AP® Cybersecurity › Unit 2: Securing Spaces
Topic 2.3
Protecting Physical Spaces
Physical security uses people, procedures, technology, and facility design to protect individuals, equipment, systems, networks, documents, and buildings. It supports cybersecurity by controlling who can reach the physical components that store, process, transmit, or display information.
Physical security as defense in depth
Defense in depth places different controls between a threat and an asset. Each layer may deter, detect, delay, deny, support response, or help recovery. No single fence, badge, lock, camera, or guard should be treated as perfect.
- Site perimeter Property boundaries, fencing, gates, vehicle controls, lighting, and visible signs define where public access ends.
- Building entrance Doors, locks, reception, badges, visitor procedures, alarms, and cameras manage entry into the facility.
- Internal restricted zone Role-based doors, escorts, monitored corridors, cages, and room-level controls protect higher-value areas.
- Asset-level protection Device locks, secure cabinets, encryption, screen locks, privacy filters, tamper evidence, and backups protect individual assets.
Physical security must preserve life safety
Security controls must comply with fire, accessibility, emergency-exit, building, privacy, and other applicable requirements. A locked or monitored space must still allow safe evacuation and authorized emergency response.
How physical security supports digital cybersecurity
Limits observation and access
Restricted rooms, privacy screens, locked storage, clean desks, and secure disposal reduce unauthorized disclosure.
Discourages unauthorized change
Controlled access, tamper evidence, surveillance, inventories, and maintenance records help protect hardware and configurations.
Protects continued operation
Fire controls, cooling, backup power, water protection, secure equipment, disaster planning, and tested recovery reduce disruption.
Perimeter security and secure entry points
| Control | Primary purpose | Important limitation | Supporting layer |
|---|---|---|---|
| Fencing and boundaries | Define controlled property and guide people toward approved entrances. | A boundary can be crossed or damaged and needs inspection. | Lighting, cameras, patrols, signs, and response procedures |
| Gates | Control pedestrian or vehicle entry at designated points. | Open, unattended, or malfunctioning gates weaken the boundary. | Staffing, credentials, intercoms, alarms, and logs |
| Doors and locks | Deny or delay entry to buildings, rooms, cabinets, and cages. | Keys can be lost, doors can be propped, and hardware can fail. | Door-position sensors, access logs, inspections, and key control |
| Windows | Support visibility and building use while maintaining the envelope. | Unlocked, open, or easily damaged windows may bypass door controls. | Locks, alarms, appropriate materials, placement, and inspections |
| Secure entry layout | Direct people to reception, screening, credential checks, or controlled routes. | Poor signage or confusing routes may encourage accidental bypass. | Clear procedures, trained staff, accessible design, and visitor communication |
Secure the normal route
People are more likely to follow access procedures when entrances are clearly marked, accessible, staffed as expected, and convenient for legitimate use. Security design should support correct behavior rather than depending only on warnings.
Identification, authentication, and role-based access
Physical access control should answer three questions: Who is requesting entry? Is the identity claim valid? Is that person authorized for this space at this time?
Visible identification
Photo badges help staff recognize roles and identify people who may need assistance. Badges should be individual, current, visibly worn where policy requires, and reported immediately if lost.
Electronic authorization
Cards or mobile credentials can limit doors, times, and zones while creating logs. They can still be lost, shared, stolen, copied, or misused and should be reviewed and revoked promptly.
Something known
PINs and door codes can support authentication but may be observed or shared. Individual credentials, code-change procedures, shielding, and monitoring reduce risk.
Something inherent
Biometric systems measure a physical or behavioral characteristic. Organizations must consider accuracy, accessibility, privacy, retention, fallback access, and the fact that biometric traits are difficult to replace if compromised.
Only the access needed
A student may enter a supervised lab but not the network closet. A technician may enter a server room for approved work without receiving permanent access to every records area.
Permissions tied to duties
Standard access profiles can be assigned to roles such as student, teacher, receptionist, facilities technician, security officer, contractor, or visitor, then reviewed when roles change.
Two factors can protect high-risk spaces
A restricted room may require two different forms of evidence, such as an individual card plus a code or biometric check. Multifactor access reduces reliance on one credential, but privacy, emergency access, maintenance, and failure procedures still matter.
Guards, reception, visitors, surveillance, and alarms
People-centered controls
- Security guards observe, assist, verify, patrol, and coordinate response.
- Reception staff confirm appointments and connect visitors with hosts.
- Visitor records document identity, host, purpose, arrival, and departure.
- Temporary badges clearly differ from regular employee credentials.
- Escorts and approved routes limit movement through sensitive areas.
- Training explains how to report suspicious access without unsafe confrontation.
