ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 4. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 7.2 Physical entry controls

ISO 27001 Annex A 7.2 Physical entry controls

What is ISO 27001 Annex A 7.2 – Physical Entry Controls?

ISO 27001 Annex A 7.2 focuses on ensuring that physical access to areas containing information and other associated assets is authorized and controlled.

The objective is simple:

Only authorized people should be able to physically enter protected areas, and the organization should be able to demonstrate that physical entry is controlled.

Physical entry controls may apply to:

  • Offices
  • Server rooms
  • Network rooms
  • Data centers
  • Records rooms
  • Storage areas
  • Restricted work areas
  • Security-sensitive laboratories
  • Areas where confidential information is processed
  • Areas where critical infrastructure or equipment is located

The controls should be appropriate to the organization’s risks. A small cloud-based startup may need basic office access controls, while a company operating its own data center may require significantly stronger controls.


Why is A.7.2 Physical Entry Controls Important?

Unauthorized physical access can result in:

  • Theft of laptops or other equipment
  • Unauthorized access to confidential information
  • Viewing or photographing sensitive documents
  • Tampering with network equipment
  • Installation of unauthorized devices
  • Theft of backup media
  • Damage to critical systems
  • Social engineering or impersonation
  • Unauthorized access by former employees
  • Loss of physical records
  • Physical security incidents that become cybersecurity incidents

For example, if an unauthorized person can freely enter a room containing network equipment, they may be able to:

  • Disconnect equipment
  • Connect an unauthorized device
  • Access network ports
  • Photograph configuration information
  • Steal equipment
  • Tamper with physical security devices

Simple Principle

Control who can enter, where they can enter, and what happens when someone no longer needs access.


What Does A.7.2 Require?

Organizations should establish and maintain appropriate physical entry controls for areas where information and associated assets are located.

This normally means defining:

  1. Who is authorized to enter
  2. Which areas they are authorized to enter
  3. How access is granted
  4. How access is verified
  5. How visitors are managed
  6. How access is revoked
  7. How physical entry is monitored where appropriate
  8. How access records are maintained
  9. How exceptions and physical security incidents are handled

The organization should apply controls according to:

  • Information sensitivity
  • Asset criticality
  • Physical location
  • Business requirements
  • Threat environment
  • Number and type of personnel
  • Visitor activity
  • Regulatory or contractual requirements

There is no requirement for every startup to install expensive biometric systems.

A practical combination of:

  • Locked doors
  • Keys or access cards
  • Authorized access lists
  • Visitor registration
  • Escort requirements
  • CCTV where appropriate
  • Access reviews
  • Immediate access revocation

may be sufficient for many organizations.


A.7.1 vs A.7.2

These two controls are closely connected but have different purposes.

ControlMain Purpose
A.7.1 Physical Security PerimetersDefines and protects the physical boundary
A.7.2 Physical Entry ControlsControls who is allowed to cross that boundary

Example

A company has a restricted network room.

A.7.1:

The network room is identified as a restricted physical area.

A.7.2:

Only authorized IT administrators can enter the network room, using an access card or key.

So:

A.7.1 = Where should physical protection apply?
A.7.2 = Who is allowed to enter?


Activities Required to Implement A.7.2

1. Identify Protected Areas

Start by identifying areas where unauthorized physical access could create an information-security risk.

Examples:

  • Main office
  • Network room
  • Server room
  • Finance department
  • HR records area
  • Document storage
  • Backup storage
  • Security operations area
  • Data center
  • Research/development laboratory

Not every room needs restricted access.


2. Classify Physical Areas

Create appropriate physical security zones.

For example:

ZoneExampleTypical Access
PublicReceptionAnyone
GeneralEmployee workspaceEmployees
RestrictedHR/FinanceAuthorized employees
Highly RestrictedNetwork roomIT/security personnel
CriticalServer/data centerSpecifically authorized personnel

This should align with the organization’s risk assessment.


