EvidenceSheet

7.2 Physical entry

Requires secure areas to be protected by appropriate entry controls and by control over the access points themselves.

5
artefacts
1
held by a system
2
at each review
hard
to go live
Physical access / facilities
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Entry control configuration for each secure area, showing the authentication required and any multi factor or dual control · Physical access / facilities

periodic reviewEvidence produced at each review

  • Access logs for the period, retained and reviewed, with evidence of what the review looked for · Physical access / facilities
  • Evidence of periodic review and removal of physical access rights, including on departure and role change · Physical access / facilities

governing documentDocuments that govern the control

  • The authorisation list per area, with the basis for each person's access · Policy repository / GRC workspace
  • Visitor procedures, covering identification, authorisation, escort and record of entry and exit · Policy repository / GRC workspace

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your Physical access / facilities on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

7.1 Physical security perimeters · 7.3 Securing offices, rooms and facilities