Priya Chandrasekaran got the call at 7:42 on a Tuesday morning, twelve minutes after she'd sat down with her coffee. She was VP of Security at Sable Analytics, a 220-person healthcare data analytics firm in Raleigh that processed claims data for four regional health plans. The call was from her facilities manager, and it started with the sentence nobody wants to hear before their coffee is even warm: "I think someone was in the server room overnight who shouldn't have been."
Here's what the badge logs and the grainy lobby camera eventually pieced together. At 8:14 the previous morning — during the ten-minute window when the receptionist was covering a second-floor delivery and the front desk sat empty — a man in a courier jacket carrying a flat package had walked in directly behind two Sable employees returning from a smoke break. The employees held the door. Of course they held the door; that's what polite people do. The man in the courier jacket had no badge, made no attempt to check in, and nobody stopped him, because nobody was there to stop him and the two employees assumed he was headed to the mailroom, which — as it happened — shared a hallway with the network closet that Sable's facilities team had, for reasons of pure convenience, always called "the data room."
That hallway had never been formally designated as anything. It wasn't listed as a secure zone in any policy. It didn't have its own badge reader — the network closet's push-button lock used a four-digit code that had last been changed when the building opened, three years earlier, and was written on a sticky note inside the door frame because contractors kept forgetting it. The man in the courier jacket didn't even need the code. The door had been propped with a fire extinguisher because the HVAC technician working that week found the auto-closer annoying.
He was inside for eleven minutes. He plugged a USB drive into an idle terminal that a claims-processing analyst had left logged in overnight — a separate failure, but one made possible by the physical one — and copied a folder of denormalized claims exports totaling 41,000 patient records: names, dates of birth, diagnosis codes, and partial Social Security numbers used for cross-plan reconciliation. He was gone before the receptionist got back to her desk.
Sable never identified him. What Sable did get, over the following five months, was a forensic investigation bill of $180,000, breach notification and two years of credit monitoring for 41,000 people at just under $310,000, a state attorney general inquiry that cost another $90,000 in outside counsel, and — the number that actually kept Priya up at night — the loss of a $1.4-million-a-year contract renewal with the largest of the four health plans, whose own security team asked a question Sable couldn't answer convincingly: "How do you define the boundary of your secure areas, and how do you control who crosses it?"
That question is, almost word for word, what ISO/IEC 27001:2022 Annex A Control 7.1 and Control 7.2 ask you to answer in writing, with evidence. Sable didn't have a perimeter, because nobody had ever drawn one. It had a lock, but no controlled entry point, no visitor process, no logging, and no zone hierarchy that separated "anyone can walk in" from "only cleared staff go here." This article is about making sure that gap doesn't exist in your organization — and about building something an auditor, a customer security questionnaire, or a real intruder in a courier jacket can't walk straight through.
Who This Is For
This article is for the person who owns — or is about to be handed — physical security as part of an ISO 27001 implementation: a facilities manager suddenly responsible for compliance evidence, a security or IT leader who assumed physical controls were "someone else's problem," or a founder at a growing company who just realized their office lease doesn't come with a security policy attached. You'll walk away with a working definition of what counts as a security perimeter under Control 7.1, a concrete entry-control scheme under Control 7.2 that covers badges, visitors, and deliveries, a clear sense of where Control 7.3 picks up the story, and the specific evidence an auditor will ask you to produce. If you manage a single leased office suite or a multi-building campus with a data center, the same layered logic applies — only the scale changes.
Physical Controls in the Bigger ISO 27001 Picture
Controls 7.1 through 7.3 sit at the front of Annex A's physical theme, which runs from 7.1 through 7.14 and covers everything from perimeters to equipment disposal — the full sweep is mapped out in our ISO 27001 Physical Controls Overview. Perimeters and entry controls are the foundation the rest of that theme builds on: you can't secure "offices, rooms, and facilities" under Control 7.3 if you haven't first defined where your security perimeter actually is, and you can't meaningfully monitor physical access under the related Control 7.4 (physical security monitoring) if there's no controlled entry point generating events worth watching. If any of the terminology here — "secure area," "controlled zone," "physical entry" — is unfamiliar, our ISO 27001 glossary of terms defines them the way the standard uses them, which is worth doing before an auditor uses them differently than you expect.
It's also worth being precise about what these controls are not. Control 7.1 and 7.2 govern the physical layer — walls, doors, badges, guards, cameras at entry points. They work hand in hand with, but are distinct from, Access Control Policy under Controls 5.15–5.18, which governs logical access to systems and information. A badge that opens a server room door and a login that opens a database are both "access control" in the colloquial sense, but ISO 27001 separates them deliberately, because the risks, the controls, and often the owners are different. A mature ISMS treats them as two halves of the same coin — a badge revoked the same day as an account, a visitor log that mirrors a system access log — but they are not the same control, and conflating them in your documentation is one of the more common ways organizations confuse their own auditors.
