A.7.2
Physical entry
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Secure entry points to ensure only authorized personnel access secure areas.
Points of focus
- Control entry to any secure area you operate with badges, keys, or equivalent mechanisms
- Log and escort visitors and vendors; never leave them unsupervised in areas with information processing facilities
- Separate delivery/loading areas from areas holding sensitive equipment or media
- Document a clear, specific rationale wherever entry controls are marked not applicable
Implementation notes
For any leased or owned office, define entry control mechanics: badge or key access to the space, a visitor log capturing name, purpose, host, and time in/out, and an escort requirement for anyone without standing access — vendors, interviewees, delivery personnel. Keep delivery and mailroom areas separate from any space holding servers, network equipment, or sensitive physical media, even in a small office. Tie badge deprovisioning into the same joiner-mover-leaver process that handles system access, since a terminated employee retaining building access for two weeks is functionally the same failure as retaining a system account. For companies with no controlled facility — fully remote teams using co-working day passes or nothing at all — mark this not applicable in the SoA, but write the actual reason ("no company-controlled facility; workforce is fully remote; co-working access is managed entirely by third-party landlords") rather than a bare N/A. If you inherit data-center physical entry controls through a cloud or colo provider, reference their assurance report the same way you would for A.7.1, rather than re-describing badge systems you don't operate.
Audit tip: If entry controls are not applicable because you have no controlled facility, say exactly that and stop — don't pad the SoA with generic badge-system language for a control you don't operate. If you do have an office, pull one badge log excerpt and one visitor log excerpt with real dates.
Evidence auditors typically request:
- Badge system access logs or a visitor sign-in register with dates and escort notes
- Office security procedure describing entry rules, visitor handling, and delivery-area separation
- Deactivation records showing badge/key access removed promptly for departed employees
- Documented rationale where the control is excluded (e.g., fully remote workforce, no company-controlled facility)
Common gaps
- Visitor sign-in exists as a paper sheet at reception but no one can produce it when an auditor asks for a sample from six months ago
- Former employees' badge access wasn't deactivated until weeks after their termination date
- The control is marked not applicable with no explanation, even though the company leases a small office where the server closet used to sit
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.7.2 | This control |
| SOC 2 | CC6.4, CC6.5 | CC6.4 and CC6.5 cover physical access restriction and removal of access when no longer required — the badge-deactivation timing auditors sample under A.7.2 maps directly to the same evidence SOC 2 examiners request. |
| HIPAA | 164.310(a) | 164.310(a)(2)(iii) — Access Control and Validation Procedures — requires controlling and validating physical access based on role, relevant if any office space stores devices or media containing ePHI. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.7.2)