View a markdown version of this page

HNSEC04-BP05 Allow only authorized personnel access to on-premises infrastructure - Hybrid Networking Lens - AWS Well-Architected Framework

HNSEC04-BP05 Allow only authorized personnel access to on-premises infrastructure

Ensure that only authorized personnel have physical access to your on-premises networking infrastructure, such as data centers, server rooms, and network equipment. Implement strict access controls, logging, and monitoring to protect against unauthorized entry and physical tampering.

Desired outcome: Prevent unauthorized physical access and tampering with critical hybrid network resources, supporting a robust security posture across both cloud and on-premises environments.

Level of risk exposed if this best practice is not established: High

Benefits of establishing this best practice:

  • Reduces risk of physical compromise or sabotage of network infrastructure

  • Supports regulatory compliance and audit requirements

  • Deters insider threats and unauthorized activity

  • Complement logical cloud security controls with physical safeguards

Implementation guidance

  • Implement access control systems (for example, keycards and biometrics) for data center and server room entry.

  • Maintain visitor logs and conduct background checks for authorized personnel.

  • Use surveillance cameras and alarms to monitor critical physical locations.

  • Conduct regular audits and reviews of physical access records.

  • Establish clear procedures for visitor access and equipment removal or servicing.