EvidenceSheet

CC6.4 Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives

Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives.

5
artefacts
2
held by a system
2
at each review
moderate
to go live
Physical access / facilities
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Authorisation records showing who is permitted physical access to each location and on what basis · Physical access / facilities
  • Access control system configuration and badge listings for those locations, reconciled against the authorisation records · Physical access / facilities

periodic reviewEvidence produced at each review

  • Records of periodic review of physical access rights and of removals made as a result · Physical access / facilities
  • Visitor and third party access records for the same locations, including escort evidence · Physical access / facilities

governing documentDocuments that govern the control

  • List of facilities and protected information assets in scope, including data centre space, back-up media storage and other sensitive locations · Policy repository / GRC workspace

First move

Start with the 2 of 5 artefacts that already live in a system (Physical access / facilities); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

CC6.3 Role-based access and least privilege are enforced · CC6.5 Discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to meet the entity's