ISO 27001 Annex A 7.3 requires organisations to protect internal rooms and work areas using physical locks and entry limits based on data sensitivity. Teams must record physical safety plans inside central portals to maintain clear oversight and pass compliance audits.
Table of contents
Key Takeaways
- Protect internal work areas: Secure rooms and work facilities based on the sensitivity of stored data and assets.
- Restrict room access: Use physical locks and keycard doors to limit site entry to approved staff only.
- Document site safety rules centrally: Store clear physical access policies inside central internal portals for easy management oversight.
- Maintain physical audit trails: Log room access rights and lock checks to provide clear operational proof for auditors.
- Define clear security perimeters: Mark sensitive room boundaries clearly and keep doors locked to stop physical security gaps.
- Review access permissions routinely: Check site access rights regularly to remove physical key privileges for former workers fast.
- Train staff on site security habits: Teach workers to challenge unbadged guests and avoid holding secure doors open for others.
- Audit physical key records: Keep strict logs of physical keys and access badges issued to track site entry rights continuously.
How to Implement ISO 27001 Annex A 7.3
- Map internal work areas: List all work rooms and office spaces in a central document database.
- Classify room risk levels: Rate each room based on the sensitivity of data handled inside.
- Set room access lists: Use central approval systems to grant high-risk room entry to verified staff only.
- Schedule routine door checks: Set recurring task reminders to check door locks and physical barriers regularly.
- Log physical security incidents: Record lock fixes and physical safety slips in central team portals right away.
- Train staff on room security rules: Teach workers to lock door barriers upon exit and keep guest access restricted.
- Audit physical key rights routinely: Review badge and key rights often to revoke physical site access for former staff fast.
- Display clear safety signage: Post visible warning labels on restricted room doors to stop unapproved entry.
How to Audit ISO 27001 Annex A 7.3
- Review physical security policies: Inspect room safety plans in central portals to confirm security zones and entry rules are clear.
- Verify area risk ratings: Check that internal rooms and offices are rated based on data sensitivity and asset value.
- Inspect physical door locks: Walk through premises to test locks, electronic door readers, and self-closing hinges on sensitive doors.
- Audit room access lists: Sample approved user lists for restricted zones to ensure only authorized staff hold entry rights.
- Check physical key records: Review key logs and badge management files to track physical keys issued to workers.
- Inspect visitor sign-in logs: Check visitor registration records and escort logs to verify guests do not enter restricted rooms alone.
- Test access cancellation speed: Compare staff departure dates against badge removal logs to ensure access gets cut fast.
- Verify physical lock repairs: Review maintenance tickets in central portals to confirm broken locks or door gear get fixed right away.
- Check restricted area signs: Walk site zones to ensure warning labels sit posted on doors protecting high-risk areas.
- Audit clean desk habits: Check offices and work areas after hours to ensure sensitive files and badges sit locked away securely.
- Verify staff safety training: Check worker training records to ensure staff know how to challenge unbadged guests in secure zones.
- Review security incident logs: Sample past security breach tickets to confirm room intrusion attempts were checked fast.
- Audit contractor entry controls: Review access permissions issued to third-party cleaners and maintenance workers to confirm full site oversight.
- Inspect room window protections: Verify ground floor windows and glass barriers in restricted rooms feature physical locks or secure films.
Audit Evidence Checklist
- Physical security policy: Supply an approved policy document outlining room access rules, perimeter boundaries, and facility risk tiers.
- Facility risk classification map: Provide a floor plan or document rating rooms and work areas by data sensitivity and asset value.
- Restricted area access lists: Present approved user sign-off sheets and badge permissions showing who holds entry rights to high-risk rooms.
- Physical key register: Produce detailed logs tracking all physical keys, master keys, and access badges issued to staff and contractors.
- Visitor entry registers: Provide visitor sign-in logs and escort sign-off sheets proving guests do not enter secure zones unassisted.
- Access cancellation logs: Present staff exit records showing physical badges and room access rights were removed fast upon departure.
- Lock maintenance records: Supply service receipts and work tickets proving physical locks, door hinges, and electronic readers undergo routine checks.
- Clean desk audit reports: Provide internal inspection logs showing routine after-hours checks for locked drawers and clear work areas.
- Contractor work agreements: Supply signed service terms and supervision logs for external cleaners, utility workers, and repair teams.
- Staff physical safety training records: Provide worker training sign-offs showing completion of site security rules and guest challenge rules.
- Physical security incident tickets: Present past investigation reports for broken locks, propped doors, or unapproved entry attempts.
- Window and perimeter barrier checks: Supply inspection logs confirming ground-floor window locks and physical room barriers stay secure.
- Emergency exit door check logs: Present inspection records proving emergency exit doors stay locked from the outside while opening freely from inside.
- Physical badge audit records: Supply routine inventory logs checking that all physical access cards match active user lists.
What to Teach Employees
- Lock doors when leaving secure areas: Teach staff to lock restricted room doors and private offices every time they step away.
- Never prop open secure doors: Remind workers that propping open fire doors or restricted access doors breaches physical security rules.
