A.7.1 Physical security perimeters
Define and use security perimeters to protect areas holding information and assets.
16
artefacts
2
held by a system
6
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Keypad entry logs · SIEM / log platform
- Sample CCTV footage logs · Physical access / facilities
periodic reviewEvidence produced at each review
- Risk assessment for perimeter protection · Policy repository / GRC workspace
- Approval sign-off for perimeter layout · Document repository
- Door lock maintenance records · Physical access / facilities
- Temporary badge issuance records · Physical access / facilities
- Visitor escort sign-off sheets · Physical access / facilities
- Camera maintenance and calibration records · Document repository
governing documentDocuments that govern the control
- Facility floor plan with security zones · Policy repository / GRC workspace
- Security fence specifications and maintenance logs · Policy repository / GRC workspace
- Access card issuance register · Policy repository / GRC workspace
- Badge access control policy · Policy repository / GRC workspace
- Visitor logbook (electronic) · Policy repository / GRC workspace
- Visitor pre-approval forms · Policy repository / GRC workspace
- CCTV camera placement diagram · Policy repository / GRC workspace
- Video retention policy · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 2 system-held artefacts from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- outdated floor plans
- inconsistent access log retention
- lack of visitor escort verification
- insufficient CCTV coverage
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.6.8 Information security event reporting · A.7.2 Physical entry