ISO 27701:2019
PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

ISO 27701:2019 6.8.1: Secure areas

Secure area controls covering the security perimeter, entry, offices and facilities, protection against external and environmental threats, working in secure areas and delivery and loading areas apply as the base guidance requires, read as protecting the personal data those areas contain.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 59 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 8 controls

PCI DSS 4.0 · 6 controls

  • 1.4.4 1.4.4 Cardholder data stores not reachable from untrusted networks
  • 9.2.1 9.2.1 Facility entry controls for CDE systems
  • 9.2.1.1 9.2.1.1 Monitoring of entry to sensitive areas
  • 9.3.1 9.3.1 Personnel physical access procedures for the CDE
  • 9.3.2 9.3.2 Visitor access procedures for the CDE
  • 9.4.1.1 9.4.1.1 Secure storage location for offline backups

HIPAA Security Rule · 5 controls

ISO 27001:2022 · 5 controls

  • 7.1 Physical security perimeters
  • 7.2 Physical entry
  • 7.3 Securing offices, rooms and facilities
  • 7.5 Protecting against physical and environmental threats
  • 7.6 Working in secure areas

ISO 27002:2022 · 5 controls

  • 7.1 Physical security perimeters
  • 7.2 Physical entry
  • 7.3 Securing offices, rooms and facilities
  • 7.5 Protecting against physical and environmental threats
  • 7.6 Working in secure areas

NIST SP 800-66 Rev 2 · 5 controls

CMMC 2.0 · 4 controls

C5 (Germany) · 3 controls

  • C5-PS-01 Physical Security and Environmental Control Requirements
  • C5-PS-03 Perimeter Protection
  • C5-PS-04 Physical site access control

FedRAMP High · 3 controls

  • PE-13 Fire Protection
  • PE-16 Delivery and Removal
  • PE-3 Physical Access Control

FedRAMP Moderate · 3 controls

  • PE-13 Fire Protection
  • PE-16 Delivery and Removal
  • PE-3 Physical Access Control
  • NIST-CSF-DE.CM-02 The physical environment is monitored to find potentially adverse events
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk

NIST SP 800-171 Rev 3 · 2 controls

  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

ISO 27017:2015 · 1 control

  • 11.1 Secure areas

ISO 27018:2019 · 1 control

  • 11.1 Secure areas

SOC 2 · 1 control

  • SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

You are reading one control. How much of ISO 27701:2019 have you already done?

ISO 27701:2019 6.8.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27701:2019 your existing evidence covers. Hold SOC 2 and 58 of 108 ISO 27701:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 289 were rejected on the SOC 2 pair alone.

Query this from an agent

The graph holds this control, the 59 it maps to, and the evidence behind each claim, over MCP and REST.