A7.2 Physical entry
1 min read
ISO 27001 A7.2 Physical entry is all about managing who can physically enter areas where sensitive information or IT infrastructure is located. It’s not enough to have walls and doors—this control ensures that only authorized individuals can pass through those doors, and that their access is tracked, limited, and monitored.
Think of it like this: Your office might be the castle, but without a guard at the gate and logs of who comes and goes, anyone could walk in and compromise your entire information system.
Implementation Guidance #
- Access Control Systems
- Install controlled access systems like:
- Electronic key card readers
- PIN pads
- Biometric authentication (e.g., fingerprint, facial recognition)
Only authorized personnel should be granted access based on their job role and necessity.
- Visitor Management
- Maintain a visitor logbook or digital check-in system.
- Issue temporary ID badges or access cards.
- Ensure visitors are always escorted within secure areas.
- Clearly label areas that are off-limits to visitors.
- Surveillance and Monitoring
- Use CCTV cameras to monitor entry and exit points.
- Store footage securely and define a retention period (commonly 30–90 days).
- Regularly check and test your monitoring systems for uptime and performance.
- Entry Logs and Review
- Keep digital or manual logs of:
- Who accessed which area
- When they accessed it
- Duration of stay (if applicable)
- Review access logs periodically to detect any anomalies.
- Segmentation of Areas
- Divide your office or facility into zones based on sensitivity:
- General work area
- Restricted area (e.g., HR, Finance)
- Highly sensitive area (e.g., server room, backup storage)
Each zone should have increasing levels of access control.
Best Practices #
- Limit “tailgating” by installing anti-passback systems or turnstiles.
- Use motion sensors or alarms in sensitive areas during off-hours.
- Immediately revoke access for employees who leave the organization.
- Audit access lists at least quarterly to ensure only active staff have entry rights.
Audit Readiness #
Documents to Maintain:
- Physical security policy and access control procedures
- Access control system configuration records
- Visitor logs (manual or digital)
- Surveillance system details (coverage, retention policy)
- Access review reports
Auditors will check:
- Whether physical access is restricted and documented
- If entry logs and access rights are regularly reviewed
- If visitor procedures are being followed
- Whether incident response plans cover physical breaches
Common Pitfalls #
- Shared access cards among employees
- Unattended visitor access or open doors
- Failure to review access logs
- No controls after working hours
ISO 27001 Control Attributes #
|
Control |
Attribute Value |
|
A.7.1 Physical Security Perimeter A.7.2 Physical Entry Controls |
Preventive, Physical, Operational |
|
Purpose |
Ensure only authorized individuals can physically access secure areas |
|
Applicability |
All offices, data centers, and restricted zones |
|
ISO 27001 Domains |
Physical and Environmental Security |
Physical entry control is about watching the gates—you wouldn’t leave your front door wide open, right? The same goes for your data center, server closet, or confidential records room. Always ensure access is limited, monitored, and auditable.