2ilent8cho Posted October 6, 2016 Posted October 6, 2016 Are there any UK laws with regard to keeping servers physically secure? At a primary we support the server is currently kept in a locked cupboard. They want to move it, and some of the places suggested would not be as secure as it was before, like a staff photocopier room.
pcstru Posted October 6, 2016 Posted October 6, 2016 Are there any UK laws with regard to keeping servers physically secure? At a primary we support the server is currently kept in a locked cupboard. They want to move it, and some of the places suggested would not be as secure as it was before, like a staff photocopier room. DPA says you must protect data by "appropriate technical and organisational measures", so if the server is hosting any personal data it should be physically secure to stop someone just unplugging and wandering off with it.
6Foot2 Posted October 6, 2016 Posted October 6, 2016 Our server room is at the first-floor level and behind three doors (fully contained within the reprographics room) This arrangement is something I inherited.
aleach2 Posted October 6, 2016 Posted October 6, 2016 I have my servers in a dedicated room with limited access to staff with keys: my department, Site team and bursar. Within the room all IT equipment are secured in locked server cabinets which are only accessible by the IT support department.
fiza Posted October 6, 2016 Posted October 6, 2016 The Server for our Primary sits in the IT Suite. It always has done since before we started looking after the School. There is no other space for it that could be locked with limited access.
localzuk Posted October 6, 2016 Posted October 6, 2016 (edited) ICO advice on the topic of data security can be found here - https://ico.org.uk/for-organisations/guide-to-data-protection/principle-7-security/ So, yes, there is a UK law that covers this. Remember the simple rule of security for computers - physical access is total access. Edited October 6, 2016 by localzuk
forkies Posted October 6, 2016 Posted October 6, 2016 As said above, ICO under the DPA states it should have "appropriate" levels of security including physical security. Ours are in a secure room with bars across all windows, frosted glass and double deadlock security door that only myself and senior tech have keys for. Server cabinets are also locked and under alarm. Hopefully new server room soon, near our new office which will be of same level security but with added access control ontop to provide auditing.
strawberry Posted October 6, 2016 Posted October 6, 2016 I'm not 100% on the law but I work on the basis that access should be on a needs only basis and should be supervised where possible. Our server room has a combo lock so it locks behind us and the code is only known by me, the caretaker who fitted it and the bursar. The room has cctv both sides of the door and the windows are blurred.
Garacesh Posted October 11, 2016 Posted October 11, 2016 I'm not 100% on the law but I work on the basis that access should be on a needs only basis and should be supervised where possible. Our server room has a combo lock so it locks behind us and the code is only known by me, the caretaker who fitted it and the bursar. The room has cctv both sides of the door and the windows are blurred. This. 2FA is the way to go. Something you own (Physical key), something you know (Lock code) Bonus points for not putting your server room on the same pin combo as the rest of the school. If you want to be really paranoid thorough, more bonus points for pointing CCTV at the door, or using some kind of magnetic latch to send an alert when the door is opened. I'd expect this would pass any checks for security ever thrown at the school.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now