What is ISO 27001 Annex A 7.2 – Physical Entry Controls?
ISO 27001 Annex A 7.2 focuses on ensuring that physical access to areas containing information and other associated assets is authorized and controlled.
The objective is simple:
Only authorized people should be able to physically enter protected areas, and the organization should be able to demonstrate that physical entry is controlled.
Physical entry controls may apply to:
- Offices
- Server rooms
- Network rooms
- Data centers
- Records rooms
- Storage areas
- Restricted work areas
- Security-sensitive laboratories
- Areas where confidential information is processed
- Areas where critical infrastructure or equipment is located
The controls should be appropriate to the organization’s risks. A small cloud-based startup may need basic office access controls, while a company operating its own data center may require significantly stronger controls.
Why is A.7.2 Physical Entry Controls Important?
Unauthorized physical access can result in:
- Theft of laptops or other equipment
- Unauthorized access to confidential information
- Viewing or photographing sensitive documents
- Tampering with network equipment
- Installation of unauthorized devices
- Theft of backup media
- Damage to critical systems
- Social engineering or impersonation
- Unauthorized access by former employees
- Loss of physical records
- Physical security incidents that become cybersecurity incidents
For example, if an unauthorized person can freely enter a room containing network equipment, they may be able to:
- Disconnect equipment
- Connect an unauthorized device
- Access network ports
- Photograph configuration information
- Steal equipment
- Tamper with physical security devices
Simple Principle
Control who can enter, where they can enter, and what happens when someone no longer needs access.
What Does A.7.2 Require?
Organizations should establish and maintain appropriate physical entry controls for areas where information and associated assets are located.
This normally means defining:
- Who is authorized to enter
- Which areas they are authorized to enter
- How access is granted
- How access is verified
- How visitors are managed
- How access is revoked
- How physical entry is monitored where appropriate
- How access records are maintained
- How exceptions and physical security incidents are handled
The organization should apply controls according to:
- Information sensitivity
- Asset criticality
- Physical location
- Business requirements
- Threat environment
- Number and type of personnel
- Visitor activity
- Regulatory or contractual requirements
There is no requirement for every startup to install expensive biometric systems.
A practical combination of:
- Locked doors
- Keys or access cards
- Authorized access lists
- Visitor registration
- Escort requirements
- CCTV where appropriate
- Access reviews
- Immediate access revocation
may be sufficient for many organizations.
A.7.1 vs A.7.2
These two controls are closely connected but have different purposes.
| Control | Main Purpose |
|---|---|
| A.7.1 Physical Security Perimeters | Defines and protects the physical boundary |
| A.7.2 Physical Entry Controls | Controls who is allowed to cross that boundary |
Example
A company has a restricted network room.
A.7.1:
The network room is identified as a restricted physical area.
A.7.2:
Only authorized IT administrators can enter the network room, using an access card or key.
So:
A.7.1 = Where should physical protection apply?
A.7.2 = Who is allowed to enter?
Activities Required to Implement A.7.2
1. Identify Protected Areas
Start by identifying areas where unauthorized physical access could create an information-security risk.
Examples:
- Main office
- Network room
- Server room
- Finance department
- HR records area
- Document storage
- Backup storage
- Security operations area
- Data center
- Research/development laboratory
Not every room needs restricted access.
2. Classify Physical Areas
Create appropriate physical security zones.
For example:
| Zone | Example | Typical Access |
|---|---|---|
| Public | Reception | Anyone |
| General | Employee workspace | Employees |
| Restricted | HR/Finance | Authorized employees |
| Highly Restricted | Network room | IT/security personnel |
| Critical | Server/data center | Specifically authorized personnel |
This should align with the organization’s risk assessment.
3. Define Authorized Personnel
For each restricted area, determine who requires access.
Example:
| Area | Authorized Personnel |
|---|---|
| General office | Employees |
| HR records room | HR team |
| Finance room | Finance team |
| Network room | IT administrators |
| Server room | Infrastructure/security team |
| Data center | Specifically authorized personnel |
Access should be based on business need, not convenience.
4. Implement Physical Authentication
The organization should use appropriate methods to verify physical access.
Examples include:
- Physical keys
- Access cards
- RFID cards
- PINs
- Smart locks
- Biometrics
- Security guards
- Reception verification
- Mobile access credentials
The required strength depends on the risk.
Startup Example
A 20-person SaaS company may reasonably use:
Office access card → employee identification → restricted rooms locked separately → visitor registration.
It may not need biometric authentication for every internal door.
5. Control Visitors
Visitors should not automatically receive unrestricted physical access.
The organization should define:
- Visitor registration
- Visitor identification
- Host confirmation
- Visitor badges
- Escort requirements
- Restricted-area rules
- Visitor sign-out
- Badge/key return
Example
A vendor arrives to repair network equipment.
