Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 7.2

Physical Entry: A Practical Implementation Guide

Allow only authorized people into protected areas and retain reliable evidence of access.

This control concerns implementing secure entry points and access controls for protected areas.

Practical interpretation: Badges and locks are only part of the process. Authorization, identity verification, visitor handling, anti-tailgating behavior, logging and prompt revocation must work together.

What should the control achieve?

  • Entry authorization reflects business need.
  • People and visitors are identified appropriately.
  • Entry records support investigation.
  • Lost credentials and access changes are handled promptly.

Step-by-step implementation

1

Define zone authorization

Assign approvers and access profiles for each physical area.

2

Select entry controls

Use reception, badges, PINs, biometrics, guards, turnstiles or keys based on risk.

3

Manage visitors

Preauthorize, verify identity, issue visible credentials, escort and record departure.

4

Prevent misuse

Address tailgating, badge sharing, held-open doors and lost credentials.

5

Integrate lifecycle

Connect joiner, mover, leaver and contractor expiry to physical access.

6

Review and monitor

Inspect logs, unusual access, dormant badges and emergency overrides.

What this could look like in practice

Visitors to a research facility are preregistered, show identification, receive expiring badges and remain escorted in restricted areas. Staff badge access is role-based and automatically disabled on termination.

ActivityPractical implementationEvidence
Employee entryRole profile grants approved zones.Badge record
VisitorReception verifies, badges and checks out visitor.Visitor log
Lost badgeCredential is disabled immediately and incident assessed.Service ticket
After-hours accessAdditional approval and monitoring apply.Access log

Implementation evidence

  • Physical access policy
  • Zone authorization matrix
  • Badge and key register
  • Visitor logs
  • Identity-check procedure
  • Access reviews
  • Lost-credential records
  • Emergency override tests

Useful metrics

  • Unauthorized entry attempts
  • Lost credentials disabled within target
  • Expired visitor or contractor badges
  • Access reviews completed

Common mistakes

  • Sharing badges or keys.
  • Issuing visitor badges without return tracking.
  • Keeping access after internal transfer.
  • Ignoring tailgating culture.
  • Collecting excessive visitor identity data.

Questions an auditor may ask

  • Who approves access to each zone?
  • How are visitors managed?
  • Show a lost badge response.
  • How is physical access removed for leavers?
Implementation test: Sample employees, contractors and visitors and trace each entry right to current need, approval, expiry and logs.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.