Skip to content
compliancebase
ISO 27001A.7 — Physical entry

A.7.2

Physical entry

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Secure entry points to ensure only authorized personnel access secure areas.

Points of focus

  • Control entry to any secure area you operate with badges, keys, or equivalent mechanisms
  • Log and escort visitors and vendors; never leave them unsupervised in areas with information processing facilities
  • Separate delivery/loading areas from areas holding sensitive equipment or media
  • Document a clear, specific rationale wherever entry controls are marked not applicable

Implementation notes

For any leased or owned office, define entry control mechanics: badge or key access to the space, a visitor log capturing name, purpose, host, and time in/out, and an escort requirement for anyone without standing access — vendors, interviewees, delivery personnel. Keep delivery and mailroom areas separate from any space holding servers, network equipment, or sensitive physical media, even in a small office. Tie badge deprovisioning into the same joiner-mover-leaver process that handles system access, since a terminated employee retaining building access for two weeks is functionally the same failure as retaining a system account. For companies with no controlled facility — fully remote teams using co-working day passes or nothing at all — mark this not applicable in the SoA, but write the actual reason ("no company-controlled facility; workforce is fully remote; co-working access is managed entirely by third-party landlords") rather than a bare N/A. If you inherit data-center physical entry controls through a cloud or colo provider, reference their assurance report the same way you would for A.7.1, rather than re-describing badge systems you don't operate.

Audit tip: If entry controls are not applicable because you have no controlled facility, say exactly that and stop — don't pad the SoA with generic badge-system language for a control you don't operate. If you do have an office, pull one badge log excerpt and one visitor log excerpt with real dates.

Evidence auditors typically request:

  • Badge system access logs or a visitor sign-in register with dates and escort notes
  • Office security procedure describing entry rules, visitor handling, and delivery-area separation
  • Deactivation records showing badge/key access removed promptly for departed employees
  • Documented rationale where the control is excluded (e.g., fully remote workforce, no company-controlled facility)

Common gaps

  • Visitor sign-in exists as a paper sheet at reception but no one can produce it when an auditor asks for a sample from six months ago
  • Former employees' badge access wasn't deactivated until weeks after their termination date
  • The control is marked not applicable with no explanation, even though the company leases a small office where the server closet used to sit

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.7.2This control
SOC 2CC6.4, CC6.5CC6.4 and CC6.5 cover physical access restriction and removal of access when no longer required — the badge-deactivation timing auditors sample under A.7.2 maps directly to the same evidence SOC 2 examiners request.
HIPAA164.310(a)164.310(a)(2)(iii) — Access Control and Validation Procedures — requires controlling and validating physical access based on role, relevant if any office space stores devices or media containing ePHI.

Primary sources

Frequently Asked Questions

Often yes, but the SoA entry needs a specific, honest rationale — no controlled facility, no leased office — rather than a blanket N/A used for every physical control regardless of whether it actually applies.

ISO 27001 doesn't fix a number of hours, but auditors expect it to track the same timeline as system deprovisioning — same day or next business day is the common benchmark for SaaS companies.

Yes, if the visitor enters a secure area. Name, purpose, host, and time in/out is the minimum an auditor expects to sample from the log.

Document what the landlord controls (main building entry) versus what you control (your own suite, if any). Physical entry evidence should focus on the boundary you actually manage.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above