How is the server room secured?
Not all locks (or doors) are made equal. Does a system log who enters the server room? E.G. using a fob to enter. Accountability may help against insider theft. Are the employees trained to be on guard against social engineering, such as Bob showing up in an Acme Networking uniform and claiming that Ted called earlier?
How are the disks encrypted. Does restarting require a passphrase be entered? If not, a key to decrypt the filesystem, that exists on the server, does not provide protection; while protecting the key with a pass phrase will prevent unattended recovery.
|