ISO/IEC 27001:2022 Annex A · Control 7.2
Physical Entry: A Practical Implementation Guide
Allow only authorized people into protected areas and retain reliable evidence of access.
This control concerns implementing secure entry points and access controls for protected areas.
What should the control achieve?
- Entry authorization reflects business need.
- People and visitors are identified appropriately.
- Entry records support investigation.
- Lost credentials and access changes are handled promptly.
Step-by-step implementation
Define zone authorization
Assign approvers and access profiles for each physical area.
Select entry controls
Use reception, badges, PINs, biometrics, guards, turnstiles or keys based on risk.
Manage visitors
Preauthorize, verify identity, issue visible credentials, escort and record departure.
Prevent misuse
Address tailgating, badge sharing, held-open doors and lost credentials.
Integrate lifecycle
Connect joiner, mover, leaver and contractor expiry to physical access.
Review and monitor
Inspect logs, unusual access, dormant badges and emergency overrides.
What this could look like in practice
Visitors to a research facility are preregistered, show identification, receive expiring badges and remain escorted in restricted areas. Staff badge access is role-based and automatically disabled on termination.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Employee entry | Role profile grants approved zones. | Badge record |
| Visitor | Reception verifies, badges and checks out visitor. | Visitor log |
| Lost badge | Credential is disabled immediately and incident assessed. | Service ticket |
| After-hours access | Additional approval and monitoring apply. | Access log |
Implementation evidence
- Physical access policy
- Zone authorization matrix
- Badge and key register
- Visitor logs
- Identity-check procedure
- Access reviews
- Lost-credential records
- Emergency override tests
Useful metrics
- Unauthorized entry attempts
- Lost credentials disabled within target
- Expired visitor or contractor badges
- Access reviews completed
Common mistakes
- Sharing badges or keys.
- Issuing visitor badges without return tracking.
- Keeping access after internal transfer.
- Ignoring tailgating culture.
- Collecting excessive visitor identity data.
Questions an auditor may ask
- Who approves access to each zone?
- How are visitors managed?
- Show a lost badge response.
- How is physical access removed for leavers?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.