3. Define Authorized Personnel

For each restricted area, determine who requires access.

Example:

AreaAuthorized Personnel
General officeEmployees
HR records roomHR team
Finance roomFinance team
Network roomIT administrators
Server roomInfrastructure/security team
Data centerSpecifically authorized personnel

Access should be based on business need, not convenience.


4. Implement Physical Authentication

The organization should use appropriate methods to verify physical access.

Examples include:

  • Physical keys
  • Access cards
  • RFID cards
  • PINs
  • Smart locks
  • Biometrics
  • Security guards
  • Reception verification
  • Mobile access credentials

The required strength depends on the risk.

Startup Example

A 20-person SaaS company may reasonably use:

Office access card → employee identification → restricted rooms locked separately → visitor registration.

It may not need biometric authentication for every internal door.


5. Control Visitors

Visitors should not automatically receive unrestricted physical access.

The organization should define:

  • Visitor registration
  • Visitor identification
  • Host confirmation
  • Visitor badges
  • Escort requirements
  • Restricted-area rules
  • Visitor sign-out
  • Badge/key return

Example

A vendor arrives to repair network equipment.

The process could be:

Reception → Identity Verification → Host Confirmation → Visitor Badge → Escort → Restricted Area → Work Completed → Badge Returned → Sign-Out


6. Control Access for Contractors and Temporary Personnel

Contractors may require physical access for:

  • Maintenance
  • IT support
  • Cleaning
  • Facilities management
  • Security services
  • Equipment installation
  • Audits

Their access should be appropriate to the task.

For example, a cleaning contractor may need access to the general office but should not automatically have access to the network room.


7. Manage Employee Joiners, Movers and Leavers

Physical access must be included in the Joiner-Mover-Leaver process.

Joiner

When an employee joins:

  • Determine required physical areas
  • Issue access card/key
  • Record issuance
  • Explain physical security requirements

Mover

When an employee changes role:

  • Review existing access
  • Remove unnecessary access
  • Grant new required access
  • Update access records

Leaver

When an employee leaves:

  • Disable access card
  • Recover keys
  • Recover badges
  • Remove physical access permissions
  • Record completion

Simple Rule

A person should not retain physical access simply because nobody remembered to remove it.


8. Maintain Physical Access Records

Where appropriate, organizations should maintain evidence showing:

  • Who has access
  • Which areas they can access
  • When access was granted
  • Who approved it
  • When it was reviewed
  • When it was revoked

Electronic access-control systems may automatically maintain access logs.

For manual systems, organizations may maintain:

  • Key register
  • Access-card register
  • Authorized-access list
  • Visitor register

9. Review Physical Access

Physical access should be periodically reviewed.

For example:

Quarterly Physical Access Review

Check:

  • Current employees
  • Former employees
  • Transferred employees
  • Contractors
  • Temporary workers
  • Visitors
  • Lost cards
  • Unreturned keys
  • Excessive access

Example:

HR confirms that five employees left during the quarter. IT/facilities confirms their access cards were disabled and returned where applicable.


10. Handle Lost or Stolen Access Credentials

Physical credentials should be treated as security-sensitive.

Examples:

  • Lost access card
  • Lost office key
  • Stolen badge
  • Compromised PIN
  • Shared access card

The organization should define how these events are reported and handled.

Example:

Employee reports lost card → Access disabled → Replacement issued → Incident recorded → Access reviewed


Startup Example

Consider a 40-person SaaS startup operating from a leased office.

The company has:

  • Reception
  • Open workspace
  • HR/Finance room
  • Meeting rooms
  • Network room
  • Storage room

The company implements:

General Office

Employees use access cards to enter the office.

HR/Finance

Only authorized HR and Finance personnel can access the room.

Network Room

Only authorized IT personnel can enter.

Visitors

Visitors register at reception and are accompanied when entering restricted areas.

