Out-of-band management
IPMI, BMC and console access are permanently reachable and often the least monitored plane in the estate.
ManagementColocation gives you space, power and connectivity. It also brings shared fabric, provider engineers, remote hands and out-of-band management planes. Physical Control governs which of those routes exists, and when.
Need → Control → Blueprint → Modules

Most data centre risk is not about the building. It is about the standing paths that make remote operation convenient.
IPMI, BMC and console access are permanently reachable and often the least monitored plane in the estate.
ManagementProvider staff can physically touch equipment on request, with the record held by the provider.
PeopleCross-connects, shared switching and provider services create routes you did not design.
NetworkReplication paths between sites stay open continuously, so an attack propagates with the data.
BackupsDecommissioned disks and appliances leave the floor holding data that was never accounted for.
AssetsControls that hold in a private facility do not always hold where other tenants share the same space.
TenancyColocation exists so that people do not have to travel. Every convenience that supports that becomes a standing route.
A colocation contract describes what the provider will and will not do. It does not remove the physical routes that make those actions possible.
Control the path, protect the asset.Out-of-band exists so equipment can be reached when everything else has failed, which is exactly why it is valuable to an attacker.
Responsibility is split, so neither party holds a complete list of the routes into the racks.
Continuous replication is treated as resilience, even though it copies the incident as faithfully as the data.
Certifications cover the building and process, not the specific connections your estate depends on.
Data centre exposure becomes manageable the moment the routes are named rather than assumed.
Physical Control sits in the path itself, so a management plane or cross-connect is not simply firewalled, it is absent between windows.
Every convenience route is available at all times.
Routes are opened deliberately and close on their own.
Software can be told to deny a connection. Physical Control removes the connection itself, so the denial does not depend on the system behaving as configured.
Every incident that spreads does so along a connection that was already there. Control begins by naming that connection in plain language, before anyone talks about products.
A path that exists only when it is needed cannot be used at three in the morning by someone who should not have it. Disconnection is the resting state, not the emergency response.
When work genuinely needs a connection, Control opens it for a named person, a stated purpose and a fixed period, then closes it again without anyone having to remember.
A policy says the path should be closed. Physical control shows that it is. That difference is what auditors, insurers and boards are actually asking about.
Data centre and colocation exposure spans two patterns: enforcing the boundary between zones and keeping critical systems available while disconnected from unnecessary routes.
Segmentation should not just be logical. It should be physically enforceable.
Applied to trust boundary enforcement between zones. The Blueprint page carries the architecture, the zone detail and the deployment sequence.
Keep critical systems available, controlled and disconnected from unnecessary exposure.
Open CP-05This page is about the routes into your racks. Holding a recovery copy that no route can reach is a different job, and that belongs in Offline Secure Storage rather than in replication.
Hold a disconnected gold copyThe questions that come up when colocation exposure is reviewed properly.
CP-04 Enforce Physical Segmentation and CP-05 Protect Critical Infrastructure set out how those routes are separated, opened and evidenced.