Detection and deterrence controls
- Cameras support observation and investigation in appropriately chosen areas.
- Intrusion and door alarms signal unexpected entry or an open controlled door.
- Lighting improves visibility and can discourage hidden activity.
- Motion sensors can identify movement in selected areas or times.
- Intercoms provide a controlled way to communicate before entry.
- Logs connect credential use, alarms, and response events for review.
| Visitor-management stage | Good practice | Reason |
|---|---|---|
| Before arrival | Confirm the host, purpose, time, required access, and any safety or accessibility needs. | Reduces uncertainty and unnecessary access. |
| Check-in | Verify identity as policy requires, record the visit, explain rules, and issue a temporary badge. | Creates accountability and makes authorized visitors recognizable. |
| During visit | Limit access to approved areas and provide an escort where required. | Supports least privilege and prevents accidental entry. |
| Departure | Record sign-out and collect temporary credentials, keys, or equipment. | Closes access and keeps inventories accurate. |
| Review | Investigate missing badges, policy exceptions, unusual routes, or alerts. | Finds gaps and supports improvement. |
Monitoring needs privacy rules
Camera and sensor placement, notice, access to recordings, retention, audit, and acceptable use should follow law and policy. Monitoring should serve a defined security purpose and avoid areas where people reasonably expect privacy.
Restricted areas, server rooms, and asset-level controls
Controlled interlocking space
A mantrap or security vestibule uses two controlled doors so entry can be checked in a small intermediate area. Design must address emergency egress, accessibility, safety, staffing, and failure modes.
High-value restricted zone
Individual credentials, access logs, cameras where appropriate, environmental monitoring, fire protection, cable management, and limited maintenance access protect critical equipment.
Separation within a shared space
Locked cages or cabinets add a boundary around selected hardware or media. Their keys, doors, inventory, and access records still require management.
Protecting local access
Screen locks and device authentication reduce misuse of unattended sessions. Automatic timeouts support users but do not replace the habit of locking before walking away.
Deterrence and delay
A cable lock can make quick theft more difficult in an appropriate setting, but it does not protect data by itself and can be defeated. Encryption, inventory, and secure storage remain important.
Reducing visual exposure
A privacy filter narrows viewing angles and can reduce casual observation. Screen positioning, user awareness, document handling, and avoiding sensitive work in public remain necessary.
Secure storage and information handling
Clean-desk and clear-screen practices
- Store sensitive papers, badges, keys, and removable media when unattended.
- Lock screens before leaving a device.
- Remove passwords and sensitive details from visible notes and whiteboards.
- Collect printouts promptly and verify recipients before sharing.
- Keep server, network, cabinet, and recovery keys under controlled custody.
Secure disposal
- Classify information before choosing a disposal method.
- Use approved locked containers for sensitive paper awaiting destruction.
- Sanitize digital media through the organization’s approved program.
- Maintain custody and records for media sent to an authorized disposal provider.
- Verify destruction or sanitization when policy requires evidence.
Environmental controls and disaster preparedness
Physical protection includes keeping equipment within safe environmental conditions and preparing for events that can interrupt essential services.
| Hazard | Possible impact | Protective measures | Preparation and recovery |
|---|---|---|---|
| Fire and smoke | Injury, equipment damage, data loss, and extended outage | Detection, alarms, safe suppression designed for the space, separation, and maintained equipment | Evacuation, emergency contacts, off-site backups, alternate operations, and recovery testing |
| Water | Electrical danger, corrosion, equipment failure, and media damage | Leak sensors, appropriate equipment placement, drainage, known shutoffs, and inspections | Safe isolation, incident procedures, backup systems, and restoration planning |
| Temperature and humidity | Overheating, condensation, static, shortened life, or shutdown | Maintained cooling, airflow, sensors, alarms, and acceptable operating ranges | Escalation thresholds, capacity planning, alternate cooling, and safe shutdown procedures |
| Power failure or surge | Service interruption, damaged hardware, or corrupted data | Surge protection, uninterruptible power supply (UPS), power conditioning, and backup generation where justified | Load priorities, fuel and maintenance plans, safe shutdown, recovery testing, and alternate sites |
| Dust and contamination | Blocked airflow, overheating, corrosion, and component damage | Filters, cleaning, enclosures, controlled work practices, and inspection | Maintenance schedules, spare parts, monitoring, and incident documentation |
Different tools, different durations
A UPS may bridge a short interruption or allow safe shutdown. A generator or alternate source may support a longer outage. Capacity, transfer, maintenance, fuel, ventilation, safety, and testing determine whether the system will work when needed.
Match the occupied space and hazard
Suppression must be professionally designed for people, equipment, building requirements, and the expected type of fire. Detection, evacuation, notification, maintenance, and recovery remain separate layers.
