CAS-002 · Question #613
An intruder was recently discovered inside the data center, a highly sensitive area. To gain access, the intruder circumvented numerous layers of physical and electronic security measures. Company…
The correct answer is A. Facilities management E. Data center operations G. Information technology. Remediation of a physical security breach in a data center primarily involves the departments that own, operate, and technically secure the facility and its systems.
Question
An intruder was recently discovered inside the data center, a highly sensitive area. To gain access, the intruder circumvented numerous layers of physical and electronic security measures. Company leadership has asked for a thorough review of physical security controls to prevent this from happening again. Which of the following departments are the MOST heavily invested in rectifying the problem? (Select THREE).
Options
- AFacilities management
- BHuman resources
- CResearch and development
- DProgramming
- EData center operations
- FMarketing
- GInformation technology
How the community answered
(37 responses)- A70% (26)
- B3% (1)
- C14% (5)
- D5% (2)
- F8% (3)
Why each option
Remediation of a physical security breach in a data center primarily involves the departments that own, operate, and technically secure the facility and its systems.
Facilities management is responsible for the physical infrastructure including access control systems, badge readers, locks, cameras, and the overall building security posture, making them central to reviewing and improving physical controls.
Human resources manages personnel policies and onboarding, but is not a primary owner of physical or electronic security infrastructure used to protect the data center.
Research and development focuses on product or technology development and has no direct ownership or operational responsibility for data center physical security controls.
Programming teams write application code and have no direct role in managing or rectifying physical access controls or facility security systems.
Data center operations staff directly manage day-to-day access, monitoring, and procedures within the data center, so they are heavily invested in identifying how security layers were bypassed and implementing procedural improvements.
Marketing is focused on external communications and brand strategy and has no involvement in physical security infrastructure or data center operations.
The information technology department is responsible for the electronic security measures such as surveillance systems, access control software, and network monitoring that are integrated into the physical security layers.
Concept tested: Organizational responsibility for physical security controls
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.