"The single most common finding I write up in physical security audits isn't a missing camera or a broken lock — it's an organization that genuinely cannot tell me where their secure area begins. If you can't draw the line, you can't defend the line." — Aisha Bello, Lead ISO 27001 Auditor, Northbridge Assurance
Control 7.1: Physical Security Perimeters
The requirement itself is deceptively short: define and use security perimeters to protect areas containing information and other associated assets. In practice, this is the control that forces you to answer a question most organizations have never explicitly asked: where, exactly, does "inside" become "outside," and how many layers of "inside" do you actually have?
What Counts as a Perimeter
A security perimeter is any physical or structural boundary that separates one level of trust from another. That's a broader idea than most people assume when they hear "perimeter" and picture a fence. A perimeter can be:
The exterior wall and locked doors of a building.
A floor-to-ceiling partition separating a leased office suite from the rest of a shared building.
A caged rack inside a colocation data center, where the colo provider controls the building perimeter and you control the cage.
The walls of a single server room, records vault, or executive floor inside an otherwise open-plan office.
The boundary of a home office for a remote employee handling regulated data — a perimeter Control 7.1 does not exempt just because there's no badge reader involved.
The mistake Sable Analytics made was treating "the building has a lock on the front door" as equivalent to "we have defined our security perimeters." It hadn't defined anything past that single, outermost layer. A network closet that holds claims data for four health plans needs to be its own perimeter, nested inside the building perimeter, with its own controls — and that nesting is the whole point of Control 7.1.
The Concentric Zone Model
The practitioner tool for this is the concentric zone model — sometimes called defense-in-depth applied to physical space. You draw your facility as a series of rings, each one harder to enter than the last, with the most sensitive assets at the center. An intruder who defeats one ring still has to defeat the next, and every ring crossing is a chance to detect them.
Zone | Typical Physical Examples | Who Belongs There | Trust Level |
|---|---|---|---|
Public | Sidewalk, parking lot, building exterior, ground-floor lobby before check-in | Anyone | None assumed |
Reception / Transition | Staffed reception desk, waiting area, delivery drop point | Staff, expected visitors, couriers | Screened on entry |
Controlled | General office floors, open-plan workspace, standard meeting rooms | Badge-holding employees and escorted visitors | Employment-based trust |
Restricted | Finance, HR, legal, executive offices, R&D labs | Role-cleared staff only | Need-to-know |
Secure | Server rooms, network closets, data centers, records vaults, cash rooms | Named, individually authorized personnel | Highest — logged and monitored |
graph TD
A[Public Zone<br/>Sidewalk, parking, building exterior] -->|Fencing, lighting, exterior CCTV| B[Reception Zone<br/>Lobby, staffed front desk]
B -->|Badge reader + visitor sign-in| C[Controlled Zone<br/>General office floors]
C -->|Role-based badge access| D[Restricted Zone<br/>Finance, HR, executive offices, labs]
D -->|Two-factor entry + mantrap| E[Secure Zone<br/>Server room, data center, records vault]
E -->|Biometric + dual authorization + full logging| F[Crown-Jewel Assets<br/>Backup media, HSMs, PII archives]Sable's problem, mapped onto this model, is obvious in hindsight: the network closet — which should have sat in the Secure zone — had no boundary distinguishing it from the Controlled zone around it. There was no ring left for the intruder to defeat after the front door, because the front door was effectively the only ring that existed.
Perimeter Construction Standards
Auditors don't expect prison-grade construction for a marketing agency's leased suite, but they do expect the physical construction of a perimeter to be proportionate to what it protects, and they expect you to have thought about it rather than inherited it from whoever signed the lease.
Perimeter Feature | Deterrent Value | Typical Application | Notes |
|---|---|---|---|
Full-height walls (slab-to-slab, not just to a drop ceiling) | High | Server rooms, records vaults | Drop-ceiling gaps are a classic pen-test entry point — go up and over |
Solid-core doors with commercial-grade locks | Medium–High | Restricted and Secure zones | Hollow-core interior doors are a common weak point in older office buildouts |
Perimeter fencing and controlled vehicle gates | High | Data centers, campuses, warehouses | Combined with lighting and CCTV for deterrence plus detection |
Anti-tailgating door hardware (delayed egress, door-forced alarms) | Medium | Any controlled or higher zone | Alerts on doors held open beyond a threshold |
Window security (laminated glass, restricted ground-floor glazing) | Medium | Ground-floor offices, retail-adjacent leases | Often overlooked because it isn't a "door" control |
Reinforced or windowless walls for server rooms | High | Data centers, network closets | Removes a bypass route around the door entirely |
Common Perimeter Types
Not every organization's perimeter looks the same, and the standard doesn't require it to. What matters is that whatever perimeter you have is documented, matches reality, and is defensible in your Statement of Applicability. Our SoA how-to guide walks through justifying inclusions like this one in the document itself.
