Information Security Standard for IT Facility Physical Access (ISS-4)
Published: August 1, 2026
Compliance Required: November 1, 2026
Per the procedures defined in the , this Information Security Standard ("ISS") for IT Facility Physical Access has been published by ÌÇÐÄVlog or its subsidiaries or affiliates ("Drexel") to better protect Drexel information.
1. Purpose and Scope
This Standard establishes baseline physical‑access requirements for all university IT facilities (e.g., server rooms, data centers, telecommunications rooms). It defines the minimum controls for granting, using, monitoring, and reviewing physical access in accordance with NIST SP 800‑171 Rev. 3‑aligned practices.
This Standard is intended to serve as a campus‑wide minimum. Individual facilities and business units may implement more restrictive controls based on risk, regulatory requirements, or operational needs.
2. Applicability
These requirements apply to faculty, staff, students, contractors, vendors, and visitors who request or exercise physical access to IT Facility.
Areas of applicability include, but are not limited to:
- Access control systems (badges, keys, card readers)
- Video monitoring
- Visitor sign‑in/sign‑out procedures
- Access roster management and review
3. Definitions
Authorized User
An individual granted access based on job function and current need‑to‑access. Authorized Users are not visitors.
Facility Owner
The executive unit or authority accountable for the IT Facility, including risk acceptance, funding, and approval of access governance.
Facility Operator
The department or unit responsible for day‑to‑day operation of the IT Facility, including access administration, monitoring, and record keeping.
Facility Manager
The designated administrative or IT authority within a business unit responsible for validating need‑to‑access for personnel associated with that unit’s facilities or equipment. Each business unit with server rooms or data centers defines this role internally.
Guest Sponsor
An Authorized User whose access has been approved by the Facility Manager or Facility Operator and who is permitted to escort and sponsor visitors for approved purposes.
Visitor
Any non-Authorized User who is present in an IT Facility. Visitors must be escorted continuously by Authorized User(s) while in IT Facilities.
4. Facility Risk Tiers
Facilities are categorized to allow proportional application of controls:
Tier 1 – High Risk
IT Facilities hosting mission‑critical systems or transmitting or processing regulated or restricted information.
Tier 2 – Medium Risk
IT Facilities hosting departmental or business‑unit systems or transmitting or processing unregulated or unrestricted information.
Tier 3 – Low Risk
IT Facilities hosting systems or transmitting or processing only public information.
Risk tier assignments are made by the Facility Owner and are subject to review and final determination by Information Security. Facility Operators are responsible for documenting the assigned tier and applying the corresponding minimum controls defined in this Standard.
5. Roles and Responsibilities
Facility Owner
- Approves access governance and risk acceptance
- Authorizes exceptions to this Standard
Facility Operator
- Maintains door controls, monitoring, visitor logging, and access rosters
- Defines facility‑specific procedures consistent with this Standard
- Performs and documents access reviews
Facility Manager
- Validates need‑to‑access for individuals associated with the facility or business unit
- Approves access requests for personnel under their authority
- Participates in access recertification
Public Safety
- Operates campus access control and video systems
- Processes credential issuance, revocation, and replacement
Authorized Users / Guest Sponsors
- Comply with this Standard
- Prevent tailgating and door propping
- Escort visitors continuously
- Report lost or stolen credentials immediately
6. Requirements
6.1 Least Privilege and Access Scope
- Access is granted only to areas and time windows necessary for job function.
- Tailgating, piggybacking, door propping, or bypassing access controls is prohibited.
- Off‑hours access requirements (e.g., notification or two‑person presence) are defined by facility tier and Facility Operator policy.
6.2 Access Requests and Approval
- All access requests must be documented and approved by the requester’s Facility Manager.
- Facility Operators implement access only after approval and record the authorization.
- Facility Owners retain authority to deny or revoke access based on risk or operational concerns.
6.3 Visitor Management
- All visitors must sign in and out with name, organization, purpose, and timestamps.
- Visitors must be escorted continuously by a Guest Sponsor.
- Facilities may require visitor badges or visible identification based on facility tier.
- Visitor logs are retained for a minimum of 90 days.
Visitor logs are reviewed to confirm completeness and to identify anomalies (e.g., missing sign‑out, unusual access times).
6.4 Monitoring and Audit
- Access events are recorded via campus access control and video systems operated by Public Safety. (Required for Tier 1 facilities, recommended for Tier 2, optional for Tier 3.)
- Logs and recordings are used for incident response, security assessments, and periodic spot checks.
- Retention follows Public Safety and institutional policy; extended retention may be authorized for investigations.
Facility Operators must be able to produce, upon reasonable notice:
- Current access rosters
- Evidence of access recertification
- Visitor logs for the prior 90 days
- Documentation of periodic reviews
6.5 Access Device Control
- Access to IT Facilities is permitted only via officially supported entry mechanisms issued or authorized by the University (e.g., university‑issued identification cards, keys, lock combinations, or other institutionally approved methods).
- Identification mechanisms may be used only by the person to whom they were issued.
- Use of unofficial, modified, cloned, duplicated, or shared access mechanisms is strictly prohibited.
- Badges, keys, lock combinations, and readers are managed by Public Safety and the Facility Operator.
- Compromised entry mechanisms must be reported immediately and replaced as soon as practicable.
- Lost or stolen credentials (e.g., identification cards) must be reported immediately and are disabled upon request.
Access Recertification (Minimum):
- Tier 1: Quarterly
- Tier 2: Semi‑annual
- Tier 3: Annual
6.6 Conduct in IT Facilities
- Food and drink are prohibited.
- Photography or recording is permitted only for legitimate operational purposes (e.g., support, inventory, incident documentation) and is limited to equipment authorized by the Facility Operator.
- Posted safety and ESD precautions must be followed.
6.7 Training
Authorized Users must complete required access training prior to activation of credentials. Training content and delivery mechanisms are defined by the Facility Operator and Information Security and may be updated over time.
This Standard assumes the existence of such training and does not prescribe specific course content.
6.8 Incident Reporting and Enforcement
- Suspected unauthorized access or safety incidents must be reported immediately to the Facility Operator and Public Safety.
- Violations may result in suspension or revocation of access and corrective action per institutional policy.
7. Exceptions
Exceptions require documented risk acceptance by the Facility Owner and Information Security, including compensating controls and expiration dates.
Facility Owner may implement temporary exceptions to address exigent circumstances (e.g., flooding, loss of cooling, etc.). These must be submitted to the Responsible Executive (or designee) within five business days for review and must be reverted if not approved.
8. References
- NIST SP 800‑171 Rev. 3 – Physical & Environmental Protection
- NIST SP 800‑171 Rev. 2 – 3.10.x Physical Protection Requirements
- DoD CIO – CMMC Resources and Documentation
9. Revision History
- v1.0 – August 1, 2026 – Initial issuance as ISS-4
10. Violations
Any violation of this Information Security Standard by any Applicable Member shall be construed as a violation of the Information Security for Institutional Information Policy (IT-8) and may result in disciplinary action up to and including termination.