Physical and Environmental Security Standard (SFA 06-107.3.1)

Summary

Requirements for physically protecting SFA's facilities and equipment, including physical access controls, visitor controls, environmental protections, and data-center facility requirements; supports Policy 06-107.3.

Body

Quick Overview
  • This standard sets the specific requirements for keeping SFA's IT facilities (data centers, server rooms, network closets, and similar spaces) physically safe and protected from environmental hazards.
  • It carries out the goals in the SFA 06-107.3 Information Security Physical & Environmental Policy.
  • Most requirements are carried out by the people who secure and maintain facilities (security and facilities staff, system administrators, and building technicians), not by general users.
  • Anyone who works in, visits, or is escorted through an SFA IT facility (including vendors and contractors) must follow these rules.
  • These requirements are the minimum baseline SFA must meet; the university may choose to do more.
  • Meeting this standard is mandatory unless a formal exception is granted.

Physical and environmental security is about protecting the actual rooms, buildings, and equipment that hold SFA's information systems and data. Even the best cybersecurity does not help if someone can walk into a server room, or if a power failure, fire, or flood damages the hardware. This standard spells out what SFA must do to control who gets into IT facilities, keep records of that access, watch for intruders, protect equipment from power and environmental problems, and manage visitors and the movement of critical assets.

i
Policy vs. Standard
The matching policy (06-107.3) says what SFA wants to achieve. This standard says how, the concrete requirements. Day-to-day steps live in procedures.

Who This Applies To

This standard applies to all SFA employees, users, third-party service providers, research partners, and other authorized users of SFA information resources. In particular, anyone who works within an SFA IT facility, including authorized vendors, visitors, and contingent workers, must follow this standard. In practice, the requirements below are carried out mostly by the people who secure and maintain those facilities: security and facilities staff, system administrators, and building engineers.

i
Baseline, not a ceiling
Everything here is the minimum SFA must do. Departments may add stricter requirements, but never anything weaker. See the SFA 06-107 Controls Crosswalk for higher control tiers.

Who Is Responsible

Key roles & responsibilities ⌄
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person.
  • Chief Information Security Officer (CISO): Implements, enforces, and monitors physical and environmental security controls at IT facilities in partnership with Physical Security Managers, and coordinates with Facility Managers on security assessments and control reviews.
  • Physical Security Managers: Oversee how physical and environmental controls are put in place and enforced at IT facilities, including access control, security training, and compliance monitoring.
  • Facility Managers: Manage the physical security of buildings, equipment, and other physical resources, including critical deliveries, periodic assessments, and access-control reviews.
  • System Administrators: Make sure access controls, backups, and environmental controls are in place and working for the systems inside IT facilities.
  • Security Guards / Maintenance Employees: Carry out controls on the ground at access points, respond to alarms, and manage visitor access.
  • Building Engineers or Technicians: Install, maintain, and repair physical security systems (alarms, cameras, gates, lighting) and help assess and address physical threats.
Full role definitions Complete responsibilities for each role are in the attached standard PDF. Italicized terms are defined in the SFA 06-107 Definitions.

What This Standard Requires

The requirements are grouped into five areas. Expand any area for a plain-language summary of what it requires. The official requirement numbers (like 06-107.3.1.1.1) are shown so you can match them to the attached PDF.

1  Physical Security Protections  The written protections for facilities ⌄

SFA must have written procedures that protect IT facilities against break-ins, theft, fire, flood, and other hazards.

  • Define and put in place procedures for the physical protections at IT facilities, covering how access is authorized and credentials are managed, how physical access is logged, and a documented review and update of those procedures at least once every 12 months (06-107.3.1.1.1).
2  Physical Access Control  Who gets in, and keeping the record ⌄

Only authorized people should be able to enter IT facilities, and every entry must be recorded, reviewed, and monitored.

  • Restrict physical access to IT facilities to authorized users only, verified through credentials such as access profiles, physical badges, biometrics (fingerprint, facial recognition), enrolled personal smartphones, or other smart credentials (06-107.3.1.2.1).
  • Log every entry into IT facilities, including failed attempts, using physical logs, electronic logs, or another system of record (06-107.3.1.2.2).
  • Review physical entry logs at least once per calendar month to confirm access is appropriate, spot improper access, and fix any problems or security incidents found (06-107.3.1.2.3).
  • Inspect physical access protections (access cards, keys, locks, and similar systems) at least once every 12 months to confirm they still work and facilities remain secured (06-107.3.1.2.4).
  • Control access at the room or enclosure level for spaces holding institution systems or Confidential Data, using physical barriers such as locked cabinets, cages, or secured rooms (06-107.3.1.2.5).
  • Monitor physical access with intrusion alarms and surveillance (cameras, monitored entry sensors), watching specific high-value spaces such as data centers and network closets in addition to the facility as a whole (06-107.3.1.2.6).
3  Physical Security Incidents & Visitor Controls  Handling events & managing visitors ⌄

SFA must respond to physical and environmental events at facilities and keep careful, privacy-conscious records of visitors.

