Secure areas are to be protected by suitable entry controls and access points. Purpose: allow physical access to information and assets only to those authorized. General guidance: entry points like loading bays and goods-in, and anywhere unauthorized people could get in, are controlled and where possible kept apart from processing facilities. Consider: restricting sites and buildings to authorized people, with physical access rights provided, reviewed, updated and revoked (5.18); recording every entry in a protected paper log or electronic trail that is watched, and safeguarding those logs (5.33) and sensitive authentication information; a process and technical means to govern entry to rooms that hold or process information, using cards, biometrics or two-factor methods such as card plus PIN, and double doors for sensitive areas; a staffed reception or other means of controlling entry; inspecting personal belongings on entry and exit where local law permits; visible identification for everyone, prompt reporting of unescorted or unbadged people, and distinguishable badges for staff, suppliers and visitors; supplier access to secure areas only when needed, authorized and monitored; extra attention in buildings shared with other organizations; measures that can be stepped up when physical risk rises; protecting secondary entrances like fire exits against misuse; and a key management process for physical keys and lock codes or combinations, with a logbook or yearly key audit and controlled access (5.17). Visitors: authenticate their identity, record arrival and departure times, admit them only for specific authorized purposes with briefings on the area's security rules and emergency procedures, and keep them supervised unless expressly exempted. Goods-in areas: restrict outside access to identified, authorized people; design areas so delivery staff cannot reach the rest of the building; secure external doors while inner doors are open; inspect incoming items for explosives, chemicals or other hazards before moving them; register deliveries under asset management (5.9, 7.10); separate incoming and outgoing goods where possible; and check for tampering in transit, reporting any at once to security.
This control maps to 64 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
ISO 27002:2022 7.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 64 it maps to, and the evidence behind each claim, over MCP and REST.