vStream Digital Media / ShineVR
Physical Security Policy
Definitions
| Term | Definition |
|---|---|
| Company | means vStream Digital Media |
| ShineVR | means the ShineVR product developed and operated by vStream Digital Media |
| GDPR | means the General Data Protection Regulation |
| Responsible Person | means Andrés Pitt, CTO |
| Data Centre | Specialized building housing computer systems and associated components such as telecommunications and storage systems, including environmental controls and security devices |
| Physical Access Control | Security measures restricting physical entry to facilities, rooms, or equipment |
| Company Premises | vStream Digital Media office at 37 Leeson Close, Dublin 2, D02 H344, Ireland |
| Production Data | Live customer data, including ShineVR trial data and healthcare information |
| Biometric Authentication | Authentication based on unique physical characteristics (fingerprints, facial recognition, iris scans) |
| Environmental Controls | Systems managing temperature, humidity, fire suppression, and power supply for IT infrastructure |
1. Policy Statement
vStream Digital Media operates a cloud-first infrastructure model with no customer or production data hosted at Company premises. All customer data, ShineVR trial data, and production systems reside exclusively on Google Cloud Platform infrastructure in European data centres.
This Physical Security Policy establishes requirements for two distinct security environments:
- Data Centre Physical Security: Complete reliance on Google Cloud Platform's comprehensive physical security controls for data centres housing production systems and customer data
- Company Office Physical Security: Basic physical security measures for employee workspace at Company premises in Dublin, Ireland
The Company maintains no data centre facilities and does not manage physical security for production infrastructure. All data centre physical security is provided by Google Cloud Platform in their certified facilities in the Netherlands and Belgium.
2. Purpose
The purpose of this policy is to:
- Document reliance on Google Cloud Platform for data centre physical security
- Establish physical security requirements for Company office premises
- Protect Company-owned equipment and assets
- Define physical access controls for office facilities
- Establish equipment disposal and decommissioning procedures
- Ensure compliance with GDPR, ISO 27001, and customer security requirements
- Define roles and responsibilities for physical security
- Support business continuity through appropriate physical security measures
- Provide evidence of physical security controls for audit and compliance purposes
3. Scope
This policy applies to:
3.1 Data Centre Facilities (Google Cloud Platform)
- Google Cloud data centres in europe-west4-a (Eemshaven, Netherlands)
- Google Cloud data centres in europe-west1-b (St. Ghislain, Belgium)
- All infrastructure hosting production systems, customer data, and ShineVR applications
- Physical security for these facilities is managed entirely by Google Cloud Platform
3.2 Company Office Premises
- Company office at 37 Leeson Close, Dublin 2, D02 H344, Ireland
- Employee workspaces and meeting rooms
- Company-owned equipment and devices
- Physical asset storage and disposal
3.3 Personnel
- All employees, contractors, and temporary staff of vStream Digital Media
- Visitors to Company premises
- Third-party personnel with physical access to Company facilities
Important Context: The Company operates from a small office with controlled access. No customer data, production data, or ShineVR trial data is stored at Company premises. All production systems are cloud-hosted.
4. Data Centre Physical Security (Google Cloud Platform)
4.1 Cloud-First Model
Complete Reliance on Google Cloud Platform:
- vStream does not manage, operate, or maintain physical data centre facilities
- All customer data and production systems hosted on Google Cloud Platform infrastructure
- Google Cloud provides comprehensive physical security for their data centres
- Data centres located in europe-west4-a (Eemshaven, Netherlands) - Primary and europe-west1-b (St. Ghislain, Belgium) - Secondary
- EU data residency maintained (no data stored outside Europe)
Company's Role:
- Select secure cloud provider with appropriate certifications
- Review and verify Google Cloud's security certifications and compliance
- Document reliance on Google Cloud physical security controls
- Monitor Google Cloud security notifications and updates
- Participate in Google Cloud security programmes
- Maintain evidence of Google Cloud compliance for audits
4.2 Google Cloud Data Centre Physical Security Controls
The following physical security controls are documented by Google Cloud Platform as implemented at their data centres. This information is derived from Google Cloud's official security documentation and should be verified against current Google Cloud security whitepapers and compliance reports.
