ISO 27001 Annex A 7.2 Physical Entry requires organisations to control physical access to secure zones by keeping clear written entry rules. Teams must record every entry and exit, while managers review access logs regularly to protect physical data assets.
Table of contents
Key Takeaways
- Control physical area access: Protect secure zones by restricting entry to approved workforce members and guests.
- Document site entry procedures: Keep clear, written rules for physical site entry stored centrally for team access.
- Log all entries and exits: Maintain complete logs of every person entering and leaving restricted physical zones.
- Review access records regularly: Require management to audit physical entry logs routinely to spot unusual activity fast.
- Protect physical information assets: Ensure only authorized people enter sensitive spaces to keep data and hardware safe.
- Verify visitor badges on entry: Check visitor identities and issue clear temporary badges before granting entry to secure zones.
- Revoke unused entry access fast: Remove physical entry rights right away when employees change roles or leave the business.
- Audit entry points routinely: Inspect physical doors, keypads, and entry barriers regularly to ensure controls work properly.
How to Implement ISO 27001 Annex A 7.2
- Define secure zones on site maps: Mark all secure areas clearly on physical floor plans stored in a central team folder.
- Set up formal access workflows: Require staff to submit formal online forms for all physical site access requests.
- Require manager sign-off for entry: Ensure the local site lead reviews and approves every physical access ticket before issuing badges.
- Maintain central visitor registers: Keep a complete digital log of all guest visits, entry times, and staff guides in a shared workspace.
- Audit entry logs every month: Check physical access records monthly and save the review notes in official meeting records.
- Cancel physical access right away: Remove site access rights immediately when a worker leaves the firm or changes roles.
- Issue visible visitor badges: Require all guests to wear clear identity passes while walking through secure company areas.
- Inspect entry barriers routinely: Test physical door locks and entry points regularly to ensure all access controls work properly.
How to Audit ISO 27001 Annex A 7.2
- Review physical entry rules: Inspect written site security plans to confirm entry rules and perimeter boundaries stay up to date.
- Verify manager entry approvals: Sample physical access request forms to confirm site leads approved every active badge.
- Inspect visitor sign in logs: Check guest entry books to ensure visitor names, entry times, and staff guides stay fully logged.
- Audit monthly access reviews: Review past management records to verify site leads check entry logs each month.
- Test access cancellation speed: Compare worker exit dates against badge removal logs to ensure access gets cut fast.
- Check visitor pass controls: Walk entry points to verify visitors receive clear passes and wear them visibly across secure zones.
- Inspect physical entry doors: Test physical door locks, keypads, and automatic gates to confirm they limit access properly.
- Verify guest escort rules: Interview staff to confirm external visitors stay accompanied at all times inside secure areas.
- Audit vendor access rights: Check entry records for external cleaners and repair crews to confirm limited, short term access.
- Inspect delivery drop off zones: Verify delivery drivers drop packages in set areas without entering core work rooms alone.
- Review tailgating check rules: Check spot inspection records and entry signs meant to stop unbadged people from following staff.
- Verify breach incident logs: Sample past security logs to confirm unapproved entry attempts were checked fast.
- Audit emergency exit door locks: Test emergency exit doors to confirm they stay locked from the outside while opening freely from inside.
- Inspect spare access card safety: Review storage spots for spare badges and keys to ensure unissued passes sit locked away securely.
Audit Evidence Checklist
- Physical site access policy: Supply an approved policy document outlining entry rules, perimeter boundaries, and site access tiers stored in a central version controlled portal.
- Approved access request records: Present completed access request tickets proving site leads approved entry badges for all staff and contractors.
- Management log review minutes: Provide official meeting records showing managers audit site entry and exit logs on a regular schedule.
- Digital visitor sign in registers: Produce guest entry records showing full timestamps, host worker signatures, and visit reasons.
- Physical security signage photos: Provide clear photos showing warning signs and access restriction labels posted at site entry points.
- Access cancellation exit logs: Present staff exit records proving physical access cards and entry rights were removed fast upon worker departure.
- Physical key inventory records: Supply detailed logs tracking all physical keys, master keys, and entry badges issued to staff and vendors.
- Contractor supervision sign offs: Provide signed visitor logs confirming third party repair teams and cleaners stay accompanied inside secure zones.
- Entry barrier maintenance tickets: Produce work receipts proving physical door locks, keypads, and automatic entry gates undergo routine repairs.
- Physical breach incident reports: Supply investigation records for past tailgating alerts, unapproved entry attempts, or door fault tickets.
What to Teach Employees
- Wear identity badges visibly: Teach workers to display security passes clearly at all times while inside company premises.
- Stop tailgating at entry gates: Remind staff never to let unbadged people follow them through doors or physical entry points.
- Challenge unknown visitors fast: Instruct employees to politely question or report anyone walking through secure areas without a visible pass.
