. site perimeter, building, secure room, locked cabinet) so that defeating one layer still leaves further barriers — no single point of failure protects the asset.
Define 'tailgating' (piggybacking) as a physical security threat.
An unauthorised person follows an authorised person through a controlled access point (e.g. a card-controlled door) without presenting their own credentials, defeating the access control.
What is a 'mantrap' (access control vestibule / airlock) and what threat does it counter?
A small space with two interlocking doors where the second door cannot open until the first has closed, allowing only one person through at a time. It counters tailgating/piggybacking and enforces single-person authenticated entry.
What is a 'clear desk and clear screen' policy?
A policy requiring that papers, removable media and other sensitive information are locked away when not in use, and that screens are locked/logged off when unattended, to reduce unauthorised access, loss and damage during and outside working hours.
Why should delivery and loading areas be controlled and ideally isolated from information-processing facilities?
To prevent unauthorised persons gaining entry through goods-handling points; incoming and outgoing material should be inspected and registered, and external delivery staff kept separate from secure processing areas.
Name three common physical intrusion-detection or deterrent controls for secure areas.
Examples include intruder alarms/motion detectors, CCTV surveillance, security lighting, guards/patrols, fences and gates, and door/window contact sensors.
What is the security concern with placing critical equipment near windows or in ground-floor/public-facing rooms?
It increases exposure to theft, vandalism, eavesdropping/shoulder-surfing, and environmental threats; sensitive equipment should be sited to reduce the risk of unauthorised viewing and physical attack.
In equipment security, what is the difference between protecting against 'theft' and protecting against 'interruption of service'?
Anti-theft controls (locks, cable tethers, asset tags, secure cabinets) protect confidentiality and asset value; service-continuity controls (UPS, redundant power, environmental controls) protect availability by keeping equipment operating.
What does a UPS provide and what is its primary security objective?
An Uninterruptible Power Supply provides short-term battery power during a mains failure, primarily to support availability — allowing equipment to keep running or to shut down gracefully without data loss until generators or mains are restored.
What is the role of a standby generator versus a UPS in power resilience?
A UPS bridges the gap for seconds to minutes during outages and conditions power, while a generator supplies sustained power for longer outages. They are typically used together: UPS covers the start-up delay until the generator comes online.
What is 'cable security' and why does it matter?
Protecting power and telecommunications cabling from interception, interference and damage — e.g. using conduit, avoiding public routes, segregating power and data cables, and shielding to prevent eavesdropping and accidental/deliberate disruption.
Why must equipment removed from site or used off-premises still be protected, and what is the main risk?
Off-site equipment (laptops, mobile devices) leaves the protection of the secure perimeter and is exposed to theft and loss; the main risk is exposure of data, so encryption, authentication and physical care are required.
What environmental conditions must data-centre controls typically manage?
Temperature and humidity (via HVAC/air conditioning), dust/contaminants, fire, water/flood, and power quality — to keep equipment within safe operating ranges and prevent damage or failure.
Why is humidity control important in equipment rooms, considering both extremes?
Too low humidity increases the risk of static electricity (ESD) damaging components; too high humidity promotes condensation and corrosion. Humidity is kept within a controlled band to protect equipment.
What is the preferred type of fire-suppression system for a server room and why?
A gaseous (inert/clean-agent) suppression system (e.g. inert gas or chemical agents that displace oxygen or interrupt combustion) is preferred because it extinguishes fire without the water damage that sprinklers would cause to electronics.
What is the difference between 'detective' and 'suppressive' fire controls?
Detective controls (smoke/heat detectors, VESDA aspirating detection) sense a fire and raise the alarm; suppressive controls (gas systems, sprinklers, extinguishers) act to put the fire out.
Define 'asset' in the context of information security asset management.
Anything of value to the organisation that needs protection — including information, software, physical equipment, services, people and intangibles such as reputation.
What is the purpose of maintaining an asset inventory/register?
To identify and record all assets, their owners and their value so that appropriate protection can be assigned and accountability maintained throughout the asset's lifecycle.
What is the role of an 'asset owner' (information owner)?
The individual or role accountable for an asset throughout its lifecycle — responsible for its classification, defining and reviewing access restrictions, and ensuring it is appropriately protected (though day-to-day handling may be delegated).
What is the purpose of an information classification scheme?
To indicate the value, sensitivity and criticality of information so that a consistent, proportionate level of protection (handling, storage, transmission, disposal) can be applied according to the level assigned.
What are the four labels commonly used in a UK government-style information classification model?
In the current UK scheme: OFFICIAL, SECRET and TOP SECRET (with OFFICIAL-SENSITIVE as a handling caveat). Many commercial schemes instead use Public, Internal, Confidential and Restricted/Highly Confidential.
On what three security properties is information typically classified for impact?
Confidentiality, Integrity and Availability — the potential business impact of a breach of each property determines the appropriate classification level.
What is the difference between 'classification' and 'labelling' of information?
Classification is the process of determining the sensitivity level of information; labelling is marking the asset (physically or in metadata) with that classification so handlers know how to treat it.
What are 'standard operating procedures' (operating procedures) and why should they be documented?
Documented step-by-step instructions for routine operational activities (e.g. start-up/shutdown, backup, system handling). Documenting them ensures consistency, reduces error, supports availability, and enables others to perform tasks correctly.
See more Physical, Environmental and Operational Security flashcards →
Planning Physical, Environmental and Operational Security for CISMP (Certificate in Information Security Management Principles)
Physical, Environmental and Operational Security is about 12% of the CISMP (Certificate in Information Security Management Principles) syllabus by topic count — 10 of 81 topics, spread over 3 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 10 hours.
The heaviest chapters are Operational Security and Asset Management (4 topics), Physical and Environmental Security (3 topics), Security Monitoring and Vulnerability Management (3 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.
Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.
Physical, Environmental and Operational Security (CISMP (Certificate in Information Security Management Principles)) FAQ
What is in the CISMP (Certificate in Information Security Management Principles) Physical, Environmental and Operational Security syllabus?
Physical, Environmental and Operational Security is split into 3 chapters — Physical and Environmental Security, Operational Security and Asset Management and Security Monitoring and Vulnerability Management, containing 10 topics and 14 sub-topics in total.
How many chapters are there in Physical, Environmental and Operational Security for CISMP (Certificate in Information Security Management Principles)?
3 chapters. Physical, Environmental and Operational Security accounts for about 12% of the topics in the whole CISMP (Certificate in Information Security Management Principles) syllabus (10 of 81).
How long should I spend on Physical, Environmental and Operational Security for CISMP (Certificate in Information Security Management Principles)?
Budget around 10 hours for a first pass through Physical, Environmental and Operational Security — about 45 minutes per topic plus 12 minutes per sub-topic across its 10 topics. Add revision cycles on top.
Are there flashcards for CISMP (Certificate in Information Security Management Principles) Physical, Environmental and Operational Security?
Yes — a 51-card Physical, Environmental and Operational Security deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.