Employees Leaving

HR notifies IT/facilities → access card disabled → key/badge recovered → access record updated.

Result

The company has a practical physical entry-control system without implementing unnecessarily expensive technology.


Physical Entry Control Matrix

A simple matrix can help demonstrate that access is intentional.

AreaSecurity LevelAuthorized PersonnelAccess MethodVisitor AccessReview Frequency
ReceptionPublicEveryoneOpenYesN/A
General OfficeGeneralEmployeesAccess CardControlledAnnual
HR RoomRestrictedHRAccess Card/KeyEscortedQuarterly
Finance RoomRestrictedFinanceAccess Card/KeyEscortedQuarterly
Network RoomHighly RestrictedITAccess Card/KeyEscortedQuarterly
Server RoomCriticalAuthorized Infrastructure TeamStrong Physical Access ControlExceptionalQuarterly

Physical Access Authorization Register

A startup can maintain a simple register.

PersonDepartmentAreaAccess Approved ByAccess MethodGranted DateReview DateStatus
Employee AITNetwork RoomIT ManagerAccess Card01-Apr30-JunActive
Employee BHRHR RoomHR ManagerKey05-Apr30-JunActive
Contractor CIT VendorNetwork RoomIT ManagerTemporary Card10-Jun10-JunExpired

The register does not need to be complicated.

The objective is to demonstrate:

Physical access is authorized, controlled and reviewed.


Visitor Management Register

A basic visitor register may contain:

VisitorOrganizationHostPurposeEntryExitBadge No.Escort
John SmithABC LtdIT ManagerNetwork Support10:0012:00V-021Yes
Jane DoeXYZ LtdHR ManagerMeeting14:0015:00V-022Yes

Organizations should avoid collecting unnecessary personal information and should handle visitor information appropriately.


What About Small Startups?

A startup should not create a complex physical-security program just to satisfy ISO 27001.

Consider the actual environment.

Scenario 1: Traditional Office

The startup operates from a dedicated office.

Potential controls:

  • Locked office entrance
  • Employee access cards
  • Visitor register
  • Restricted rooms
  • Key register
  • Access reviews

Scenario 2: Coworking Space

The startup uses a coworking facility.

The building operator may control:

  • Building entrance
  • Reception
  • Elevators
  • CCTV
  • Floor access
  • Security personnel

The startup should understand which physical controls are provided by the coworking provider and what responsibilities remain with the startup.

This should also connect with supplier/cloud/facility risk management.

Scenario 3: Fully Remote Startup

There may be no dedicated corporate office.

The organization should still consider:

  • Employee devices
  • Home working
  • Physical protection of laptops
  • Confidential documents
  • Remote-working requirements
  • Access to coworking spaces
  • Storage of backup media, if any

A.7.2 should reflect the organization’s actual physical environment.


Physical Entry Controls for Cloud-First Startups

A common misunderstanding is:

“We use AWS/Azure/GCP, so physical entry controls are not our responsibility.”

The cloud provider may operate the physical data centers, but the organization still needs to understand its own physical-security responsibilities.

For example, the startup may still have:

  • Corporate offices
  • Employee laptops
  • Networking equipment
  • Physical documents
  • Backup devices
  • Access cards
  • Meeting rooms
  • Home-working environments

For cloud infrastructure, the organization can evaluate the provider’s physical-security controls through appropriate assurance information such as:

  • SOC reports
  • ISO certifications
  • Contractual commitments
  • Supplier assessments
  • Security documentation

This connects A.7.2 with supplier and cloud-service controls.


