ISO27001

Physical Security Perimeters and Entry Controls: ISO 27001 Controls 7.1–7.3

Physical Security Perimeters and Entry Controls: ISO 27001 Controls 7.1–7.3
Loading advertisement...
30

Priya Chandrasekaran got the call at 7:42 on a Tuesday morning, twelve minutes after she'd sat down with her coffee. She was VP of Security at Sable Analytics, a 220-person healthcare data analytics firm in Raleigh that processed claims data for four regional health plans. The call was from her facilities manager, and it started with the sentence nobody wants to hear before their coffee is even warm: "I think someone was in the server room overnight who shouldn't have been."

Here's what the badge logs and the grainy lobby camera eventually pieced together. At 8:14 the previous morning — during the ten-minute window when the receptionist was covering a second-floor delivery and the front desk sat empty — a man in a courier jacket carrying a flat package had walked in directly behind two Sable employees returning from a smoke break. The employees held the door. Of course they held the door; that's what polite people do. The man in the courier jacket had no badge, made no attempt to check in, and nobody stopped him, because nobody was there to stop him and the two employees assumed he was headed to the mailroom, which — as it happened — shared a hallway with the network closet that Sable's facilities team had, for reasons of pure convenience, always called "the data room."

That hallway had never been formally designated as anything. It wasn't listed as a secure zone in any policy. It didn't have its own badge reader — the network closet's push-button lock used a four-digit code that had last been changed when the building opened, three years earlier, and was written on a sticky note inside the door frame because contractors kept forgetting it. The man in the courier jacket didn't even need the code. The door had been propped with a fire extinguisher because the HVAC technician working that week found the auto-closer annoying.

He was inside for eleven minutes. He plugged a USB drive into an idle terminal that a claims-processing analyst had left logged in overnight — a separate failure, but one made possible by the physical one — and copied a folder of denormalized claims exports totaling 41,000 patient records: names, dates of birth, diagnosis codes, and partial Social Security numbers used for cross-plan reconciliation. He was gone before the receptionist got back to her desk.

Sable never identified him. What Sable did get, over the following five months, was a forensic investigation bill of $180,000, breach notification and two years of credit monitoring for 41,000 people at just under $310,000, a state attorney general inquiry that cost another $90,000 in outside counsel, and — the number that actually kept Priya up at night — the loss of a $1.4-million-a-year contract renewal with the largest of the four health plans, whose own security team asked a question Sable couldn't answer convincingly: "How do you define the boundary of your secure areas, and how do you control who crosses it?"

That question is, almost word for word, what ISO/IEC 27001:2022 Annex A Control 7.1 and Control 7.2 ask you to answer in writing, with evidence. Sable didn't have a perimeter, because nobody had ever drawn one. It had a lock, but no controlled entry point, no visitor process, no logging, and no zone hierarchy that separated "anyone can walk in" from "only cleared staff go here." This article is about making sure that gap doesn't exist in your organization — and about building something an auditor, a customer security questionnaire, or a real intruder in a courier jacket can't walk straight through.

Who This Is For

This article is for the person who owns — or is about to be handed — physical security as part of an ISO 27001 implementation: a facilities manager suddenly responsible for compliance evidence, a security or IT leader who assumed physical controls were "someone else's problem," or a founder at a growing company who just realized their office lease doesn't come with a security policy attached. You'll walk away with a working definition of what counts as a security perimeter under Control 7.1, a concrete entry-control scheme under Control 7.2 that covers badges, visitors, and deliveries, a clear sense of where Control 7.3 picks up the story, and the specific evidence an auditor will ask you to produce. If you manage a single leased office suite or a multi-building campus with a data center, the same layered logic applies — only the scale changes.

Physical Controls in the Bigger ISO 27001 Picture

Controls 7.1 through 7.3 sit at the front of Annex A's physical theme, which runs from 7.1 through 7.14 and covers everything from perimeters to equipment disposal — the full sweep is mapped out in our ISO 27001 Physical Controls Overview. Perimeters and entry controls are the foundation the rest of that theme builds on: you can't secure "offices, rooms, and facilities" under Control 7.3 if you haven't first defined where your security perimeter actually is, and you can't meaningfully monitor physical access under the related Control 7.4 (physical security monitoring) if there's no controlled entry point generating events worth watching. If any of the terminology here — "secure area," "controlled zone," "physical entry" — is unfamiliar, our ISO 27001 glossary of terms defines them the way the standard uses them, which is worth doing before an auditor uses them differently than you expect.

It's also worth being precise about what these controls are not. Control 7.1 and 7.2 govern the physical layer — walls, doors, badges, guards, cameras at entry points. They work hand in hand with, but are distinct from, Access Control Policy under Controls 5.15–5.18, which governs logical access to systems and information. A badge that opens a server room door and a login that opens a database are both "access control" in the colloquial sense, but ISO 27001 separates them deliberately, because the risks, the controls, and often the owners are different. A mature ISMS treats them as two halves of the same coin — a badge revoked the same day as an account, a visitor log that mirrors a system access log — but they are not the same control, and conflating them in your documentation is one of the more common ways organizations confuse their own auditors.