- Challenge unbadged visitors fast: Instruct employees to question or report anyone walking through secure zones without a visible badge.
- Stop tailgating at access points: Train staff never to let unverified people follow them through locked doors or entry gates.
- Follow clean desk rules: Teach workers to lock away sensitive files, keys, and access badges at the end of each workday.
- Escort guests at all times: Ensure staff accompany external visitors whenever they pass through restricted office zones.
- Protect physical keys and badges: Remind staff not to lend keys or access cards to colleagues or leave them lying around.
- Report broken locks fast: Teach workers to log damaged door latches, broken hinges, or reader flaws right away in central portals.
- Return keys upon job role changes: Instruct employees to hand back restricted room keys when moving teams or leaving the business.
- Keep window locks secured: Train staff in ground floor or accessible offices to check that windows stay locked at the end of the day.
- Verify contractor badges: Teach teams to check identity badges before letting repair workers or cleaners enter secure rooms.
- Know emergency exit door rules: Ensure workers understand that emergency doors must stay clear and closed during normal daily ops.
- Hide sensitive screens from view: Teach employees to position monitors away from windows and guest areas to stop visual spying.
- Shred sensitive paper notes: Remind workers to drop sensitive prints and notes into locked bin boxes for safe shredding.
Common Implementation Challenges
- Propping open secure doors: Staff hold doors open with wedges or chairs for ease. Use door alarms and self-closing hinges to enforce locked barriers.
- Allowing door tailgating: Staff let unbadged guests follow them into locked rooms. Run spot checks and train staff to challenge unbadged people right away.
- Inconsistent room risk ratings: Teams fail to rate internal offices based on data risk. Map and classify all work areas in a central tracking portal.
- Uncontrolled physical key tracking: Master keys and access badges get handed out without clear records. Maintain a strict key log and check access rights often.
- Slow access cancellation: Departing staff keep physical keys or active access cards after leaving. Link staff departure steps to physical access removal tasks.
- Poor clean desk habits: Sensitive prints and physical keys sit on unattended desks overnight. Conduct after-hours checks to ensure workers lock drawers and cabinets.
- Unsupervised contractor access: External cleaners or repair crews roam secure rooms unescorted. Require signed visitor logs and active staff guides for third parties.
- Ignoring broken door hardware: Damaged latches and faulty readers go unreported for days. Set up simple reporting paths in central portals to fix locks fast.
- Unlocked ground floor windows: Accessible windows stay open or unlocked overnight in quiet rooms. Include window lock checks in daily end-of-day security steps.
- Missing restricted area signs: High-risk rooms lack visible warning labels to stop entry. Place clear warning signs on doors leading to sensitive work zones.
- Visible screen displays: Screens near windows or guest areas allow unwanted visual viewing. Position computer screens away from glass walls or use screen privacy filters.
- Lack of physical safety training: New hires miss local room access rules during induction. Require all workforce members to finish physical security training upon joining.
- Uncontrolled spare key storage: Spare office keys sit in unlocked drawers or open key boxes. Store all spare physical keys inside secure lock boxes with restricted access.
- Skipping physical security reviews: Teams forget to review room access lists as team roles shift. Audit physical entry rights twice a year to remove old permissions fast.
How to Measure Effectiveness (KPIs)
- Physical access removal speed: Track the average time taken to cancel badge rights and recover room keys after staff departure dates.
- Unapproved room entry count: Monitor the total number of forced doors, propped door alerts, or unapproved access attempts detected in secure areas.
- Clean desk compliance rate: Measure the share of after-hours site checks where desks, drawers, and screens meet clean desk safety rules.
- Physical key audit accuracy: Track the percentage of physical master keys and room badges accounted for during quarterly inventory checks.
- Lock repair resolution speed: Measure the average time taken to fix broken door latches, lock cylinders, or door closing gear after reporting.
- Visitor escort compliance rate: Track the percentage of external contractor and guest visits logged with an assigned staff escort.
- Room risk review completion rate: Measure the share of internal offices and facilities re-evaluated for data risk on schedule each year.
- Staff physical safety training rate: Track the proportion of workforce members who complete physical room access and guest challenge training.
- Propped door incident count: Track the number of propped door alerts triggered across secure work zones to stop bad worker habits.
- Restricted area check rate: Measure the share of routine checks confirming high-risk room doors stay locked and clearly marked with warning signs.
- Physical audit fix speed: Track the total number of physical room access flaws found during internal checks and resolved before the next audit.
- Window barrier check completion: Measure the share of ground floor window locks and physical safety barriers checked on schedule each quarter.
- Physical key loss rate: Count lost or missing physical keys and badges each year to lower physical breach risks.
- Contractor log audit rate: Check worker and vendor sign-in books monthly to verify complete access records for all guests.
Related ISO 27001 Controls
ISO 27001 Control A 7.3 connects directly to the following ISO 27001 requirements:
- ISO 27001 Clause 8.1: Operational planning for facility security.
- ISO 27001 Annex A 7.1: Physical security perimeters (the external boundary).
- ISO 27001 Annex A 7.4: Physical security monitoring (CCTV and alarms).