Perimeter Security: Data centres located in nondescript buildings; physical barriers and controlled entry points; 24/7 perimeter monitoring; vehicle access controls and inspection; separate delivery and visitor entrances.
Access Control: Multi-factor authentication for facility access; biometric authentication systems; security badges with photo identification; escort requirements for visitors; access granted on need-to-enter basis only; regular access review and revocation for terminated personnel.
Surveillance and Monitoring: 24/7 video surveillance of data centre areas; security operations centre monitoring; intrusion detection systems; alarm systems for unauthorized access attempts; video footage retained for security investigations.
Physical Security Personnel: Trained security guards on-site 24/7; security guard screening and background checks; regular security patrols; incident response procedures; coordination with local law enforcement.
Environmental Controls: Redundant power supplies with backup generators; Uninterruptible Power Supply (UPS) systems; climate control systems; fire detection and suppression systems; water leak detection; natural disaster protection measures.
Hardware Security and Decommissioning: Server racks locked and access-controlled; asset tracking and inventory management; secure hardware decommissioning procedures including multi-step data sanitization, cryptographic erasure, degaussing, and physical destruction of storage media; documented chain of custody; no customer access to physical servers.
4.3 Google Cloud Security Certifications
Google Cloud maintains comprehensive security certifications:
- ISO/IEC 27001: Information Security Management
- ISO/IEC 27017: Cloud Security
- ISO/IEC 27018: Cloud Privacy
- SOC 2 Type II: Service Organization Controls
- SOC 3: Security, Availability, and Confidentiality
- PCI DSS: Payment Card Industry Data Security Standard
- HIPAA: Health Insurance Portability and Accountability Act
- Various national and regional certifications
4.4 Company Responsibilities for Cloud Physical Security
What vStream Does: Select and contract with certified cloud provider; define data residency requirements (EU only); review Google Cloud security certifications annually; monitor Google Cloud security notifications; maintain documentation of Google Cloud security controls for audits; provide customers with evidence of data centre security.
What vStream Does Not Do: Manage or operate data centre physical security; conduct physical security audits of Google Cloud data centres; maintain physical access to data centre facilities; dispose of data centre hardware; implement physical environmental controls.
5. Company Office Physical Security
5.1 Office Context and Risk Profile
Office Environment: Small office with controlled building access; limited employee count; shared office building with building security; no customer data or production data stored on premises; no servers or production infrastructure at office. Office used primarily for employee workspace, meetings and collaboration, and development on laptops accessing cloud resources.
Security Risk Assessment: Low risk to customer data (no customer data at premises); medium risk to Company assets (laptops, equipment); low risk to business continuity (cloud-based systems enable remote work); physical security important for employee safety and asset protection.
5.2 Building Access Control
Building Security: Office located in multi-tenant building; building access controlled by landlord/building management; building security includes reception desk during business hours, access card system for after-hours entry, and CCTV in common areas.
Company Office Access: Office door locked when unattended; keys issued to permanent employees only; key return upon employee termination; visitors must be escorted by employee; visitor log maintained.
After-Hours Access: Building access card required for after-hours entry; employees notified of building access card procedures; lost or stolen access cards reported immediately; access cards deactivated upon employee termination.
5.3 Visitor Management
Visitor Procedures: All visitors must be pre-arranged with employee host; visitors check in with employee host; visitor log maintained including visitor name and company, purpose of visit, date and time in/out, and employee host name; visitors escorted at all times; no visitor access to employee workstations or Company systems; visitors use segregated guest wireless network if implemented; confidential information secured before visitor meetings.
