Customer responsibilities.
WHAT REMAINS YOURS
Your equipment, its configuration, and its physical protection within your allocated space.
WHAT TO USE
A locked cabinet or cage, rather than open racks.
WHY
Others are in the same hall.
WHAT TO SECURE ON THE EQUIPMENT ITSELF
Management interfaces, with strong credentials Console access Boot configuration, so it cannot be started from external media
THAT LAST POINT
Physical access to an unprotected server is complete access.
WHAT TO ENABLE
Full disk encryption, where the workload permits.
WHY
So a removed drive discloses nothing.
WHAT TO BE CAREFUL WITH
Ports left accessible Credentials written on labels Spare drives left in the rack
WHAT TO RECORD
Serial numbers of everything installed.
WHY
For recovery and for insurance.
WHAT TO REVIEW
Who on your own team has access, and whether they still need it.
WHAT TO DO WHEN SOMEONE LEAVES
Revoke facility access and change equipment credentials.