The process could be:
Reception → Identity Verification → Host Confirmation → Visitor Badge → Escort → Restricted Area → Work Completed → Badge Returned → Sign-Out
6. Control Access for Contractors and Temporary Personnel
Contractors may require physical access for:
- Maintenance
- IT support
- Cleaning
- Facilities management
- Security services
- Equipment installation
- Audits
Their access should be appropriate to the task.
For example, a cleaning contractor may need access to the general office but should not automatically have access to the network room.
7. Manage Employee Joiners, Movers and Leavers
Physical access must be included in the Joiner-Mover-Leaver process.
Joiner
When an employee joins:
- Determine required physical areas
- Issue access card/key
- Record issuance
- Explain physical security requirements
Mover
When an employee changes role:
- Review existing access
- Remove unnecessary access
- Grant new required access
- Update access records
Leaver
When an employee leaves:
- Disable access card
- Recover keys
- Recover badges
- Remove physical access permissions
- Record completion
Simple Rule
A person should not retain physical access simply because nobody remembered to remove it.
8. Maintain Physical Access Records
Where appropriate, organizations should maintain evidence showing:
- Who has access
- Which areas they can access
- When access was granted
- Who approved it
- When it was reviewed
- When it was revoked
Electronic access-control systems may automatically maintain access logs.
For manual systems, organizations may maintain:
- Key register
- Access-card register
- Authorized-access list
- Visitor register
9. Review Physical Access
Physical access should be periodically reviewed.
For example:
Quarterly Physical Access Review
Check:
- Current employees
- Former employees
- Transferred employees
- Contractors
- Temporary workers
- Visitors
- Lost cards
- Unreturned keys
- Excessive access
Example:
HR confirms that five employees left during the quarter. IT/facilities confirms their access cards were disabled and returned where applicable.
10. Handle Lost or Stolen Access Credentials
Physical credentials should be treated as security-sensitive.
Examples:
- Lost access card
- Lost office key
- Stolen badge
- Compromised PIN
- Shared access card
The organization should define how these events are reported and handled.
Example:
Employee reports lost card → Access disabled → Replacement issued → Incident recorded → Access reviewed
Startup Example
Consider a 40-person SaaS startup operating from a leased office.
The company has:
- Reception
- Open workspace
- HR/Finance room
- Meeting rooms
- Network room
- Storage room
The company implements:
General Office
Employees use access cards to enter the office.
HR/Finance
Only authorized HR and Finance personnel can access the room.
Network Room
Only authorized IT personnel can enter.
Visitors
Visitors register at reception and are accompanied when entering restricted areas.
Employees Leaving
HR notifies IT/facilities → access card disabled → key/badge recovered → access record updated.
Result
The company has a practical physical entry-control system without implementing unnecessarily expensive technology.
Physical Entry Control Matrix
A simple matrix can help demonstrate that access is intentional.
| Area | Security Level | Authorized Personnel | Access Method | Visitor Access | Review Frequency |
|---|---|---|---|---|---|
| Reception | Public | Everyone | Open | Yes | N/A |
| General Office | General | Employees | Access Card | Controlled | Annual |
| HR Room | Restricted | HR | Access Card/Key | Escorted | Quarterly |
| Finance Room | Restricted | Finance | Access Card/Key | Escorted | Quarterly |
| Network Room | Highly Restricted | IT | Access Card/Key | Escorted | Quarterly |
| Server Room | Critical | Authorized Infrastructure Team | Strong Physical Access Control | Exceptional | Quarterly |
Physical Access Authorization Register
A startup can maintain a simple register.
| Person | Department | Area | Access Approved By | Access Method | Granted Date | Review Date | Status |
|---|---|---|---|---|---|---|---|
| Employee A | IT | Network Room | IT Manager | Access Card | 01-Apr | 30-Jun | Active |
| Employee B | HR | HR Room | HR Manager | Key | 05-Apr | 30-Jun | Active |
| Contractor C | IT Vendor | Network Room | IT Manager | Temporary Card | 10-Jun | 10-Jun | Expired |
The register does not need to be complicated.
The objective is to demonstrate:
Physical access is authorized, controlled and reviewed.
Visitor Management Register
A basic visitor register may contain:
| Visitor | Organization | Host | Purpose | Entry | Exit | Badge No. | Escort |
|---|---|---|---|---|---|---|---|
| John Smith | ABC Ltd | IT Manager | Network Support | 10:00 | 12:00 | V-021 | Yes |
| Jane Doe | XYZ Ltd | HR Manager | Meeting | 14:00 | 15:00 | V-022 | Yes |
Organizations should avoid collecting unnecessary personal information and should handle visitor information appropriately.
