A.7.2A.7 Physical controls

Physical entry

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.7.2 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Make sure only authorised people can physically enter areas holding the organisation information and assets.

How to meet this control

In short: Protect secure areas with appropriate entry controls.

  1. Step 01Deploy badge or access-card entry for staff with stronger authentication, such as PIN-plus-card or biometrics, on sensitive rooms
  2. Step 02Operate a visitor management process where guests sign in, are issued a temporary badge, and are escorted, with the record retained
  3. Step 03Require visible ID for all personnel and encourage staff to challenge or report anyone unbadged or unescorted
  4. Step 04Review and revoke access-card rights regularly, especially after leavers and role changes, and reconcile the badge list against current staff
  5. Step 05Control delivery and loading areas separately so couriers do not reach internal zones, and inspect incoming goods
  6. Step 06Run a key-management process for physical keys with issue, return and periodic audit

Tip: Badge access plus a visitor log/escort policy.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Limit site and building entry to authorised staff, and regularly review and revoke access rights
  • ›Keep and protect a secure logbook or electronic record of all entries
  • ›Use authentication such as access cards, biometrics or two-factor methods for sensitive areas
  • ›Staff a reception or use another method to control who reaches the site
  • ›Require everyone to wear visible ID and report anyone unescorted or without a badge
  • ›Give suppliers restricted, authorised and monitored access only when needed
  • ›Authenticate, log and supervise visitors, admitting them only for approved purposes
  • ›Control delivery and loading areas, inspect incoming goods, and run a key management process

Audit evidence to keep

  • - Access-card and door-controller logs showing entries to secure areas
  • - The visitor sign-in log for a defined period
  • - Access-rights review records reconciling badges against active staff
  • - The visitor and escort policy
  • - Key-issue and key-return register for physical keys

Common mistakes

  • - Relying on office trust without logs
  • - Not tracking assets used away from the office
  • - Disposing equipment without wipe or destruction evidence

Owner, cadence, and proof

Assign one accountable owner for A.7.2. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all physical controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.