ISO 27002:2022
Physical controls – ISO 27002:2022

ISO 27002:2022 7.2: Physical entry

Secure areas are to be protected by suitable entry controls and access points. Purpose: allow physical access to information and assets only to those authorized. General guidance: entry points like loading bays and goods-in, and anywhere unauthorized people could get in, are controlled and where possible kept apart from processing facilities. Consider: restricting sites and buildings to authorized people, with physical access rights provided, reviewed, updated and revoked (5.18); recording every entry in a protected paper log or electronic trail that is watched, and safeguarding those logs (5.33) and sensitive authentication information; a process and technical means to govern entry to rooms that hold or process information, using cards, biometrics or two-factor methods such as card plus PIN, and double doors for sensitive areas; a staffed reception or other means of controlling entry; inspecting personal belongings on entry and exit where local law permits; visible identification for everyone, prompt reporting of unescorted or unbadged people, and distinguishable badges for staff, suppliers and visitors; supplier access to secure areas only when needed, authorized and monitored; extra attention in buildings shared with other organizations; measures that can be stepped up when physical risk rises; protecting secondary entrances like fire exits against misuse; and a key management process for physical keys and lock codes or combinations, with a logbook or yearly key audit and controlled access (5.17). Visitors: authenticate their identity, record arrival and departure times, admit them only for specific authorized purposes with briefings on the area's security rules and emergency procedures, and keep them supervised unless expressly exempted. Goods-in areas: restrict outside access to identified, authorized people; design areas so delivery staff cannot reach the rest of the building; secure external doors while inner doors are open; inspect incoming items for explosives, chemicals or other hazards before moving them; register deliveries under asset management (5.9, 7.10); separate incoming and outgoing goods where possible; and check for tampering in transit, reporting any at once to security.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 64 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 7 controls

  • 9.2.1 9.2.1 Facility entry controls for CDE systems
  • 9.2.1.1 9.2.1.1 Monitoring of entry to sensitive areas
  • 9.3.1 9.3.1 Personnel physical access procedures for the CDE
  • 9.3.1.1 9.3.1.1 Personnel access to sensitive areas controlled
  • 9.3.2 9.3.2 Visitor access procedures for the CDE
  • 9.3.3 9.3.3 Visitor badges returned or deactivated
  • 9.3.4 9.3.4 Visitor logs for facility and sensitive areas

NIST SP 800-53 Rev 5 · 6 controls

CMMC 2.0 · 4 controls

FedRAMP High · 4 controls

  • PE-16 Delivery and Removal
  • PE-2 Physical Access Authorizations
  • PE-3 Physical Access Control
  • PE-8 Visitor Access Records

FedRAMP Moderate · 4 controls

  • PE-16 Delivery and Removal
  • PE-2 Physical Access Authorizations
  • PE-3 Physical Access Control
  • PE-8 Visitor Access Records
  • B.1.6.1 B.1.6.1 Site access control and perimeter delineation
  • B.5.1 B.5.1 Entry and access control objectives and the three identification factors
  • B.5.2 B.5.2 Implementing entry and access control systems
  • 6.2.8 6.2.8 Additional prevention and intervention strategies and protocols
  • 8.5.1.1 8.5.1.1 Managing an employee with an intimate partner violence issue
  • 8.5.3 8.5.3 Additional actions

NIST SP 800-171 Rev 3 · 3 controls

  • ISM-0813 Securing server rooms and containers
  • ISM-1074 Controlling keys to secure areas

HIPAA Security Rule · 2 controls

MTCS (Singapore) · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • P2-7.1.2 P2-7.1.2 Single-entry portal with positive authentication
  • P2-7.1.5 P2-7.1.5 Anti-piggybacking entry controls
  • 0205 0205 Control personnel, vehicle and equipment access to Zones One to Five per Table 44
  • 0206 0206 Control visitor access per Table 45

TSA Pipeline Security · 2 controls

  • TSA-PSG-05 Facility security measures for critical pipeline facilities
  • TSA-PSG-16 Liquefied natural gas facility security
  • ANSSI-HYG-26 Control and Protect Access to Server Rooms and Technical Areas
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

C5 (Germany) · 1 control

  • CFTC-SS-6 Physical Security and Environmental Controls Category

ISO 27001:2022 · 1 control

  • 7.2 Physical entry

ISO 27701:2019 · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-7.2 Physical entry and securing offices
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
  • 9.4.9.C.01 9.4.9.C.01 Minimum visitor log fields for TOP SECRET areas

SOC 2 · 1 control

  • SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets
  • MTSA-105.255 Maritime Security (MARSEC) Level Implementation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Physical controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 7.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 64 it maps to, and the evidence behind each claim, over MCP and REST.