PK0-005 · Basics of IT and Governance · Updated July 26, 2026
Physical, Operational, and Data Security for Project Managers
Project managers are not expected to design firewalls, but PK0-005 does expect them to recognize the three broad security categories — physical, operational, and digital/data — and to make sound project decisions in each: choosing the right control category for a situation, building security activities into schedules and budgets, and insisting on data-protection terms in vendor agreements. The classification question is the most common trap: a badge reader on a server room door is a physical control, no matter how digital the badge system’s back end is, because what it restricts is physical entry to a space.
The three security categories
Physical security protects places, equipment, and people from physical access, theft, and damage. Its controls act on the tangible world:
- Badge readers, key locks, and smart locks on doors
- Security guards and visitor sign-in procedures
- Fences, gates, bollards, and mantraps (double-door entry vestibules)
- Surveillance cameras (CCTV, closed-circuit television)
- Locked server racks, cable locks, and equipment cages
- Environmental protections in the same spaces: fire suppression, climate control
The classification test is simple: if the control decides who can physically get to something or protects hardware from physical harm, it is physical — regardless of whether electronics are involved. A biometric door scanner is physical security; biometric login to a laptop is digital security.
Operational security covers the processes and procedures that keep security working day to day: patching cadences, maintenance windows, change control, account provisioning and deprovisioning, backup routines, security awareness training, and clean-desk policies. This is the category that most often collides with a project schedule, because operational requirements arrive as recurring, non-negotiable activities the project must plan around.
Digital and data security protects information and the systems that hold it: multi-factor authentication (MFA — requiring two or more proof factors to log in), encryption at rest and in transit, access controls, data classification (labeling data public, internal, confidential, or restricted so handling rules follow the label), data masking or anonymization, and secure disposal of data when it is no longer needed.
| Category | What it protects | Example controls | Typical PM decision |
|---|---|---|---|
| Physical | Spaces, hardware, people | Badge readers, locks, guards, cameras, mantraps, locked racks | Facility requirements for a data closet or office move |
| Operational | Day-to-day secure practice | Patching windows, change control, onboarding/offboarding, training | Scheduling recurring security work and outages |
| Digital/data | Information and systems | MFA, encryption, data classification, masking, secure disposal | Vendor data-handling terms, access decisions |
Physical controls: the project angle
Projects meet physical security whenever they stand up a space — a data closet, an office suite, a lab — or move equipment. The project manager’s job is not to pick the lock vendor; it is to ensure the physical control requirements are captured as project requirements, costed, scheduled (badge systems have lead times), and verified before go-live. When a facilities lead recommends a badge reader for a server room, that is a physical security requirement entering project scope, and it should flow through normal scope and change processes like any other requirement.
For exam purposes, be ready to pick physical controls out of a mixed list. Cameras, locks, badge readers, guards, and fencing are physical; firewalls, MFA, encryption, and antivirus are digital; patching schedules and training are operational.
Operational security: patching windows and the schedule
A recurring pattern: mid-planning, the security team announces that all servers in scope require monthly patching windows, each with a short planned outage. The right project-management response has two parts, and both matter:
- Build the windows into the schedule as recurring tasks. Treat each patching window as a scheduled activity with duration and resources, and sequence dependent work around the outages so testing or cutover tasks don’t collide with them. Ignoring the windows, or treating them as someone else’s problem, guarantees schedule surprises.
- Coordinate and communicate the outages with affected stakeholders. Users and dependent teams need advance notice of each planned outage — timing, expected duration, and impact. That means the communication plan carries the patching calendar too.
What you do not do is ask security to waive the requirement for the project’s convenience, or absorb the outages silently and let the baseline slip. Security-driven recurring work is a legitimate schedule input, and surfacing its impact on dates is exactly the job. Where the outage risk is material, it also earns an entry in the risk register.
Data security in vendor agreements
The highest-stakes moment for a PM is handing data to an outside party — for example, an offshore team receiving a copy of production customer data for testing. Whatever the statement of work (SOW) says is, practically, all the protection that data gets — which is why data-protection terms deserve the same scrutiny as the commercial factors in your vendor evaluation criteria. Controls worth insisting on in the agreement:
- Data classification and handling requirements: state what the data is, its sensitivity level, and the handling rules that follow — who may access it, on what systems, in which locations.
- Encryption: required in transit and at rest on every system that touches the data.
- Confidentiality obligations: a non-disclosure agreement (NDA) or confidentiality clause binding the vendor and its staff.
- Data minimization and masking: prefer masked, anonymized, or synthetic data for testing; if production data is truly necessary, limit it to the minimum fields and records required.
- Access restrictions and MFA: named-user access only, revoked when staff roll off.
- Secure return or destruction: at engagement end, the vendor returns or verifiably destroys all copies, with written certification.
- Breach notification and audit rights: the vendor must report incidents within a defined window, and the customer may audit compliance.
On the exam, distractor options in these scenarios typically include things that do nothing to protect the data — bigger penalties without controls, faster delivery terms, or trusting the vendor’s internal policy sight unseen. Pick the answers that put enforceable, specific controls on the data itself.
How the PK0-005 exam tests this
- Category-classification scenarios: a control is described in context (badge reader on a server room, camera in a data closet) and you must name the security category. Physical-world access = physical security, even when the mechanism is electronic.
- “Choose three” control-sorting items: a mixed list of physical, digital, and operational controls, asking you to pick only the physical ones. Sort by what the control acts on, not by how techy it sounds.
- Vendor data-handling scenarios: an SOW or outsourcing agreement involving sensitive data, asking which contract controls to insist on — expect encryption, NDA/confidentiality, and secure return or destruction to be the credited cluster.
- Schedule-integration scenarios: a security requirement (patching windows, mandated outages) surfaces during planning, and the credited actions are building it into the schedule as recurring work and communicating planned outages to affected stakeholders.
Security questions like these belong to the Basics of IT and Governance domain — the full PK0-005 study guide shows where they fit in the overall exam blueprint. The physical-vs-digital classification trap loses its teeth after a handful of practice questions.
Quick reference
- Three categories: physical (spaces and hardware), operational (day-to-day secure process), digital/data (information and systems).
- Badge readers, locks, guards, cameras, mantraps, fencing, and locked racks are physical controls — even with electronic parts.
- MFA, encryption, data classification, and masking are digital/data controls; patching cadences and training are operational.
- Security-mandated recurring work goes into the schedule as recurring tasks, with outages sequenced around and communicated ahead of time.
- Vendor agreements touching sensitive data need: classification/handling rules, encryption, NDA, minimized or masked data, access limits, secure return/destruction, breach notification.
- The PM’s security role is requirements, schedule, budget, and contract terms — not control engineering.