Environment | Perimeter Approach | Primary Risk If Undefined |
|---|---|---|
Single leased office suite | Suite entry door as outer perimeter; internal server closet as inner perimeter | Shared-building common areas treated as "inside" when they aren't |
Multi-tenant office building | Building lobby + suite door as two nested perimeters | Landlord-controlled areas assumed to be under your control (they aren't) |
Owned campus with data center | Site fence, building entry, and data center floor as three nested perimeters | Vehicle gates and loading areas left out of the model entirely |
Colocation data center | Provider controls building/floor perimeter; you control your cage or rack perimeter | Assuming the colo's perimeter substitutes for your own access records |
Retail or warehouse with back-office | Public sales floor vs. staff-only back office as the primary boundary | Stockroom and office areas physically adjoining public space with no clear line |
Remote / home office | Home itself as outer perimeter; locked room or cabinet as inner perimeter for regulated data | Treated as out of scope entirely, when Control 7.1 still applies to the assets involved |
"People hear 'security perimeter' and think fences and turnstiles. Half the perimeters I assess are a locked door with a keypad — and that's fine, as long as someone can tell me why that door is where it is, what's on the other side of it, and who's allowed through. The construction matters less than the intentionality." — Marcus Feld, Director of Physical Security, Continental Freight Systems
The output of Control 7.1 work is not a fence — it's a diagram. Every organization implementing this control should be able to produce a floor plan or campus map with zones drawn on it, asset locations marked, and a one-line justification for each boundary. That diagram becomes the backbone of everything Control 7.2 builds next: you cannot design entry controls for zones you haven't drawn.
Control 7.2: Physical Entry
Once your perimeters are drawn, Control 7.2 asks the next logical question: secure areas shall be protected by appropriate entry controls and access points. "Appropriate" is doing a lot of work in that sentence, and it's the word an auditor will press you on. Appropriate for a five-person accounting firm's file room is not appropriate for a payment processor's data center floor, and the standard deliberately doesn't specify a mechanism — it specifies an outcome: only authorized individuals cross into a secure area, and there's a record of who did.
Entry Control Mechanisms
Most organizations end up using a mix of these, layered by zone rather than applied uniformly everywhere. Uniform application is itself a common mistake — a badge reader on the front lobby door and an identical badge reader on the server room door look consistent, but they're protecting wildly different assets and usually deserve different strength.
Mechanism | Strength | Approximate Cost per Door | Best Suited To |
|---|---|---|---|
Staffed reception / security guard | Medium (human judgment, but fatigue and shift gaps are real) | Ongoing labor cost, no hardware | Reception / transition zone |
Proximity (RFID) badge reader | Medium (clonable with cheap hardware unless encrypted) | $800–$2,500 installed | Controlled and restricted zones |
Encrypted smart card (e.g., high-frequency, mutual-auth) | High | $1,500–$4,000 installed | Restricted and secure zones |
PIN keypad | Low–Medium (shared codes, shoulder-surfing) | $300–$1,000 | Low-sensitivity internal doors, as a secondary factor |
Biometric (fingerprint, iris, palm-vein) | High | $2,500–$6,000 installed | Secure zones, especially where badge-sharing is a risk |
Two-factor entry (badge + PIN, or badge + biometric) | Very high | Sum of components | Secure zones holding regulated or crown-jewel data |
Mantrap / interlocking door (only one door opens at a time) | Very high — defeats tailgating structurally | $8,000–$25,000 installed | Data centers, cash rooms, high-security labs |
Mechanical key lock | Low (no logging, keys get copied, hard to revoke) | Low | Acceptable only as a fallback or for the lowest-risk internal doors |
A note on mechanical keys: they're not banned by ISO 27001, but they fail the evidentiary test badly. A key can't tell you who opened a door at 2:14 a.m., and re-keying every lock when an employee leaves is rarely done in practice. If a mechanical key is your primary control on anything above the Controlled zone, expect an auditor to flag it as disproportionate to the risk.
Visitor Management
Visitors are where most physical intrusions actually happen, because visitors are, by design, people the organization doesn't fully trust yet — and every process built around them has to balance hospitality against verification. A functioning visitor program has five non-negotiable elements: pre-registration where feasible, identity verification at arrival, a visibly distinct temporary badge, a named escort or designated escort-free zone, and a logged sign-out. Skip any one of these and you've effectively created an unmonitored door into your Controlled zone.
The badge itself matters more than organizations think. A visitor badge that looks similar to an employee badge from ten feet away defeats the entire purpose — it should be a different color, prominently marked "VISITOR," and ideally time-limited so it visibly expires or must be surrendered. Sable Analytics, notably, had no visitor badge process at all; the man in the courier jacket was never issued anything to distinguish him from staff, because nobody engaged with him in the first place.
