# Physical and environmental security policy

Source: https://aestech.com.au/policy-templates/#physical-and-environmental-security-policy
Markdown URL: https://aestech.com.au/policy-templates/physical-and-environmental-security-policy.md

Use for ISO 27001 A.7.1 to A.7.14, SOC 2 Security, and PCI DSS requirement 9 physical access controls.

Frameworks: ISO 27001, SOC 2, PCI DSS

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how company facilities, equipment and physical media are protected against unauthorised access, damage, theft and environmental threats.

2. Scope
This policy applies to all company premises, secure areas, equipment, media and the facilities of providers that host company systems. Where the company is fully remote, the requirements apply to data centre and cloud provider facilities and to home working arrangements.

3. Policy statements
- Access to offices and secure areas must be restricted to authorised people and controlled by suitable measures such as locks, access cards or reception controls.
- Visitors must be identified, recorded and supervised in sensitive areas.
- Physical access rights must be reviewed periodically and revoked promptly when no longer needed.
- Equipment must be protected from theft, damage and unauthorised use, and must not be left unattended in insecure locations.
- A clear desk and clear screen practice applies to confidential information.
- Media and equipment containing data must be securely sanitised or destroyed before disposal or reuse.
- Environmental controls such as power protection, fire detection and suitable cooling must protect critical equipment, primarily through the hosting provider.
- Where systems are hosted with cloud or data centre providers, physical security must be confirmed through provider attestations.

4. Roles and responsibilities
- The [Facilities or Office Manager] manages premises access and visitor controls.
- IT manages equipment, media disposal and asset tracking.
- The [Security Lead] reviews physical controls and provider attestations.
- All staff follow clear desk, clear screen and visitor handling rules.

5. Procedures
- Maintain an access list for offices and secure areas and review it periodically.
- Record and supervise visitors.
- Track equipment and media as assets and record secure disposal.
- Obtain and review physical security attestations from hosting providers at least annually.
- Define home working security expectations for remote staff.

6. Evidence and records
Keep access lists and reviews, visitor logs, asset and media inventories, secure disposal records, provider attestations and exception approvals.

7. Review cadence
This policy is reviewed at least annually and after changes to premises or hosting arrangements.

Owner: [role]
Version: [x.y]   Approved by: [name/role]   Date: [date]
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md