5.4 Clear Desk and Clear Screen Policy
Clear Desk Requirements: Sensitive documents secured in locked drawers when not in use; confidential printouts not left unattended on printers; whiteboards with confidential information erased after meetings; secure disposal of confidential documents (shredding); no customer data printed.
Clear Screen Requirements: Computers automatically lock after 5 minutes of inactivity; employees lock screens when leaving desk; password-protected screensavers enabled; monitors positioned to prevent unauthorized viewing.
5.5 Equipment and Asset Security
Company-Owned Equipment: IT hardware asset register maintained including asset type and model, serial number, assignment to employee, location, acquisition date, and status.
Laptop and Device Security: Laptops locked to desks with cable locks; laptops secured in locked drawers or taken home; Company devices encrypted; lost or stolen devices reported immediately; remote wipe capability enabled.
Peripheral Security: External hard drives and USB drives encrypted; removable media not used for Company data; unused equipment stored in locked cabinets; equipment surplus securely stored until disposal.
5.6 Office Environmental Controls
Basic Environmental Protection: Fire extinguishers present and inspected; smoke detectors installed; emergency exit routes clearly marked; emergency evacuation procedures displayed; first aid kit available; no specialized environmental controls required.
6. Hardware Disposal And Decommissioning
6.1 Company-Owned Device Disposal
Disposal Process for Company Devices: Device returned to CTO or designated IT personnel; device wiped using secure data erasure methods; for Google Workspace devices, factory reset and Google account removal; data backed up to Google Drive before wiping if required.
Data Erasure: Full disk encryption keys destroyed; operating system reinstall or factory reset; multiple-pass data overwrite if encryption keys cannot be destroyed; verification of successful data erasure; documentation of data erasure in disposal log.
Physical Disposal: Wiped devices donated to charity, sold, or recycled; if device cannot be wiped, physical destruction of storage media; certificate of disposal obtained from disposal vendor if applicable; asset register updated with disposal date and method.
6.2 Data Centre Hardware Disposal (Google Cloud)
vStream does not physically dispose of data centre hardware. All production infrastructure hosted on Google Cloud Platform. Google Cloud manages hardware lifecycle including decommissioning: multi-step data sanitization, cryptographic erasure, degaussing, physical destruction of storage media, chain of custody documentation, and zero-touch decommissioning.
6.3 Removable Media Disposal
Company does not use removable media for production data. If removable media used: encrypt all data, wipe before disposal using secure erasure tools, physically destroy media containing sensitive information, and document disposal. All backups stored in Google Cloud Storage (no physical backup media).
7. Mobile Device Management
7.1 Company Device Security
Company does not currently issue mobile phones to employees. If Company-issued mobile devices used in future: device encryption mandatory; screen lock with PIN/biometric authentication required; remote wipe capability enabled; lost or stolen device reporting procedures; device tracking enabled.
7.2 Personal Device Security (BYOD)
Employees use personal devices for work (primarily mobile phones). BYOD Policy establishes security requirements for personal devices: device encryption enabled; screen lock with strong passcode/biometric; anti-malware software installed; operating system kept updated; separation of work and personal data.
8. Physical Security Incidents
8.1 Incident Types
Lost or stolen Company device; unauthorized physical access to office; theft of Company property; physical damage to equipment; security violation (propped door, lost keys, etc.); visitor policy violation; environmental incident (fire, flood, power outage).
8.2 Incident Reporting
All physical security incidents reported immediately to CTO; lost or stolen devices reported within 1 hour of discovery; after-hours incidents call CTO directly at (086) 788 6570; document incident details.
8.3 Incident Response
Lost or Stolen Device Response:
- Employee reports to CTO immediately
- CTO initiates remote wipe via Google Workspace (if Company device)
- Account passwords changed (if account credentials on device)
- Monitoring for unauthorized access to Company systems
- Police report filed (if appropriate)
- Insurance claim filed (if applicable)
- Incident documented in incident register
- Post-incident review to prevent recurrence
9. Business Continuity And Disaster Recovery
9.1 Physical Disaster Impact
Office Disaster Scenarios: Fire, flood, or other physical damage to office; extended power outage; building access denial; equipment theft or destruction.