Preparedness turns controls into capability
Documented roles, emergency communication, current contact lists, evacuation and shelter procedures, alternate work locations, tested backups, supply arrangements, and exercises help an organization respond when preventive controls are not enough.
Real-world layered security examples
Student records office
Reception manages visitors, staff badges limit entry, privacy screens protect displays, cabinets secure paper, screens lock automatically, and sensitive waste enters a controlled disposal process.
Shared workplace
Building access, staffed reception, visitor badges, role-based floors, clean desks, secure print release, cable locks for selected devices, and after-hours alarms protect different layers.
Critical equipment
Perimeter controls, controlled entry, a security vestibule, individual credentials, equipment cages, cameras, environmental sensors, backup power, fire controls, and off-site recovery reduce different risks.
Library computer area
Public and staff zones are clearly separated, networking equipment is locked, screens time out, sight lines are considered, cameras cover appropriate public areas, and staff know how to report device tampering.
Limited maintenance access
The closet remains locked, access is role-based and logged, visits match work orders, cables and devices are inventoried, alerts report door conditions, and configurations are backed up.
Confidential materials
A restricted room, limited authorized roles, dual custody for selected actions, access records, sealed storage, inventory checks, and secure disposal protect confidentiality and integrity.
AP-style analysis
For each space, identify the asset, threat, vulnerability, preventive, detective, and recovery controls, effect on confidentiality, integrity, or availability, and the residual risk.
Watch: protecting physical spaces
As you watch, identify each security zone and decide whether a control mainly deters, detects, delays, denies, supports response, or supports recovery.
Interactive knowledge check
Build the Security Layers
Complete all ten questions, check your score, and review the explanation for every answer. The quiz runs in your browser and does not collect personal information.
What the quiz covers
- Perimeters, doors, credentials, reception, visitors, surveillance, and alarms
- Restricted areas, mantraps, server rooms, equipment cages, and device protection
- Clean desks, privacy screens, secure storage, and document disposal
- Environmental controls, backup power, least privilege, and defense in depth
AP® Cybersecurity study support
Access zone
An area with defined entry requirements based on its people, activities, and assets.
Defense in depth
Multiple complementary controls placed across different security layers.
Environmental monitoring
Measurement and alerting for conditions such as heat, humidity, water, smoke, or power.
Mantrap
A controlled intermediate space between two access doors.
Role-based physical access
Entry permissions assigned according to job or activity requirements.
Visitor management
Processes for verifying, recording, limiting, monitoring, and ending visitor access.
Continue your study
Physical protection works with encryption and secure computing practices. Review how cryptography protects digital information, explore broader computer science study materials, or organize your revision using the guide to self-studying for an AP exam.
Trusted defensive references
Frequently asked questions
1. What is physical security?
Physical security uses facility design, people, procedures, and technology to protect individuals, buildings, devices, systems, infrastructure, documents, and other assets from unauthorized access, damage, theft, or disruption.
2. How does physical security support digital cybersecurity?
It controls access to devices, screens, cables, servers, storage media, backups, and network equipment that store, process, display, or transmit information.
3. Are badges and access cards enough to secure a building?
No. Credentials should be combined with visitor procedures, door controls, monitoring, access reviews, prompt revocation, user awareness, and response processes.
4. What are the advantages and limitations of biometric access?
Biometrics can provide evidence tied to a physical characteristic, but systems must address error rates, accessibility, privacy, retention, fallback access, and the difficulty of replacing compromised biometric traits.
5. What does a security guard or reception desk contribute?
Trained personnel can observe context, verify visitors and hosts, assist users, manage exceptions, patrol, interpret alerts, and coordinate an appropriate response.
6. What is a mantrap or security vestibule?
It is a controlled intermediate space between two access doors where identity and authorization can be checked. Its design must preserve emergency egress, accessibility, and safety.
7. What is the purpose of a clean-desk policy?
It reduces visual exposure, loss, and unauthorized access by requiring sensitive documents, media, keys, badges, and credentials to be secured when unattended.
8. How do environmental controls protect cybersecurity?
Fire detection, water protection, cooling, humidity control, filtration, alarms, surge protection, and backup power protect equipment and service availability from physical hazards.
9. What is role-based physical access?
It grants access to spaces according to assigned duties. Permissions should follow least privilege, be time-limited where appropriate, and be reviewed when roles change.
10. Why is defense in depth important for physical spaces?
Different controls deter, detect, delay, deny, support response, and support recovery. If one layer fails, other layers can still protect people and assets or reduce the impact.
AP® is a registered trademark of the College Board, which is not affiliated with and does not endorse this independent educational resource.