Audit Evidence for A.7.2

An auditor may request evidence such as:

Policies and Procedures

  • Physical Security Policy
  • Physical Entry Control Procedure
  • Visitor Management Procedure
  • Access Control Policy
  • Joiner-Mover-Leaver Procedure

Registers

  • Physical Access Register
  • Key Register
  • Access Card Register
  • Restricted Area Register
  • Visitor Register
  • Contractor Access Register

System Evidence

  • Door access logs
  • Access-card records
  • Access-control system reports
  • CCTV arrangements where applicable
  • Security guard logs

Operational Evidence

  • Physical access approvals
  • Access reviews
  • Access revocation records
  • Lost-card reports
  • Visitor records
  • Physical security inspection records
  • Physical security incident records

Third-Party Evidence

Where physical infrastructure is outsourced:

  • Data-center certifications
  • SOC reports
  • Supplier assessments
  • Contractual security requirements
  • Physical-security information from providers

Audit Checklist for A.7.2

An auditor may ask:

Physical Areas

  • Have you identified areas requiring physical access controls?
  • How are restricted areas identified?
  • Which areas contain sensitive information or critical equipment?

Authorization

  • Who is authorized to enter restricted areas?
  • Who approves physical access?
  • How do you determine access requirements?

Employees

  • What happens when a new employee joins?
  • What happens when an employee changes roles?
  • What happens when an employee leaves?

Visitors

  • How are visitors identified?
  • Are visitors required to sign in?
  • Are visitors escorted?
  • Can visitors enter restricted areas?

Contractors

  • How do you control contractor access?
  • How do you control temporary access?
  • How do you ensure temporary access expires?

Monitoring

  • Do you maintain physical access logs?
  • How often are physical access rights reviewed?
  • What happens when an access card is lost?

Evidence

  • Can you show an example of an approved access request?
  • Can you show evidence of a recent access review?
  • Can you show evidence that a former employee’s access was revoked?

Common Mistakes

1. Giving Everyone the Same Access

Employees should not automatically have access to every physical area.


2. No Visitor Controls

Allowing visitors to move freely through the office can create unnecessary risk.


3. Forgetting Contractors

Contractors, vendors and temporary workers may require physical access and should be included in the process.


4. Not Revoking Access

A former employee retaining an active access card is a common control weakness.


5. No Evidence

Having a door lock is not enough to demonstrate a controlled process.

The organization should be able to demonstrate:

Who → approved by whom → access to what → when → how → reviewed when → revoked when


6. Overengineering

A small startup does not necessarily need:

  • Biometrics everywhere
  • Multiple security guards
  • Complex surveillance systems
  • Expensive access-control platforms

Controls should be proportionate to risk.


7. Ignoring Shared Offices

Coworking spaces and serviced offices still need to be considered in the physical-security risk assessment.


8. Assuming Cloud Means No Physical Security Responsibility

Cloud infrastructure reduces the organization’s direct responsibility for data-center physical controls, but it does not eliminate physical security responsibilities across the organization.


Practical Startup Implementation Model

A startup can implement A.7.2 using this simple lifecycle:

Identify → Classify → Authorize → Control → Monitor → Review → Revoke → Record → Improve

1. Identify

Identify areas requiring controlled physical access.

2. Classify

Determine the sensitivity/criticality of each area.

3. Authorize

Define who needs access and who approves it.

4. Control

Implement appropriate access mechanisms.

5. Monitor

Maintain logs or other appropriate records.

6. Review

Periodically verify that access remains necessary.

7. Revoke

Remove access when employment, role or business need changes.

8. Record

Maintain evidence of approvals, changes and reviews.

9. Improve

Address incidents, audit findings and identified weaknesses.


Policy vs. Process vs. Evidence

Understanding this distinction is useful for ISO 27001 implementation.

ElementExample
PolicyPhysical Entry Control Policy
ProcessEmployee physical-access request and approval process
ProcedureVisitor registration procedure
RegisterPhysical Access Register
System ControlAccess-card system
EvidenceAccess logs and approval records
ReviewQuarterly physical-access review

A policy explains what the organization requires.

A process explains how it is managed.

Evidence demonstrates that it actually happened.


Relationship With Other ISO 27001 Controls

A.7.2 does not operate independently.