Delivery and Loading Areas
Deliveries deserve their own entry point, separate from the main employee and visitor entrance, for a simple reason: couriers arrive constantly, are rarely verified beyond a company logo on a jacket, and have a legitimate reason to be carrying boxes that could just as easily conceal something else. A dedicated loading dock or delivery point, physically separated from the Controlled zone, with its own sign-in and a rule that delivery personnel never proceed past the drop point unescorted, closes off one of the most exploited entry vectors in physical social engineering. This is also where Control 7.2 intersects with supplier and vendor risk more broadly — a courier is, functionally, an unvetted third party with physical access, and the same due-diligence instinct that governs supplier relationships applies here even though the interaction lasts ninety seconds.
"Deliveries are the blind spot in almost every physical security program I've reviewed. Everyone locks down the front door and forgets that the loading dock is a second front door with no receptionist and a lot more foot traffic." — Devon Track, Facilities Security Manager, Halcyon Biotech
Defending Against Tailgating and Piggybacking
Tailgating (following an authorized person through a door without badging in) and piggybacking (a variant where the authorized person knowingly, if unwittingly-negligently, holds the door) are the single most common way physical entry controls actually fail. The technology can be flawless and the process still collapses at the point where a badge reader meets ordinary human politeness — nobody wants to be the person who lets a door slam in a stranger's face.
Defense | How It Works | Relative Cost | Effectiveness |
|---|---|---|---|
Security awareness training with physical scenarios | Staff practice declining to hold doors and challenging unbadged individuals | Low | Medium — decays without reinforcement |
"Challenge culture" policy, backed by management | Explicit permission (and expectation) to politely challenge anyone without a visible badge | Low | Medium–High, if genuinely reinforced |
Turnstiles / optical turnstiles | Physically permit one badge-in per one person-through | Medium–High | High |
Mantrap / interlocking vestibule | Second door only unlocks after first door fully closes and locks | High | Very high |
Door-held-open alarms | Alerts security if a controlled door stays open beyond a set threshold | Low–Medium | Medium — detective, not preventive |
Video analytics / tailgating detection cameras | AI-assisted detection of two people crossing on one badge event | Medium–High | Medium–High, improving rapidly |
Badge-back / anti-passback logic | System rejects a badge attempting to badge in twice without an intervening badge-out | Low (software config) | Medium — catches shared-credential misuse |
No single row in that table is sufficient on its own. The strongest programs combine a cultural layer (challenge culture, reinforced training) with a structural layer (turnstiles or mantraps at the highest-sensitivity boundaries) and a detective layer (door alarms, video analytics) that catches what the first two miss. Sable's failure was the absence of all three at once: no reinforced culture (employees were never trained to question a courier), no structural barrier past the front door, and no detection mechanism that would have flagged an eleven-minute unauthorized presence in the network closet.
Where Control 7.3 Fits
It's worth being precise about the boundary between these three controls, because organizations frequently blur them in their documentation and auditors notice. Control 7.1 defines where your perimeters are. Control 7.2 governs how people cross those perimeters. Control 7.3 — securing offices, rooms and facilities — governs what happens inside the space once someone has legitimately crossed: physical security for offices, rooms and facilities shall be designed and implemented. That covers room-level design decisions such as whether sensitive work happens in rooms visible from public corridors, how meeting rooms used for confidential discussions are positioned, where server rooms sit relative to exterior walls and plumbing risk, and how individual offices, cabinets, and archive rooms are hardened beyond the general office footprint.
Sable's network closet is a useful illustration of where these controls hand off to one another. Control 7.1 should have required Sable to formally designate that closet as a Secure zone with its own defined boundary. Control 7.2 should have required a proper entry mechanism — not a shared sticky-note PIN — governing who crosses that boundary. Control 7.3 would then govern the room itself: was it built with slab-to-slab walls, was it free of unrelated foot traffic like the mailroom, did it have appropriate fire suppression that wouldn't damage equipment, and was equipment sited away from windows and water lines — the last point overlapping with the equipment-level protections covered under equipment security and maintenance in Controls 7.8–7.13. This article focuses its depth on the first two questions — the boundary and the crossing point — because they're the foundation everything else sits on. For the room-by-room implementation detail on server rooms, executive offices, records rooms, and shared facilities, see the dedicated walkthrough on securing offices, rooms, and facilities under Control 7.3.