"The single most common finding I write up in physical security audits isn't a missing camera or a broken lock — it's an organization that genuinely cannot tell me where their secure area begins. If you can't draw the line, you can't defend the line." — Aisha Bello, Lead ISO 27001 Auditor, Northbridge Assurance

Control 7.1: Physical Security Perimeters

The requirement itself is deceptively short: define and use security perimeters to protect areas containing information and other associated assets. In practice, this is the control that forces you to answer a question most organizations have never explicitly asked: where, exactly, does "inside" become "outside," and how many layers of "inside" do you actually have?

What Counts as a Perimeter

A security perimeter is any physical or structural boundary that separates one level of trust from another. That's a broader idea than most people assume when they hear "perimeter" and picture a fence. A perimeter can be:

  • The exterior wall and locked doors of a building.

  • A floor-to-ceiling partition separating a leased office suite from the rest of a shared building.

  • A caged rack inside a colocation data center, where the colo provider controls the building perimeter and you control the cage.

  • The walls of a single server room, records vault, or executive floor inside an otherwise open-plan office.

  • The boundary of a home office for a remote employee handling regulated data — a perimeter Control 7.1 does not exempt just because there's no badge reader involved.

The mistake Sable Analytics made was treating "the building has a lock on the front door" as equivalent to "we have defined our security perimeters." It hadn't defined anything past that single, outermost layer. A network closet that holds claims data for four health plans needs to be its own perimeter, nested inside the building perimeter, with its own controls — and that nesting is the whole point of Control 7.1.

The Concentric Zone Model

The practitioner tool for this is the concentric zone model — sometimes called defense-in-depth applied to physical space. You draw your facility as a series of rings, each one harder to enter than the last, with the most sensitive assets at the center. An intruder who defeats one ring still has to defeat the next, and every ring crossing is a chance to detect them.

Zone

Typical Physical Examples

Who Belongs There

Trust Level

Public

Sidewalk, parking lot, building exterior, ground-floor lobby before check-in

Anyone

None assumed

Reception / Transition

Staffed reception desk, waiting area, delivery drop point

Staff, expected visitors, couriers

Screened on entry

Controlled

General office floors, open-plan workspace, standard meeting rooms

Badge-holding employees and escorted visitors

Employment-based trust

Restricted

Finance, HR, legal, executive offices, R&D labs

Role-cleared staff only

Need-to-know

Secure

Server rooms, network closets, data centers, records vaults, cash rooms

Named, individually authorized personnel

Highest — logged and monitored

Sable's problem, mapped onto this model, is obvious in hindsight: the network closet — which should have sat in the Secure zone — had no boundary distinguishing it from the Controlled zone around it. There was no ring left for the intruder to defeat after the front door, because the front door was effectively the only ring that existed.

Perimeter Construction Standards

Auditors don't expect prison-grade construction for a marketing agency's leased suite, but they do expect the physical construction of a perimeter to be proportionate to what it protects, and they expect you to have thought about it rather than inherited it from whoever signed the lease.

Perimeter Feature

Deterrent Value

Typical Application

Notes

Full-height walls (slab-to-slab, not just to a drop ceiling)

High

Server rooms, records vaults

Drop-ceiling gaps are a classic pen-test entry point — go up and over

Solid-core doors with commercial-grade locks

Medium–High

Restricted and Secure zones

Hollow-core interior doors are a common weak point in older office buildouts

Perimeter fencing and controlled vehicle gates

High

Data centers, campuses, warehouses

Combined with lighting and CCTV for deterrence plus detection

Anti-tailgating door hardware (delayed egress, door-forced alarms)

Medium

Any controlled or higher zone

Alerts on doors held open beyond a threshold

Window security (laminated glass, restricted ground-floor glazing)

Medium

Ground-floor offices, retail-adjacent leases

Often overlooked because it isn't a "door" control

Reinforced or windowless walls for server rooms

High

Data centers, network closets

Removes a bypass route around the door entirely

Common Perimeter Types

Not every organization's perimeter looks the same, and the standard doesn't require it to. What matters is that whatever perimeter you have is documented, matches reality, and is defensible in your Statement of Applicability. Our SoA how-to guide walks through justifying inclusions like this one in the document itself.

