Through appropriate design, protect secure areas from natural or man made threats. The following control objectives must be covered in the design of premises:
• public access areas are located away from secure areas;
• buildings housing computers are not signposted and provide minimum indication of their purpose;
• photocopiers and fax machines are not located within secure areas. Staff are to ensure that any output from such equipment that contains sensitive or critical information is appropriately secured;
• doors and windows are normally locked, especially if the premises are left unattended;
• exterior windows are protected, particularly those at ground level;
• intruder detection systems are installed and regularly tested.
• unoccupied areas are alarmed at all times;
• subject to a risk assessment, alarms are installed in other areas;
• information processing facilities managed by third parties are physically separated from those managed by the university;
• Monash internal telephone books and directories that include references to information processing facilities are not accessible to the public;
• hazardous or combustible materials are housed away from information processing facilities;
• fallback equipment and backup media are located away from the main site.