What About Small Startups?
A startup should not create a complex physical-security program just to satisfy ISO 27001.
Consider the actual environment.
Scenario 1: Traditional Office
The startup operates from a dedicated office.
Potential controls:
- Locked office entrance
- Employee access cards
- Visitor register
- Restricted rooms
- Key register
- Access reviews
Scenario 2: Coworking Space
The startup uses a coworking facility.
The building operator may control:
- Building entrance
- Reception
- Elevators
- CCTV
- Floor access
- Security personnel
The startup should understand which physical controls are provided by the coworking provider and what responsibilities remain with the startup.
This should also connect with supplier/cloud/facility risk management.
Scenario 3: Fully Remote Startup
There may be no dedicated corporate office.
The organization should still consider:
- Employee devices
- Home working
- Physical protection of laptops
- Confidential documents
- Remote-working requirements
- Access to coworking spaces
- Storage of backup media, if any
A.7.2 should reflect the organization’s actual physical environment.
Physical Entry Controls for Cloud-First Startups
A common misunderstanding is:
“We use AWS/Azure/GCP, so physical entry controls are not our responsibility.”
The cloud provider may operate the physical data centers, but the organization still needs to understand its own physical-security responsibilities.
For example, the startup may still have:
- Corporate offices
- Employee laptops
- Networking equipment
- Physical documents
- Backup devices
- Access cards
- Meeting rooms
- Home-working environments
For cloud infrastructure, the organization can evaluate the provider’s physical-security controls through appropriate assurance information such as:
- SOC reports
- ISO certifications
- Contractual commitments
- Supplier assessments
- Security documentation
This connects A.7.2 with supplier and cloud-service controls.
Audit Evidence for A.7.2
An auditor may request evidence such as:
Policies and Procedures
- Physical Security Policy
- Physical Entry Control Procedure
- Visitor Management Procedure
- Access Control Policy
- Joiner-Mover-Leaver Procedure
Registers
- Physical Access Register
- Key Register
- Access Card Register
- Restricted Area Register
- Visitor Register
- Contractor Access Register
System Evidence
- Door access logs
- Access-card records
- Access-control system reports
- CCTV arrangements where applicable
- Security guard logs
Operational Evidence
- Physical access approvals
- Access reviews
- Access revocation records
- Lost-card reports
- Visitor records
- Physical security inspection records
- Physical security incident records
Third-Party Evidence
Where physical infrastructure is outsourced:
- Data-center certifications
- SOC reports
- Supplier assessments
- Contractual security requirements
- Physical-security information from providers
Audit Checklist for A.7.2
An auditor may ask:
Physical Areas
- Have you identified areas requiring physical access controls?
- How are restricted areas identified?
- Which areas contain sensitive information or critical equipment?
Authorization
- Who is authorized to enter restricted areas?
- Who approves physical access?
- How do you determine access requirements?
Employees
- What happens when a new employee joins?
- What happens when an employee changes roles?
- What happens when an employee leaves?
Visitors
- How are visitors identified?
- Are visitors required to sign in?
- Are visitors escorted?
- Can visitors enter restricted areas?
Contractors
- How do you control contractor access?
- How do you control temporary access?
- How do you ensure temporary access expires?
Monitoring
- Do you maintain physical access logs?
- How often are physical access rights reviewed?
- What happens when an access card is lost?
Evidence
- Can you show an example of an approved access request?
- Can you show evidence of a recent access review?
- Can you show evidence that a former employee’s access was revoked?
Common Mistakes
1. Giving Everyone the Same Access
Employees should not automatically have access to every physical area.
2. No Visitor Controls
Allowing visitors to move freely through the office can create unnecessary risk.
3. Forgetting Contractors
Contractors, vendors and temporary workers may require physical access and should be included in the process.
4. Not Revoking Access
A former employee retaining an active access card is a common control weakness.
5. No Evidence
Having a door lock is not enough to demonstrate a controlled process.
The organization should be able to demonstrate:
Who → approved by whom → access to what → when → how → reviewed when → revoked when
6. Overengineering
A small startup does not necessarily need:
- Biometrics everywhere
- Multiple security guards
- Complex surveillance systems
- Expensive access-control platforms
Controls should be proportionate to risk.
7. Ignoring Shared Offices
Coworking spaces and serviced offices still need to be considered in the physical-security risk assessment.
8. Assuming Cloud Means No Physical Security Responsibility
Cloud infrastructure reduces the organization’s direct responsibility for data-center physical controls, but it does not eliminate physical security responsibilities across the organization.
Practical Startup Implementation Model
A startup can implement A.7.2 using this simple lifecycle:
Identify → Classify → Authorize → Control → Monitor → Review → Revoke → Record → Improve
1. Identify
Identify areas requiring controlled physical access.
