ISO 27001 Physical Entry Explained – Control 7.2

ISO 27001 Physical Entry Explained – Control 7.2

Physical access is the last step before compromise. Once an unauthorized individual gets past your front door or into your server room, many of your most expensive logical security controls are already bypassed. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations spend thousands on cloud firewalls and endpoint protection, only to allow unvetted delivery drivers to walk straight past an unattended reception desk into core IT areas. Physical boundaries must be actively enforced, not assumed.

ISO 27001:2022 includes Annex A 7.2 to ensure you strictly control physical entry to secure locations where information assets and critical processing systems reside. This control replaces former 2013 requirements (11.1.2) and focuses on role-based physical access, visitor identification, tailgating prevention, loading bay segregation, and maintaining auditable entry logs.

Quick Summary: What ISO 27001 Annex A 7.2 Requires

At a practical level, Annex A 7.2 is about making sure physical presence is always authorized, verified, and accountable. It does not require installing high-cost biometric scanners or armed guards at every single doorway; it demands risk-proportionate physical access control. Here is what you need to do in plain English:

  • Identify Controlled Entry Zones: Define physical boundaries around offices, data centers, server closets, and media vaults requiring restricted access.
  • Deploy Proportionate Entry Mechanisms: Use electronic keycards, smart fobs, PIN keypads, or biometrics to restrict physical door access.
  • Identify Everyone Before Entry: Require staff, contractors, and visitors to wear visible physical ID badges at all times.
  • Govern Visitor Access Strictly: Log all visitors, issue temporary guest passes, and enforce mandatory escorts in high-security zones.
  • Isolate Delivery & Loading Bays: Segregate delivery points from internal operational spaces so couriers cannot wander into office areas.
  • Prevent Tailgating & Shared Entry: Train staff to stop “courtesy holding” of secure doors and review access logs regularly for anomalies.

Why Weak Physical Entry Controls Are a Critical Hazard

Once an attacker, competitor, or disgruntled ex-employee physically enters a secure area, they gain direct proximity to your hardware and network interfaces. They can steal laptops, unplug core servers, attach rogue hardware taps, or physically view confidential files sitting on desks.

Ignoring physical entry controls exposes your business to severe hazards:

  • Unnoticed Tailgating Intrusions: Unauthorized strangers slipping into secure zones behind legitimate employees holding doors open out of politeness.
  • Direct Hardware Theft & Tampering: Intruders physically stealing backup tapes, unencrypted laptops, or plugging keyloggers into administrative terminals.
  • Unescorted Visitor Reconnaissance: Delivery personnel, cleaners, or visiting clients wandering unmonitored through HR, finance, or server rooms.
  • Legacy Access Exploitation: Former employees or departed contractors retaining active physical keycards because access rights were never revoked in the access control system.

My 8 Step Plan to Implement Annex A 7.2 Fast

You do not need to turn your office into a military fortress to satisfy an ISO 27001 auditor. Here is my pragmatic, 8-step plan to establish an audit-ready physical entry control framework.

1. Define In-Scope Physical Entry Perimeters

Identify all physical entry points protecting locations where sensitive information or IT infrastructure resides (Annex A 8.9):

  • Main building reception desks, employee staff entrances, and parking garage doors.
  • Internal high-security zones like server rooms, network closets, and backup archives (Annex A 7.3).
  • Delivery docks, loading bays, service elevators, and waste staging areas (Annex A 7.5).

2. Deploy Electronic Entry Controls and Credentials

Replace traditional, unmanageable metal keys with electronic access control systems that maintain auditable logs:

  • Install RFID badge readers, smart keycard systems, or biometric scanners on all external and high-security internal doors.
  • Assign unique, individual access credentials to every employee—never issue generic or shared keycards.
  • Scope physical badge permissions strictly to specific zones based on job role and business need (Annex A 8.3).

3. Enforce Universal Visual Identification Badges

Ensure anyone walking inside your facilities can be instantly recognized as an authorized individual:

  • Require all employees, contractors, and visitors to wear visible photo ID badges on lanyards or clips above the waist.
  • Use color-coded lanyards or badge holders to distinguish at a glance between permanent staff, contractors, and temporary guests.
  • Train staff to politely challenge anyone inside secure areas who is not wearing a visible ID badge.

4. Establish a Strict Visitor Management Workflow

Visitors and external guests present high physical exposure risks if unmanaged:

  • Require all visitors to check in at reception, present government photo ID, and sign a physical or digital visitor log.
  • Issue temporary, dated visitor badges that must be returned to reception upon departure.
  • Enforce mandatory staff escorts for all visitors inside operational, administrative, and server areas.

5. Isolate and Supervise Delivery and Loading Bays

Delivery points are natural weak spots where external couriers interact with facility perimeters:

  • Designate dedicated loading docks and delivery areas that are physically segregated from internal office spaces (Annex A 7.12).
  • Lock internal doors connecting delivery bays to operational hallways, restricting access strictly to authorized facilities staff.
  • Supervise external delivery personnel continuously while they unload packages or equipment.

6. Combat Tailgating and Courtesy Door-Holding

Tailgating (piggybacking) is the single most common cause of physical access breaches:

  • Educate staff continuously that holding secure doors open for others breaks security policy—every person must swipe their own badge.
  • Deploy anti-tailgating hardware (such as turnstiles, speed gates, or mantraps/airlocks) at high-security entrances.
  • Configure local door-ajar alarms to sound if an electronic door is held open longer than 15–30 seconds.

7. Integrate Physical Access with HR Onboarding/Offboarding

Ensure physical access permissions stay perfectly synchronized with employee employment status (Annex A 8.2):

  • Automate physical badge provisioning so access rights activate only on an employee’s official start date.
  • Mandate immediate physical badge revocation and keycard retrieval during the employee offboarding checklist.
  • Audit active keycard databases quarterly to purge inactive, orphaned, or duplicate access profiles.

8. Monitor Entry Logs and Review Physical Access Periodically

Maintain complete auditability over physical movements into secure zones (Annex A 7.4):

  • Log all badge swipes, access approvals, and failed entry attempts automatically inside your central access control software.
  • Reconcile physical entry logs against CCTV footage during incident investigations or routine spot checks.
  • Review physical access lists bi-annually with department leads to ensure permissions remain aligned with least privilege.

Common Implementation Pitfalls and How to Fix Them

When preparing clients for ISO 27001 audits, I frequently spot the same physical entry mistakes. Here are the main traps and how to solve them:

  • Problem: Polite Employees Holding Secure Doors Open for Unbadged Strangers
    Ninja Solution: Run anti-tailgating awareness campaigns framing badge swiping as a safety rule rather than rudeness.
  • Problem: Departed Staff Keycards Remaining Active Months After Offboarding
    Ninja Solution: Link your physical access control system directly to your HR/IT offboarding ticketing workflow for instant revocation.
  • Problem: Unescorted Delivery Drivers Walking Straight from the Loading Dock into Server Closets
    Ninja Solution: Install locked barrier doors between delivery bays and internal corridors, requiring facilities staff escort.
  • Problem: Reusable Visitor Badges Left Uncollected and Taken Off-Site
    Ninja Solution: Require visitors to surrender guest badges at reception or turnstiles before exit turnstiles allow physical departure.

The ISO 27001 Ninja Bottom Line

ISO 27001 Annex A 7.2 is about ensuring that physical presence inside your facilities is always authorized, verified, and accountable. Sophisticated cyber firewalls protect your network, but a single unbadged intruder walking into your server room bypasses everything in seconds.

By defining controlled entry perimeters, deploying electronic badge systems, enforcing universal visual ID badges, managing visitors strictly, isolating delivery bays, combating tailgating, and revoking departed staff credentials immediately, you build a defensible physical security posture, protect core hardware assets, and satisfy your ISO 27001 auditor with complete confidence.