Physical entry
Purpose
Make sure only authorised people can physically enter areas holding the organisation information and assets.
How to meet this control
In short: Protect secure areas with appropriate entry controls.
- Step 01Deploy badge or access-card entry for staff with stronger authentication, such as PIN-plus-card or biometrics, on sensitive rooms
- Step 02Operate a visitor management process where guests sign in, are issued a temporary badge, and are escorted, with the record retained
- Step 03Require visible ID for all personnel and encourage staff to challenge or report anyone unbadged or unescorted
- Step 04Review and revoke access-card rights regularly, especially after leavers and role changes, and reconcile the badge list against current staff
- Step 05Control delivery and loading areas separately so couriers do not reach internal zones, and inspect incoming goods
- Step 06Run a key-management process for physical keys with issue, return and periodic audit
Tip: Badge access plus a visitor log/escort policy.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Limit site and building entry to authorised staff, and regularly review and revoke access rights
- ›Keep and protect a secure logbook or electronic record of all entries
- ›Use authentication such as access cards, biometrics or two-factor methods for sensitive areas
- ›Staff a reception or use another method to control who reaches the site
- ›Require everyone to wear visible ID and report anyone unescorted or without a badge
- ›Give suppliers restricted, authorised and monitored access only when needed
- ›Authenticate, log and supervise visitors, admitting them only for approved purposes
- ›Control delivery and loading areas, inspect incoming goods, and run a key management process
Audit evidence to keep
- - Access-card and door-controller logs showing entries to secure areas
- - The visitor sign-in log for a defined period
- - Access-rights review records reconciling badges against active staff
- - The visitor and escort policy
- - Key-issue and key-return register for physical keys
Common mistakes
- - Relying on office trust without logs
- - Not tracking assets used away from the office
- - Disposing equipment without wipe or destruction evidence
Owner, cadence, and proof
Assign one accountable owner for A.7.2. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.