It's also worth flagging two closely related controls you'll encounter as you build out the rest of the physical theme, both of which extend naturally from the work in this article: Physical Security Monitoring (Control 7.4), which governs the CCTV and surveillance layer that watches the entry points you've just controlled, and Working in Secure Areas (Control 7.6), which governs staff behavior once inside a secure zone — things like no unsupervised work by third parties and no photography. Neither has a dedicated deep-dive published yet, but they're a natural next read once your perimeters and entry points are in place. Once someone is legitimately at a desk inside a Controlled or Restricted zone, the baton passes again — this time to the clear desk and clear screen policy under Control 7.7, which governs what's left visible or unlocked once the entry control has already done its job.
Building an Entry-Control Scheme by Zone
Pulling Control 7.1's zone model and Control 7.2's mechanisms together, here's the reference scheme we use with clients building this out for the first time. It's a starting template, not a mandate — the standard doesn't prescribe exact mechanisms, only proportionality.
Zone | Entry Mechanism | Visitor Policy | Escort Required? | Logging | Review Cadence |
|---|---|---|---|---|---|
Public | None (open access) | N/A | No | CCTV only | Annual |
Reception / Transition | Staffed desk, sign-in sheet or digital kiosk | Sign in, show ID, receive visitor badge | No (contained to reception area) | Visitor log, CCTV | Quarterly |
Controlled (general office) | Proximity badge reader | Escorted only, badge visible at all times | Yes | Badge access log | Quarterly |
Restricted (finance, HR, execs, labs) | Encrypted smart card, role-based | Pre-approved and escorted, logged separately from general visitor log | Yes, by role-authorized staff | Badge access log, reviewed monthly | Monthly |
Secure (server room, data center, vault) | Two-factor: badge + biometric or badge + PIN | No unescorted visitors under any circumstance; contractors logged individually | Yes, by named authorized personnel only | Badge log + CCTV + entry/exit register, reviewed weekly | Weekly to monthly, per risk |
Delivery / loading dock | Separate entry, dock staff sign-in | Couriers never proceed past drop point | Yes, if any progression beyond dock | Delivery log, CCTV | Quarterly |
Two things stand out when clients see this table for the first time. First, the review cadence tightens as sensitivity increases — a Secure zone's access log reviewed only annually is functionally the same as not reviewing it at all, because by the time an anomaly surfaces, the exposure window has already closed. Second, "escort required" isn't a box to tick once; it needs a named accountable role in each zone, or it degrades into the same politeness failure that let Sable's intruder through the front door.
Visitor Management Flow
The process itself, end to end, is worth diagramming rather than just describing, because the failure points cluster at the handoffs between steps rather than within any single step.
flowchart TD
A[Pre-registration<br/>Host submits visitor name and purpose] --> B[Arrival at reception]
B --> C{Identity verified<br/>against pre-registration or valid ID?}
C -- No --> D[Denied entry / escalate to security]
C -- Yes --> E[Issue visitor badge<br/>distinct color, time-limited]
E --> F[Host or designated escort assigned]
F --> G[Entry logged: name, time, host, purpose]
G --> H[Escorted movement within Controlled/Restricted zones]
H --> I[Badge surrendered at departure]
I --> J[Sign-out logged: exit time]
J --> K[Visitor log retained per policy]Visitor Type | Special Rule |
|---|---|
Contractor (recurring, e.g., HVAC/cleaning) | Background-checked and issued a longer-term but still distinct badge; access limited to zones relevant to their work |
Delivery / courier | Stops at loading dock or reception; never issued a badge that permits Controlled-zone access |
Auditor (internal or certification body) | Full facility access under escort, logged with unusual specificity since they'll review the log itself |
Interview candidate | Reception and designated interview room only; never left unattended in the Controlled zone |
Vendor technician (on-site system work) | Escorted to the specific Restricted or Secure zone only, with work logged alongside entry/exit times |
Executive guest / board member | Still badges in and is still logged — status is not an exemption from Control 7.2 |
That last row trips up more organizations than any other. Exempting executives or "VIP" visitors from the standard process is one of the fastest ways to undermine an otherwise solid entry-control scheme, because it signals — to staff and to an auditor sampling the logs — that the policy is optional rather than universal.
"I tell every client the same thing before their first Stage 2 audit: if your CEO doesn't badge in like everyone else, don't bother printing the visitor policy, because the auditor will find the gap in about four minutes." — Grace Nakamura, Physical Security Consultant, Meridian Risk Partners
Evidence and Audit Logs for Controls 7.1–7.2
Certification bodies don't take your word for any of this — they sample it. An auditor will typically pull a date range of badge access logs, cross-reference it against the visitor log and HR's current employee roster, and ask you to explain any discrepancy: a badge that fired for someone who left the company two months ago, a visitor logged in with no corresponding sign-out, a Secure-zone entry with no matching work ticket. The evidence has to exist, has to be retrievable on demand, and has to actually reconcile.
