COBIT 2019
Deliver, Service and Support – COBIT 2019

COBIT 2019 DSS05.05: DSS05.05 Manage physical access to I&T assets

Procedures, emergency procedures among them, give, restrict and withdraw access to premises, buildings and areas as business need dictates, with each access justified, authorised, logged and monitored, and they cover everyone who enters: staff, temporary staff, clients, vendors, visitors and any other third party: every entry point to IT sites is logged and monitored, and visitors, contractors and vendors included, are registered; all personnel wear approved identification at all times; visitors are accompanied throughout their visit; access to sensitive sites is restricted and monitored through perimeter controls such as walls, fences and security devices on internal and external doors; requests for access to computing facilities are managed; access profiles are kept up to date according to job function; and physical security awareness training is held regularly.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 3 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 3 controls

  • 7.1 Physical security perimeters
  • 7.2 Physical entry
  • 7.4 Physical security monitoring

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Deliver, Service and Support – COBIT 2019

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.