- Sign in all external guests: Ensure staff register every visitor in central entry logs upon arrival at site access points.
- Escort visitors continuously: Teach workers to accompany guests at all times until they exit the physical security perimeter.
- Protect entry access cards: Remind staff never to lend physical access badges or keys to colleagues or external guests.
- Report lost access cards fast: Teach employees to log missing badges or stolen keys right away in central portals so rights get cut fast.
- Submit access request forms: Instruct staff to follow official approval steps before entering restricted work zones or new sites.
- Verify contractor identity passes: Teach teams to check ID passes before granting external repair crews or cleaners physical site entry.
- Keep emergency exits clear: Remind workers that emergency exit doors must remain closed and unblocked during normal daily work hours.
- Direct deliveries to set drop zones: Train staff to ensure delivery drivers stay in designated drop off areas without entering main work rooms.
- Return entry cards upon leaving: Instruct departing workers to hand back all physical badges and site access passes on their final working day.
- Report entry barrier damage: Teach staff to report faulty door latches or broken entry gates right away to fix safety gaps fast.
- Follow out of hours entry rules: Ensure workers complete sign in logs when entering or leaving company sites outside normal working hours.
Common Implementation Challenges
- Allowing door tailgating: Staff let unbadged people follow them through entry gates. Run spot checks and train workers to challenge unknown guests fast.
- Failing to log visitors: Guests enter offices without signing in at reception. Use a central sign in register to track every visitor name and entry time.
- Slow access removal: Departing staff keep active entry cards after leaving the business. Link worker exit steps directly to badge cancellation tasks.
- Skipping monthly log reviews: Managers forget to audit physical entry and exit records regularly. Set calendar reminders to review access logs every month.
- Missing access approvals: Badges get issued without formal site lead approval. Require online request forms and manager sign offs before granting access.
- Unescorted third party workers: Cleaners and repair crews roam secure areas alone. Require signed visitor logs and active staff guides for all vendors.
- Sharing access cards: Staff lend physical security badges or keys to colleagues. Remind workers never to share access passes under any circumstances.
- Propping open entry doors: Workers use wedges or chairs to keep security doors open for convenience. Install door alarms and self closing hinges to stop this habit.
- Unsecured delivery zones: Delivery drivers walk deep into office work areas without checks. Set up clear drop off points near reception to keep drivers out.
- Poor visitor badge visibility: Guests walk through secure zones without wearing temporary passes. Issue clear ID badges and enforce visible wear rules.
- Ignoring broken entry gear: Faulty door latches and broken card readers go unreported for days. Set up simple reporting paths in central portals to fix locks fast.
- Missing security signs: Entry points lack clear warnings about visitor rules and secure zones. Place visible notification labels on all doors leading to secure areas.
- Skipping out of hours rules: Staff enter and leave office sites late at night without signing logs. Require manual or digital sign ins for all after hours visits.
- Lack of physical security training: New hires miss site access rules during onboarding. Require all workers to complete physical entry training when joining.
How to Measure Effectiveness (KPIs)
- Physical access removal speed: Track the average time taken to cancel badge rights and recover entry passes after staff departure dates.
- Unapproved entry attempt count: Monitor the total number of tailgating events, forced door alerts, or unapproved access attempts detected at entry points.
- Visitor sign in log accuracy: Measure the share of guest visits recorded with complete entry times, host signatures, and clear exit times.
- Monthly log review completion: Track the percentage of monthly access log checks completed and signed off on time by site leads.
- Visitor escort compliance rate: Measure the share of guest and vendor visits logged with an assigned staff escort throughout their stay.
- Entry barrier repair speed: Measure the average time taken to fix broken door locks, faulty keypads, or gate barriers after reporting.
- Physical access audit findings: Track the total number of physical entry control flaws found during internal checks and resolved before re-audit.
- Staff entry security training rate: Track the proportion of workforce members who complete site entry rules and tailgating challenge training.
- Lost access card frequency: Count the number of lost, stolen, or missing physical entry badges reported each quarter to lower site risk.
- Out of hours entry log checks: Measure the share of after-hours site visits matched correctly against approved access logs.
- Unapproved access card count: Track the total number of active physical badges found during quarterly checks that lack valid manager sign-offs.
- Contractor sign in compliance: Check third-party worker sign-in records monthly to confirm complete access tracking for external teams.
- Emergency exit door check rate: Measure the share of routine checks proving emergency doors remain locked from the outside while opening freely inside.
- Badge audit discrepancy rate: Track the percentage of active user entries in physical access logs that do not match live staff records.
Related ISO 27001 Controls
ISO 27001 Annex A 7.2 does not work in isolation. It links to several core clauses:
- ISO 27001 Clause 5.3: Roles and responsibilities for site security.
- ISO 27001 Clause 9.1: Monitoring and measurement of entry point effectiveness.
- ISO 27001 Annex A 7.1: The physical perimeters that these entries protect.


