Security

Physical Security and Compliance in Data Centres

7 min read

Data centre security combines layered access controls, surveillance, operating procedures and independent compliance evidence.

Layered physical security

Professional data centres use multiple security layers rather than relying on a single locked door. Controls may include perimeter fencing, vehicle barriers, security staff, intercoms, mantraps, access cards, biometrics, CCTV and locked racks or cages. Each layer delays, detects or prevents unauthorised access. The exact design varies by site and customer area. Buyers should examine how visitors are identified, escorted and recorded, how lost credentials are handled and how access is revoked when staff or contractors leave.

Operational security matters

Strong technology can be undermined by poor procedures. Review how the provider approves access, manages deliveries, stores equipment and responds to alarms. Ask whether customers can restrict access to named individuals and whether dual authorisation is available for sensitive areas. Understand loading-dock security, package handling and disposal processes. Maintenance contractors should be controlled and supervised. Incident records, access logs and video retention may be important for investigations, but retention periods and customer access to evidence should be clarified in advance.

Compliance certifications

Data centre providers commonly hold certifications or assurance reports relating to information security, quality, business continuity, environmental management or service controls. Examples can include ISO 27001, ISO 9001, ISO 22301, SOC reports and sector-specific frameworks. A certificate is useful evidence, but it does not automatically make a customer compliant. Review the scope, site coverage, issuing body and expiry date. Your organisation remains responsible for configuring systems, managing identities, encrypting data and meeting obligations that sit above the facility layer.

Shared responsibility

In colocation, the provider secures and operates the building, power, cooling and common areas. The customer typically controls its rack contents, operating systems, applications, data and user access. Responsibility can shift for managed services, remote hands or connectivity products. Document the boundary clearly so controls are neither duplicated nor missed. For example, a provider may record who entered a cage, but the customer must decide who is authorised and review the logs. Compliance assessments should map every requirement to a named owner.

Security due diligence questions

Request current certifications, audit summaries where available, penetration or physical-security testing information, incident-notification terms and business-continuity plans. Ask how security staff are trained and how access systems continue during power or network failures. Review rack locks, cage design, CCTV coverage, fire detection, environmental monitoring and media-destruction options. Providers such as NEXTDC and Equinix publish facility and compliance information, but buyers should verify that evidence applies to the exact site and service being considered.

Frequently asked questions

Not sure how this applies to your business?

The free assessment turns answers like these into realistic pricing and a provider shortlist for your specific requirements.

Start free assessment