It connects with:

  • A.5.9 – Inventory of information and other associated assets
  • A.5.11 – Return of assets
  • A.5.15 – Access control
  • A.5.16 – Identity management
  • A.5.18 – Access rights
  • A.5.19 – Information security in supplier relationships
  • A.5.23 – Information security for use of cloud services
  • A.6.5 – Responsibilities after termination or change of employment
  • A.6.7 – Remote working
  • A.7.1 – Physical security perimeters
  • A.7.3 – Securing offices, rooms and facilities
  • A.7.4 – Physical security monitoring
  • A.7.6 – Working in secure areas
  • A.7.7 – Clear desk and clear screen
  • A.7.8 – Equipment siting and protection
  • A.7.9 – Security of assets off-premises

Key Relationship

A.7.1 defines the protected boundary.

A.7.2 controls entry through that boundary.

A.7.3 protects the offices, rooms and facilities.

A.7.4 provides appropriate physical monitoring.

Together, they create a more complete physical-security framework.


Useful Resources and Draft Documents

Organizations implementing A.7.2 may consider creating:

  1. Physical Entry Control Policy
    [Insert Draft Document Link]
  2. Physical Access Control Procedure
    [Insert Draft Document Link]
  3. Physical Access Authorization Form
    [Insert Draft Document Link]
  4. Physical Access Register
    [Insert Draft Document Link]
  5. Restricted Area Access List
    [Insert Draft Document Link]
  6. Visitor Management Procedure
    [Insert Draft Document Link]
  7. Visitor Register
    [Insert Draft Document Link]
  8. Contractor Physical Access Procedure
    [Insert Draft Document Link]
  9. Key and Access Card Register
    [Insert Draft Document Link]
  10. Physical Access Review Checklist
    [Insert Draft Document Link]
  11. Lost Access Card / Key Incident Form
    [Insert Draft Document Link]
  12. Physical Security Inspection Checklist
    [Insert Draft Document Link]
  13. Physical Security Incident Report
    [Insert Draft Document Link]

Questions an Auditor May Ask Management

An auditor may ask:

“How do you know who is authorized to enter your restricted areas?”

A good answer should be supported by an access authorization process and appropriate records.

“Show me your physical access register.”

The organization should be able to demonstrate current access.

“What happens when an employee leaves?”

The answer should include physical access revocation and recovery of keys/cards where applicable.

“How do you manage visitors?”

The organization should explain its visitor identification, authorization and monitoring process.

“Can a visitor enter your network room?”

The answer should be based on the organization’s defined physical security requirements rather than informal practice.

“Show me evidence that physical access was reviewed.”

The organization should be able to provide a recent review or equivalent evidence appropriate to its environment.


Startup-Focused Quick Summary

For a startup, A.7.2 does not mean buying an expensive biometric access-control system.

Start with the basics:

Step 1

Identify restricted physical areas.

Step 2

Define who needs access.

Step 3

Obtain appropriate approval.

Step 4

Use suitable access controls.

Step 5

Control visitors and contractors.

Step 6

Review access periodically.

Step 7

Immediately revoke access when no longer required.

Step 8

Keep enough evidence to demonstrate that the process operates.

Simple Startup Principle

The objective is not to make physical access complicated. The objective is to make unauthorized physical access difficult and authorized access accountable.


Startup-Focused Final Takeaway

A.7.2 is fundamentally about controlling physical entry to protect information and associated assets.

For a startup, the implementation can be straightforward:

Identify protected areas → Define authorized people → Approve access → Control entry → Manage visitors → Review access → Revoke access → Maintain evidence

The key audit question is not:

“Do you have an access card system?”

It is:

“Can you demonstrate that physical access is authorized, controlled, reviewed and revoked when no longer required?”

If the answer is supported by a practical process and reliable evidence, the organization is in a much stronger position to demonstrate the intent of A.7.2.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *