Physical security policy
How premises and secure areas are defined, entered, monitored and protected, including visitors, deliveries and working in secure areas.
How the register reads it
| Also called | site security, visitor policy |
|---|---|
| Family | Operations and technology |
| Document type | Policy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | Facilities or office management, with the information security lead. |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 27001 is ticked and no line resolves to it (NIS2 requires it too, inside a parent document, so it does not list it separately). |
| Template | Physical security policy. |
Which standards require it, and what each expects it to contain
4 requiring clauses, 2 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27001:2022
ISO 27001 7.1 Physical security perimetersDefine and use security perimeters to protect areas holding information and assets.
What the ISO 27002 guidance expects the document to say: Requires security perimeters to be defined and used to protect any area holding information and the assets associated with it.
Common gap: outdated floor plans
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.2 Physical entryProtect secure areas with appropriate entry controls and access points.
What the ISO 27002 guidance expects the document to say: Requires secure areas to be protected by appropriate entry controls and by control over the access points themselves.
Common gap: Use of informal sign-in sheets instead of controlled logs
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.4 Physical security monitoringContinuously monitor premises for unauthorized physical access.
What the ISO 27002 guidance expects the document to say: Requires premises to be monitored continuously for unauthorised physical access. Supporting material frames this as continuous monitoring of physical security controls so that unauthorised entry and other physical security incidents are detected and responded to.
Common gap: logs not retained for required period
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
The NIS2 Directive
NIS2 Art. 21(2)(a) Policies on risk analysis and on information system securityThe first of the ten minimum measure categories requires both a method for analysing risk and the security policy set that the analysis feeds. Risk analysis has to be an actual repeatable method with criteria for assessing and accepting risk, applied to the network and information systems the entity relies on for its operations and for delivering its services, with results that are recorded and revisited. The information system security policies are the codified decisions that follow: what is protected, to what level, who owns each decision, and what happens when the policy cannot be met. Both limbs are needed. A risk register with no policy leaves nothing binding on the organisation, and a policy library with no risk analysis behind it cannot show why it says what it says.
Common gap: Risk register maintained as a list of findings with no method or acceptance criteria behind it
Source: NIS2 Directive
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a register