Impact Assessment: Customer data impact: none (no customer data at office); production systems impact: none (cloud-hosted); business operations impact: minimal (remote work capable); employee safety: primary concern.
9.2 Business Continuity Measures
All employees equipped with laptops for remote work; all Company data stored in Google Drive; production systems accessed via cloud; communication via Google Workspace; no dependency on physical office for business operations. Recovery Time Objective (RTO): Immediate (remote work). Recovery Point Objective (RPO): Zero (all data in cloud).
10. Asset Management
10.1 IT Hardware Asset Register
Asset register contents include asset identification (asset type, make and model, serial number, asset tag), asset assignment (assigned employee, assignment date, location), and asset lifecycle (acquisition date and cost, warranty, disposal date and method, current status). Asset register updated within 5 working days of changes; annual comprehensive asset inventory audit.
10.2 Software Asset Management
Software licenses tracked separately from hardware assets; Google Workspace licenses assigned per user; development tools and software licenses documented; cloud service subscriptions tracked; regular review of software licenses for cost optimization.
11. Training And Awareness
11.1 Physical Security Training
All new employees receive physical security awareness during induction covering office access procedures, visitor management, clear desk/clear screen policies, device security, lost/stolen device reporting, and emergency procedures. Annual refresher training for all staff.
12. Compliance And Regulatory Requirements
12.1 GDPR Physical Security
GDPR Article 32 requires physical security measures appropriate to risk. No personal data stored at Company premises (all data in cloud); Google Cloud provides appropriate physical security; device encryption protects personal data on employee devices; secure disposal ensures personal data irrecoverable.
12.2 ISO 27001 Physical Security Controls
ISO 27001 Annex A.11 covers secure areas (office access control, visitor management) and equipment security (asset management, secure disposal). Compliance monitored via Google Cloud Security Command Centre for data centres; office security documented and auditable.
13. Roles And Responsibilities
| Role | Responsibilities |
|---|---|
| CTO (Responsible Person) | Overall physical security policy ownership; Google Cloud physical security verification; office security oversight; asset register management; physical security incident response; policy review and updates; approval of equipment disposal |
| All Employees | Comply with office access procedures; follow clear desk/clear screen policy; secure Company equipment; report lost/stolen devices; escort visitors; report physical security incidents; participate in emergency drills; follow asset management procedures |
| Building Management | Building access control; CCTV in common areas; emergency systems; environmental controls (HVAC, fire suppression); building security patrols |
14. Policy Review And Maintenance
Annual policy review by CTO. Review triggered by significant physical security incidents, changes to office location, changes to Google Cloud provider or data centre locations, new regulatory requirements, customer security requirement changes, or results of asset audits. All updates require CTO approval; changes communicated to all staff within 10 working days.
15. Exceptions
15.1 Exception Process
Exceptions requested in writing to CTO; business justification required; risk assessment documented; compensating controls identified; time-limited exceptions preferred; permanent exceptions require CEO approval.
16. Related Policies And Documents
This policy should be read in conjunction with:
- Information Security Policy
- Cloud Security Policy
- Network Security Policy
- Encryption Policy
- BYOD Policy
- Access Management Policy
- Incident Management Policy
- Backup and Recovery Policy
- Media Retention and Disposal Policy
- Change Control Policy
17. Contact Information
Data Protection Officer / Chief Technology Officer: Andrés Pitt Email: andres@vstream.ie Phone: (086) 788 6570 Available 24/7 for P1 physical security incidents.
Company Address: vStream Digital Media, 37 Leeson Close, Dublin 2, D02 H344, Ireland. Website: vstream.ie