2. Classify
Determine the sensitivity/criticality of each area.
3. Authorize
Define who needs access and who approves it.
4. Control
Implement appropriate access mechanisms.
5. Monitor
Maintain logs or other appropriate records.
6. Review
Periodically verify that access remains necessary.
7. Revoke
Remove access when employment, role or business need changes.
8. Record
Maintain evidence of approvals, changes and reviews.
9. Improve
Address incidents, audit findings and identified weaknesses.
Policy vs. Process vs. Evidence
Understanding this distinction is useful for ISO 27001 implementation.
| Element | Example |
|---|---|
| Policy | Physical Entry Control Policy |
| Process | Employee physical-access request and approval process |
| Procedure | Visitor registration procedure |
| Register | Physical Access Register |
| System Control | Access-card system |
| Evidence | Access logs and approval records |
| Review | Quarterly physical-access review |
A policy explains what the organization requires.
A process explains how it is managed.
Evidence demonstrates that it actually happened.
Relationship With Other ISO 27001 Controls
A.7.2 does not operate independently.
It connects with:
- A.5.9 – Inventory of information and other associated assets
- A.5.11 – Return of assets
- A.5.15 – Access control
- A.5.16 – Identity management
- A.5.18 – Access rights
- A.5.19 – Information security in supplier relationships
- A.5.23 – Information security for use of cloud services
- A.6.5 – Responsibilities after termination or change of employment
- A.6.7 – Remote working
- A.7.1 – Physical security perimeters
- A.7.3 – Securing offices, rooms and facilities
- A.7.4 – Physical security monitoring
- A.7.6 – Working in secure areas
- A.7.7 – Clear desk and clear screen
- A.7.8 – Equipment siting and protection
- A.7.9 – Security of assets off-premises
Key Relationship
A.7.1 defines the protected boundary.
A.7.2 controls entry through that boundary.
A.7.3 protects the offices, rooms and facilities.
A.7.4 provides appropriate physical monitoring.
Together, they create a more complete physical-security framework.
Useful Resources and Draft Documents
Organizations implementing A.7.2 may consider creating:
- Physical Entry Control Policy
[Insert Draft Document Link] - Physical Access Control Procedure
[Insert Draft Document Link] - Physical Access Authorization Form
[Insert Draft Document Link] - Physical Access Register
[Insert Draft Document Link] - Restricted Area Access List
[Insert Draft Document Link] - Visitor Management Procedure
[Insert Draft Document Link] - Visitor Register
[Insert Draft Document Link] - Contractor Physical Access Procedure
[Insert Draft Document Link] - Key and Access Card Register
[Insert Draft Document Link] - Physical Access Review Checklist
[Insert Draft Document Link] - Lost Access Card / Key Incident Form
[Insert Draft Document Link] - Physical Security Inspection Checklist
[Insert Draft Document Link] - Physical Security Incident Report
[Insert Draft Document Link]
Questions an Auditor May Ask Management
An auditor may ask:
“How do you know who is authorized to enter your restricted areas?”
A good answer should be supported by an access authorization process and appropriate records.
“Show me your physical access register.”
The organization should be able to demonstrate current access.
“What happens when an employee leaves?”
The answer should include physical access revocation and recovery of keys/cards where applicable.
“How do you manage visitors?”
The organization should explain its visitor identification, authorization and monitoring process.
“Can a visitor enter your network room?”
The answer should be based on the organization’s defined physical security requirements rather than informal practice.
“Show me evidence that physical access was reviewed.”
The organization should be able to provide a recent review or equivalent evidence appropriate to its environment.
Startup-Focused Quick Summary
For a startup, A.7.2 does not mean buying an expensive biometric access-control system.
Start with the basics:
Step 1
Identify restricted physical areas.
Step 2
Define who needs access.
Step 3
Obtain appropriate approval.
Step 4
Use suitable access controls.
Step 5
Control visitors and contractors.
Step 6
Review access periodically.
Step 7
Immediately revoke access when no longer required.
Step 8
Keep enough evidence to demonstrate that the process operates.
Simple Startup Principle
The objective is not to make physical access complicated. The objective is to make unauthorized physical access difficult and authorized access accountable.
Startup-Focused Final Takeaway
A.7.2 is fundamentally about controlling physical entry to protect information and associated assets.
For a startup, the implementation can be straightforward:
Identify protected areas → Define authorized people → Approve access → Control entry → Manage visitors → Review access → Revoke access → Maintain evidence
The key audit question is not:
“Do you have an access card system?”
It is:
“Can you demonstrate that physical access is authorized, controlled, reviewed and revoked when no longer required?”
If the answer is supported by a practical process and reliable evidence, the organization is in a much stronger position to demonstrate the intent of A.7.2.