Evidence Artifact | What It Proves | Typical Retention |
|---|---|---|
Badge access control system logs | Who entered which zone, when, matched to an individual credential | 12 months minimum; longer if regulatory requirements apply |
Visitor sign-in / sign-out log (paper or digital) | Non-employee access, host accountability, dwell time | 12 months minimum |
CCTV footage of entry points | Independent corroboration of badge/visitor logs; catches tailgating badge logs miss | 30–90 days typical, longer for Secure zones if storage allows |
Perimeter and zone diagram (from Control 7.1 work) | Formal definition of where perimeters and zones exist | Current version always available; prior versions retained for change history |
Badge issuance and deactivation register | Timely provisioning and, critically, timely revocation on termination | Life of employment plus retention period after |
Access review records (periodic recertification of who has access to what) | Access rights still match current role/need | Per review cycle, typically retained 2+ years |
Delivery / loading dock log | Third-party access at the dock, separate from main entry | 12 months minimum |
Incident and near-miss reports (tailgating attempts, propped doors, lost badges) | The program actually detects and responds to failures, not just prevents them | Per incident management policy |
Two of these deserve extra emphasis because they're the ones auditors dig into hardest. Badge deactivation timing is a perennial finding — organizations are generally good at issuing badges promptly and bad at revoking them the same day someone leaves, and an auditor who cross-references your HR termination list against your badge system will find every gap. And access reviews are frequently treated as a paperwork exercise rather than a real reconciliation; a review that rubber-stamps the existing access list without anyone actually checking it against current roles provides almost no assurance value, even though it technically satisfies "we conducted a review."
What Happens During the Audit Itself
For Stage 1, expect a documentation review: does a zone diagram exist, does a physical entry procedure exist, does a visitor procedure exist, and do they reference each other consistently. Gaps here are cheap to fix if caught early, which is exactly why the internal audit dry run in the implementation timeline above matters — it's far less expensive to discover a missing procedure yourself than to receive it as a formal Stage 1 finding with a remediation deadline attached.
Stage 2 is where the physical walkthrough happens. A competent auditor will ask to see a Secure zone in person, request the badge log for a date range they choose (not one you volunteer), and cross-reference a small sample of entries against your HR roster and your visitor log. They will also, more often than clients expect, simply watch the front door for ten or fifteen minutes to see whether the challenge culture you documented actually exists in practice — whether staff badge in individually, whether a held door gets questioned, whether a visitor without a badge gets stopped. Surveillance audits, conducted annually to maintain certification, repeat a lighter version of this sampling indefinitely, which is the real argument against treating any of this as a one-time project: the evidence has to keep being true, not just be true once.
Common Mistakes We See
After walking dozens of organizations through this pair of controls, the same handful of failure patterns show up again and again — often in combination, the way they did at Sable Analytics.
Mistake | Why It Happens | Fix |
|---|---|---|
No formal perimeter diagram exists | Perimeters "feel obvious" to people who work there every day | Produce an actual floor plan with zones marked and keep it version-controlled |
Reception desk unstaffed during shift changes or breaks | Staffing costs and lunch coverage get deprioritized | Overlap shifts or route front-door access through a badge reader during gaps |
Doors propped open for convenience (deliveries, HVAC work, smoke breaks) | Auto-closers are seen as an annoyance, not a control | Door-held-open alarms; enforce as a disciplinary matter, not a suggestion |
Shared or generic badges/PIN codes for contractors | Feels faster than individual provisioning | Individually issued, individually revocable credentials — no exceptions |
Badges not deactivated promptly on termination | HR offboarding and facilities/IT aren't linked processes | Integrate badge deactivation into the termination checklist as a same-day step |
Visitors indistinguishable from staff | No distinct visitor badge design, or badges not enforced visually | Bright, clearly marked, time-expiring visitor badges — and a culture that checks for them |
"VIP" exemptions from entry procedures | Deference to seniority | Zero exceptions in policy and in practice, full stop |
Loading dock treated as low-risk because it's "just deliveries" | Attention concentrated on the main entrance | Separate the dock as its own zone with its own log and escort rule |
Zone boundaries drawn once and never revisited | Office moves, renovations, and new leases outpace documentation | Re-validate the zone diagram on any facilities change and at least annually otherwise |
7.1/7.2/7.3 treated as one undifferentiated "physical security" bucket in the SoA | Faster to write, harder to evidence separately | Document each control's scope and evidence independently, even if the narrative overlaps |
Roles and Ownership
Perimeters and entry controls fail almost as often from unclear ownership as from missing technology — someone has to be accountable for the zone diagram, someone else for the badge system, and it should be written down which is which. This is a direct extension of the work covered in roles and responsibilities in information security under Controls 5.2–5.4: physical security ownership deserves the same explicit assignment as any information security responsibility.
Responsibility | Typical Owner | Backup / Escalation |
|---|---|---|
Perimeter and zone diagram (Control 7.1) | Facilities manager or head of security | CISO or security committee, for sign-off |
Badge/entry system administration (Control 7.2) | IT or facilities, depending on org size | Security operations, for anomaly review |
Visitor management (front-of-house) | Reception / office management | Facilities manager during coverage gaps |
Badge issuance and deactivation | HR (trigger) + IT/Facilities (execution) | Security, if timeliness breaches SLA |
Access log review | Security operations or internal audit function | CISO |
Loading dock and delivery oversight | Facilities or warehouse management | Security, for incident escalation |
Reception and front-of-house staff deserve a specific mention here, because they function as a live entry control, not just an administrative role. Vetting the people who staff that desk matters — the same logic covered under screening and background checks in Control 6.1 applies to anyone with standing authority to wave someone past a physical boundary, including outsourced reception or guard staff, who are sometimes overlooked because they're contractors rather than employees.
A Realistic Implementation Timeline
Clients starting from zero — no zone diagram, no formal entry-control scheme, badge logs nobody has ever pulled for review — consistently ask the same question: how long does this actually take? The honest answer depends heavily on whether you're retrofitting an existing occupied facility or specifying controls for a new lease, but the sequencing below is close to what we run with most mid-sized organizations.
Phase | Typical Duration | Key Activities | Primary Owner |
|---|---|---|---|
Assessment and mapping | Weeks 1–2 | Walk the facility, draw the zone diagram, inventory existing locks/readers/cameras, identify undefined boundaries (Sable's network closet problem) | Facilities manager + security lead |
Gap analysis | Week 2–3 | Compare current state against the zone-by-zone scheme, prioritize gaps by asset sensitivity, estimate cost | Security lead, with facilities input |
Procurement and installation | Weeks 3–10 | Order and install badge readers, biometric units, mantraps, door hardware, or signage as needed; longer for mantraps or structural wall work | Facilities, with vendor support |
Process build | Weeks 4–8 (parallel to installation) | Draft visitor management procedure, badge issuance/deactivation workflow, delivery/dock procedure | Security lead, HR, facilities |
Staff rollout and training | Weeks 8–10 | Train reception and facilities staff on new procedures; brief all staff on challenge culture and badge policy | Security awareness / training owner |
Evidence baseline | Weeks 10–12 | Run the new process for a full cycle, pull the first badge/visitor log reconciliation, correct gaps before the audit sees them | Security lead / internal audit |
Internal audit dry run | Week 12–13 | Sample logs the way an external auditor would; fix findings before Stage 1 | Internal audit function |
Twelve to thirteen weeks is a reasonable planning horizon for an organization with one or two facilities and no structural construction required. Add meaningfully more time — often two to four months — if the gap analysis surfaces a need for a mantrap, a reinforced server room wall, or a full badge-system replacement, since procurement and installation lead times for access-control hardware routinely run six to ten weeks on their own before a single door is fitted.
A budget note worth flagging early: the single biggest line-item variance we see between clients isn't the hardware, it's whether reception needs to move from single coverage to overlap-shift coverage to close the gap that let Sable's intruder through. That's a recurring labor cost, not a one-time capital expense, and it belongs in the business case alongside the badge readers.
Case Studies
Case Study 1: Sable Analytics — Closing the Gap After the Fact
The remediation Priya Chandrasekaran led at Sable Analytics after the courier-jacket intrusion became, eighteen months later, the case her team used to win back the health plan contract they'd lost. The fix wasn't exotic: Sable formally mapped its zones for the first time, reclassifying the network closet as a Secure zone with slab-to-slab walls (closing the drop-ceiling gap that had also existed unnoticed), installing an encrypted smart-card reader with a PIN as a second factor, and physically separating the mailroom's foot traffic from that hallway entirely. Reception was staffed with an overlap shift so the desk was never empty, and a door-held-open alarm was added to the front entrance. Over the following fourteen months, Sable logged zero unauthorized entries into any Restricted or Secure zone, achieved ISO 27001 certification nine months after starting the remediation, and — most importantly to the board — won back the $1.4-million contract on the strength of a physical security walkthrough the health plan's own assessors conducted on-site.
"The health plan's assessor asked me to show him our zone diagram before he asked to see a single server. I used to think physical security was the boring part of this job. I don't anymore." — Priya Chandrasekaran, VP of Security, Sable Analytics
Case Study 2: Halcyon Biotech — When Badges Aren't Enough
Halcyon Biotech, a 340-person biotech firm running wet-lab research alongside a compound library worth tens of millions in R&D investment, discovered during a routine penetration test that its proximity badge system used unencrypted RFID credentials that could be cloned with a sub-$50 handheld reader from roughly six inches away — close enough to achieve in a crowded elevator or hallway without the badge holder noticing. The lab's Restricted and Secure zones, holding both physical compound samples and the electronic lab notebooks describing them, relied entirely on that badge system. Halcyon replaced badge readers at every Restricted and Secure zone door with encrypted smart cards paired with a biometric second factor for the compound library specifically, and instituted a badge-back / anti-passback rule that flags any credential used to badge in twice without an intervening exit. The firm's internal risk assessment, built for its cyber-insurance renewal, estimated the cloning vulnerability as carrying a reasonably foreseeable exposure north of $4 million in IP loss had it been exploited before discovery — a number the insurer used to justify a lower premium once the fix was verified.
Case Study 3: Continental Freight Systems — The Loading Dock Nobody Watched
Continental Freight Systems, a regional logistics operator, treated its warehouse loading dock as operationally separate from its "real" security perimeter, which the team had focused entirely on the administrative office wing. Over roughly a year, inventory shrinkage on high-value electronics pallets ran well above industry benchmarks, and an internal investigation traced a portion of it to drivers and dock workers moving freely between the dock and adjacent warehouse aisles with no log, no escort rule, and cameras pointed at the wrong angle to capture pallet movement. Continental redefined the dock as its own zone under Control 7.1, added a dock sign-in log and camera coverage aligned to the actual pallet staging area, and required warehouse staff — not drivers — to move freight past the dock boundary. Shrinkage costs attributable to the dock area dropped by an estimated $310,000 in the following year, and the finding, once remediated, became a positive note in Continental's next customer security audit rather than an open item.
How This Maps to Other Frameworks
If your organization is pursuing or maintaining more than one certification — a common position for vendors selling into both enterprise and regulated markets — it helps to know that physical perimeter and entry requirements aren't unique to ISO 27001. The underlying expectations are broadly consistent across frameworks, even though the language and audit mechanics differ.
Framework | Physical Security Requirement | How It Compares to ISO 27001 7.1–7.2 |
|---|---|---|
ISO/IEC 27001:2022 | Controls 7.1 (perimeters) and 7.2 (physical entry) | Baseline used throughout this article |
SOC 2 | Common Criteria addressing physical access controls | Similar intent — restrict and log physical access to systems — evaluated via evidence sampling over a review period rather than a point-in-time audit |
PCI DSS | More prescriptive about specific mechanisms (e.g., visitor badges, media handling) but conceptually aligned with zone-based entry control |
The practical upshot: an organization that builds a genuine, evidenced zone model and entry-control scheme for ISO 27001 is doing roughly 80% of the work a SOC 2 or PCI DSS physical security assessment will also demand. The evidence artifacts — badge logs, visitor logs, zone diagrams, review records — are largely reusable across frameworks, which is one of the stronger arguments for treating this as core operational hygiene rather than a compliance checkbox exercise done once and shelved.
Physical Security as a Trust Signal, Not Just a Checkbox
It's tempting to treat perimeters and entry controls as the least glamorous section of an ISO 27001 implementation — badges and door hardware next to threat intelligence and cryptography can feel like a step down in sophistication. That framing gets it backwards. Every enterprise customer running a vendor security review, every cyber insurer pricing a policy, and every certification auditor treats physical access as a leading indicator of how seriously an organization takes security overall, precisely because it's so visible and so easy to verify on a site visit. A company that can produce a clean zone diagram, a reconciled badge log, and a visitor process with zero exceptions is telling a prospective customer something that's hard to fake: that the discipline runs deeper than the parts of security that live only on a screen.
That's the real business case here. Sable Analytics didn't lose its contract because of a technical control gap that only a specialist would notice — it lost it because a client's own security assessor walked the floor and couldn't get a straight answer about where the secure area started. Getting Controls 7.1 through 7.3 right closes that gap permanently, and it does so with some of the least expensive controls in the entire Annex A catalogue: a diagram, a badge policy, a visitor log, and a culture that doesn't hold the door for strangers.
"Clients ask me all the time which controls give them the best return for the least spend. Physical entry controls, every time. A properly configured badge system and a visitor policy that's actually enforced costs a fraction of what a single breach notification runs, and it's usually the first thing a savvy customer's security team checks." — Tomas Rehak, CISO, Vantage Rail Logistics
If you're building out this part of your ISMS, start with the zone diagram — everything else in this article depends on it existing first. From there, our ISO 27001 Mandatory Documents Checklist will show you exactly which physical security artifacts your auditor will expect to see, and the Annex A — All 93 Controls at a Glance cheat sheet keeps the full physical theme (and the other 90 controls) on one page while you work through implementation. If you're earlier in the process and still sizing the effort, The Complete ISO 27001 Implementation Guide walks through sequencing physical controls alongside the rest of your ISMS build, our ISO 27001 Gap Analysis Tool will flag exactly where your current perimeter and entry setup falls short of certification readiness, and the Internal Audit Checklist gives you the sampling approach to test your own badge and visitor logs before an external auditor does it for you.