  • Monitor, identify, and respond to security incidents or environmental events at IT facilities following SFA's incident management procedures (06-107.3.1.3.1).
  • Obtain and record every visitor's signature in a physical or electronic log before granting access, and retain those logs in line with SFA retention requirements and risk (06-107.3.1.3.2).
  • Collect only the minimum visitor information needed (name, affiliation, SFA escort or host, purpose of visit, entry and exit date and time, and which system, facility, or area was accessed) to limit the handling of Personally Identifiable Information (PII) (06-107.3.1.3.3).
  • Maintain visitor access records for facilities housing information systems using automated mechanisms, and review them at defined intervals for anomalies (06-107.3.1.3.4).
4  Environmental Controls  Power, fire, heat & emergencies ⌄

IT facilities must be protected against power failures, fire, heat, humidity, and other environmental threats.

  • Provide emergency protections and backups, at a minimum automatic emergency lighting for exits and evacuation routes, an emergency power system or backup generator, an independent energy source (such as a microgrid), separate entry and exit points, and fire detection systems (06-107.3.1.4.1).
  • Protect equipment where power is unstable or static electricity is excessive, using surge protection devices, filtered power when available, and anti-static sprays, pads, or similar devices (06-107.3.1.4.2).
  • Define and implement emergency operating procedures for facility emergencies, including emergency power or valve shutoff, contacting the right emergency staff and groups, and emergency access restrictions (06-107.3.1.4.3).
  • Establish environmental protections such as heat and humidity alarms, fire suppression and detection on an independent energy source, and uninterruptable power systems (UPS), monitoring the environment regularly and reviewing or updating these protections at least once every 12 months (06-107.3.1.4.4).
  • Provide fire suppression systems for facilities housing information systems that activate automatically on fire detection and automatically notify SFA and emergency responders (06-107.3.1.4.5).
5  Facilities Requirements  Tracking & protecting equipment ⌄

SFA must control the movement of critical equipment, secure alternate work sites, and physically protect hardware and cabling.

  • Define and implement a process to authorize, control, and keep records of critical assets and system components entering and exiting IT facilities at designated entry and exit points (06-107.3.1.5.1).
  • Identify and document approved alternate work sites, apply security controls equal to those at the main site, assess how well those controls work, and give employees a way to reach information security and privacy staff about incidents (06-107.3.1.5.2).
  • Use asset tracking or location technologies to monitor the movement of critical system assets between IT facilities, where technically feasible (06-107.3.1.5.3).
  • Secure assets inside controlled environments using protections that match their value, such as secured rooms, locked enclosures, and cable locks (06-107.3.1.5.4).
  • Protect power equipment and cabling that serve information systems from damage and destruction (through physical protection, redundancy, and separating power from communications cabling) in proportion to how critical the systems are (06-107.3.1.5.5).

Conformance & Exceptions

Meeting this standard is mandatory and effective as of the standard's publication, unless a written contract says otherwise or a formal exception has been granted. If a requirement genuinely cannot be met and there is no feasible remediation, follow the exception process in the SFA 06-107.3 Information Security Physical & Environmental Policy; requests go to the SFA Chief Information Security Officer (CISO).

!
Important
Violations of SFA 06-107 may lead to disciplinary action, up to and including involuntary separation from employment.

Compliance Mapping (Reference)

For auditors and security staff. Everyday users can skip this section unless you need control references.

Frameworks & control references ⌄

The requirements in this standard map to one or more of these authoritative sources:

  • NIST 800-53 Rev 5.1.1, mainly the PE (Physical and Environmental Protection) control family, for example PE-2, PE-3, PE-5, PE-6, PE-8, PE-9, PE-11 through PE-17, and PE-20.
  • Texas DIR Security Controls Catalog, the matching PE controls (for example PE-2, PE-3, PE-6, PE-8, PE-13, PE-14, PE-16, PE-17).
  • NIST CSF, for example PR.AA-01, PR.AA-06, PR.IR-02, and DE.CM-02.
  • NIST 800-171, the 3.10.x physical protection requirements.
  • HIPAA physical safeguards (45 CFR 164.310).
  • UTS 165, sections 16.2 and 16.3, where cited.

The full requirement-by-requirement control mapping is in the attached standard PDF and the SFA 06-107 Controls Crosswalk.

Related Policies & Standards

Supporting policy: SFA 06-107.3 Information Security Physical & Environmental Policy

Related standards:

Other references:

  • UT System Incident Tracking Tool
  • SFA 06-107 Controls Crosswalk Reference · SFA 06-107 Definitions

Responsible office: Office of Information Security  ·  Contact: itsecurity@sfasu.edu

📎
Official document
The complete, official standard is attached to this article as a PDF, including its full requirement text, role definitions, and control mappings. This article summarizes that standard in plain language. If anything in this article conflicts with the attached PDF, the PDF is the official version and takes precedence.

Need Help?

Contact the IT Help Desk at (936) 468-4357 (HELP) or submit a ticket at help.sfasu.edu. For questions about this standard, contact the Office of Information Security at itsecurity@sfasu.edu.

Details

Details

Article ID: 173936
Created
Thu 7/16/26 2:30 PM
Modified
Fri 7/17/26 12:18 PM

Related Articles

Related Articles (2)

Sets SFA's objectives for protecting the facilities, equipment, and environmental controls that support its information systems; carried out by the Physical and Environmental Security Standard (06-107.3.1).
Definitions of the key terms used throughout the SFA 06-107 information security program; any term shown in italics in a policy or standard is defined here.