Policy Register

Physical security policy

How premises and secure areas are defined, entered, monitored and protected, including visitors, deliveries and working in secure areas.

How the register reads it

Also calledsite security, visitor policy
FamilyOperations and technology
Document typePolicy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerFacilities or office management, with the information security lead.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 27001 is ticked and no line resolves to it (NIS2 requires it too, inside a parent document, so it does not list it separately).
TemplatePhysical security policy.

Which standards require it, and what each expects it to contain

4 requiring clauses, 2 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022

ISO 27001 7.1 Physical security perimeters

Define and use security perimeters to protect areas holding information and assets.

What the ISO 27002 guidance expects the document to say: Requires security perimeters to be defined and used to protect any area holding information and the assets associated with it.

Evidence an auditor accepts: Definition of the security perimeters, with site plans or drawings showing the boundary of each area holding information and associated assets; the basis for each perimeter, tied to the classification and criticality of what it protects; evidence the perimeter is physically sound, covering walls, doors, windows, roof and floor voids
Common gap: outdated floor plans
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.2 Physical entry

Protect secure areas with appropriate entry controls and access points.

What the ISO 27002 guidance expects the document to say: Requires secure areas to be protected by appropriate entry controls and by control over the access points themselves.

Evidence an auditor accepts: Entry control configuration for each secure area, showing the authentication required and any multi factor or dual control; the authorisation list per area, with the basis for each person's access; access logs for the period, retained and reviewed, with evidence of what the review looked for
Common gap: Use of informal sign-in sheets instead of controlled logs
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.4 Physical security monitoring

Continuously monitor premises for unauthorized physical access.

What the ISO 27002 guidance expects the document to say: Requires premises to be monitored continuously for unauthorised physical access. Supporting material frames this as continuous monitoring of physical security controls so that unauthorised entry and other physical security incidents are detected and responded to.

Evidence an auditor accepts: The design of physical monitoring, covering surveillance, intrusion detection, alarms and guarding, and its coverage against the areas defined; evidence monitoring is continuous, including out of hours and during holidays; records of alarms and detections in the period, with the response taken and the time to respond
Common gap: logs not retained for required period
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

The NIS2 Directive

NIS2 Art. 21(2)(a) Policies on risk analysis and on information system security

The first of the ten minimum measure categories requires both a method for analysing risk and the security policy set that the analysis feeds. Risk analysis has to be an actual repeatable method with criteria for assessing and accepting risk, applied to the network and information systems the entity relies on for its operations and for delivering its services, with results that are recorded and revisited. The information system security policies are the codified decisions that follow: what is protected, to what level, who owns each decision, and what happens when the policy cannot be met. Both limbs are needed. A risk register with no policy leaves nothing binding on the organisation, and a policy library with no risk analysis behind it cannot show why it says what it says.

Evidence an auditor accepts: The documented risk analysis method, including risk criteria and acceptance thresholds; the current risk assessment output covering the in-scope network and information systems; the approved information system security policy set, with owners and review dates
Common gap: Risk register maintained as a list of findings with no method or acceptance criteria behind it
Source: NIS2 Directive

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Patch management policy · Secure development policy