ISO27001:2022 – A7.2

Physical entry controls

 Want to fast track your ISO 27001 journey? 

Our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements. Take a look, and when you buy it, you also receive our “Real Easy Guide To ISO27001” book (available on Amazon).

Introduction to ISO 27001 – A7.2

The purpose of ISO 27001 A7.2 is to ensure that you’re not only thinking about technical access controls, but you’re also considering physical entry controls too.  Ensuring these are in place so that only authorised personnel and interested parties have access to your organisation’s information and associated assets.

What does the standard require?

The standard states that “Secure areas shall be protected by appropriate entry controls and access points.” (A7.2 – Physical entry controls).

Why is this required?

At home, you have locks on your car doors, on your doors to your house, and on your windows.  You might also install a combination lock on your garden shed, which only adults can access (because of the presence of sharp tools or toxic paint and chemicals).   

 

You implement physical entry controls to allow access to those who need it at home. So, it makes sense that you do this in the workplace. For example, not everyone who visits your offices will need access to your server or comms cabinet or room. 

By implementing these controls, either at home or in the workplace, you reduce the risk of people either injuring themselves or accessing unauthorised information. The risks you’re looking to mitigate will vary, but it can range from accidental damage through to deliberate theft, tampering or sabotage.

 

Keep in mind that physical entry controls aren’t only there to protect you, they are there to protect the individual from stumbling into places which could place them at risk, too.

What the auditor is looking for

The auditor will look for evidence that you have implemented multiple layers of physical access controls, from the physical elements through to policies and procedures.  Typical evidence that an auditor will review will include;

  • Physical Access controls (e.g. RFID card access, bio-metric, PIN codes, scanners)
  • Visitor access management (e.g. visitor badges with limited access rights)
  • Personnel access management processes (e.g. allocation of keys and RFID cards)
  • Access Control policy
  • Access rights reviews
  • Onboarding and off-boarding processes
  • Incident logs
  • Risk Register

Even when your audits are remote, the auditor will want to have a ‘virtual tour’ of your site, so be prepared to show them how you manage physical entry into your office. For example, if you are in a multi-tenanted building, demonstrate to them how you separate entry into your office space from the other tenants in the building.  If you have areas within your office space which is further controlled by limited access. For example, if you have a server room, then show them how only IT personnel have access to that area.

What do you need to do?

First, take a walk around your premises to review your physical entry controls and note any vulnerabilities on your risk register. For example, does the front door have a PIN code that is known to all employees and visitors, but you haven’t changed it for several years? Does it need changing? Is this a risk? What about any deliveries or loading areas? Are these under your control? What access do they provide? Are there any emergency fire escapes and stairs that can allow easy access to your premises?

 

Remember that physical entry controls go beyond the perimeter, so be sure to look internally at your office space and identify any additional areas which require different physical security to be implemented.

 

You should review any relevant policies and procedures you have which relate to physical access, which most likely includes your Access Control Policy and your onboarding processes.  Access Control policies often focus on logical access to systems, and neglect to consider the physical access controls required.  Don’t make this mistake; Ensure your policies outline the responsibilities placed upon your personnel and interested parties. For example, stating that they should not share ID passes, or PIN codes.

 

Update your onboarding and off-boarding processes to include the allocation and collection of keys and RFID cards.  The off-boarding process should also include consideration for changing PIN codes when someone leaves the business. Of course, you might not want to do this every time someone leaves, but there may be exceptional situations where this becomes necessary. At the very least, ensure that you change PIN codes periodically (e.g. bi-annually)

Q & A

Do I need a process for lost or stolen badges?

Yes, this should be in place. It doesn’t have to be complicated, but it should be clear to personnel and relevant interested parties what needs to happen if a card is lost. It should also be clear to the receptionist (if you have one), what to do if someone presents themselves to the front desk claiming to have lost their card.  Do they let them in? Do they call someone? Develop a simple step process which protects your information and other assets.

Difficulty rating

We rate this a 2.5 out of 5 difficulty rating. This ISO27001 control isn’t difficult, but because it’s unlikely that you’re going to have a lot of say in what defences are, you are going to need to think strategically about how identify risks. If you find there are vulnerabilities, then you should provide guidance on managing these by designing additional security measures. Remember that you need to evidence that entry controls are in place, using a variety of physical evidence, and policies and procedures. Therefore, although this is a relatively simple control to understand, it can quickly become complex.

More questions?

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you like to consider buying our book, “The Real Easy Guide to ISO27001” which is available on Amazon.  

Fastback your journey to ISO27001 and buy our Policies to get started TODAY!

Take a look at our “ISO 27001:2022 Policy Pack” and when coupled with our book you’ll have everything you need to succeed in achieving ISO 27001 certification!

ISO 27001 – A7.2 - Physical Entry Controls