CC6.4 Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives
Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives.
5
artefacts
2
held by a system
2
at each review
moderate
to go live
Physical access / facilities
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Authorisation records showing who is permitted physical access to each location and on what basis · Physical access / facilities
- Access control system configuration and badge listings for those locations, reconciled against the authorisation records · Physical access / facilities
periodic reviewEvidence produced at each review
- Records of periodic review of physical access rights and of removals made as a result · Physical access / facilities
- Visitor and third party access records for the same locations, including escort evidence · Physical access / facilities
governing documentDocuments that govern the control
- List of facilities and protected information assets in scope, including data centre space, back-up media storage and other sensitive locations · Policy repository / GRC workspace
First move
Start with the 2 of 5 artefacts that already live in a system (Physical access / facilities); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Primary data centre well controlled while back-up media storage and offsite locations rely on a provider attestation with no entity level review
- Physical access rights reviewed less often than logical access, so leavers keep badge access after their accounts are disabled
- Sensitive locations such as network rooms and media handling areas omitted from the scope list entirely
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetCC6.3 Role-based access and least privilege are enforced · CC6.5 Discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to meet the entity's