Environment

Perimeter Approach

Primary Risk If Undefined

Single leased office suite

Suite entry door as outer perimeter; internal server closet as inner perimeter

Shared-building common areas treated as "inside" when they aren't

Multi-tenant office building

Building lobby + suite door as two nested perimeters

Landlord-controlled areas assumed to be under your control (they aren't)

Owned campus with data center

Site fence, building entry, and data center floor as three nested perimeters

Vehicle gates and loading areas left out of the model entirely

Colocation data center

Provider controls building/floor perimeter; you control your cage or rack perimeter

Assuming the colo's perimeter substitutes for your own access records

Retail or warehouse with back-office

Public sales floor vs. staff-only back office as the primary boundary

Stockroom and office areas physically adjoining public space with no clear line

Remote / home office

Home itself as outer perimeter; locked room or cabinet as inner perimeter for regulated data

Treated as out of scope entirely, when Control 7.1 still applies to the assets involved

"People hear 'security perimeter' and think fences and turnstiles. Half the perimeters I assess are a locked door with a keypad — and that's fine, as long as someone can tell me why that door is where it is, what's on the other side of it, and who's allowed through. The construction matters less than the intentionality." — Marcus Feld, Director of Physical Security, Continental Freight Systems

The output of Control 7.1 work is not a fence — it's a diagram. Every organization implementing this control should be able to produce a floor plan or campus map with zones drawn on it, asset locations marked, and a one-line justification for each boundary. That diagram becomes the backbone of everything Control 7.2 builds next: you cannot design entry controls for zones you haven't drawn.

Control 7.2: Physical Entry

Once your perimeters are drawn, Control 7.2 asks the next logical question: secure areas shall be protected by appropriate entry controls and access points. "Appropriate" is doing a lot of work in that sentence, and it's the word an auditor will press you on. Appropriate for a five-person accounting firm's file room is not appropriate for a payment processor's data center floor, and the standard deliberately doesn't specify a mechanism — it specifies an outcome: only authorized individuals cross into a secure area, and there's a record of who did.

Entry Control Mechanisms

Most organizations end up using a mix of these, layered by zone rather than applied uniformly everywhere. Uniform application is itself a common mistake — a badge reader on the front lobby door and an identical badge reader on the server room door look consistent, but they're protecting wildly different assets and usually deserve different strength.

Mechanism

Strength

Approximate Cost per Door

Best Suited To

Staffed reception / security guard

Medium (human judgment, but fatigue and shift gaps are real)

Ongoing labor cost, no hardware

Reception / transition zone

Proximity (RFID) badge reader

Medium (clonable with cheap hardware unless encrypted)

$800–$2,500 installed

Controlled and restricted zones

Encrypted smart card (e.g., high-frequency, mutual-auth)

High

$1,500–$4,000 installed

Restricted and secure zones

PIN keypad

Low–Medium (shared codes, shoulder-surfing)

$300–$1,000

Low-sensitivity internal doors, as a secondary factor

Biometric (fingerprint, iris, palm-vein)

High

$2,500–$6,000 installed

Secure zones, especially where badge-sharing is a risk

Two-factor entry (badge + PIN, or badge + biometric)

Very high

Sum of components

Secure zones holding regulated or crown-jewel data

Mantrap / interlocking door (only one door opens at a time)

Very high — defeats tailgating structurally

$8,000–$25,000 installed

Data centers, cash rooms, high-security labs

Mechanical key lock

Low (no logging, keys get copied, hard to revoke)

Low

Acceptable only as a fallback or for the lowest-risk internal doors

A note on mechanical keys: they're not banned by ISO 27001, but they fail the evidentiary test badly. A key can't tell you who opened a door at 2:14 a.m., and re-keying every lock when an employee leaves is rarely done in practice. If a mechanical key is your primary control on anything above the Controlled zone, expect an auditor to flag it as disproportionate to the risk.

Visitor Management

Visitors are where most physical intrusions actually happen, because visitors are, by design, people the organization doesn't fully trust yet — and every process built around them has to balance hospitality against verification. A functioning visitor program has five non-negotiable elements: pre-registration where feasible, identity verification at arrival, a visibly distinct temporary badge, a named escort or designated escort-free zone, and a logged sign-out. Skip any one of these and you've effectively created an unmonitored door into your Controlled zone.

The badge itself matters more than organizations think. A visitor badge that looks similar to an employee badge from ten feet away defeats the entire purpose — it should be a different color, prominently marked "VISITOR," and ideally time-limited so it visibly expires or must be surrendered. Sable Analytics, notably, had no visitor badge process at all; the man in the courier jacket was never issued anything to distinguish him from staff, because nobody engaged with him in the first place.

Delivery and Loading Areas

Deliveries deserve their own entry point, separate from the main employee and visitor entrance, for a simple reason: couriers arrive constantly, are rarely verified beyond a company logo on a jacket, and have a legitimate reason to be carrying boxes that could just as easily conceal something else. A dedicated loading dock or delivery point, physically separated from the Controlled zone, with its own sign-in and a rule that delivery personnel never proceed past the drop point unescorted, closes off one of the most exploited entry vectors in physical social engineering. This is also where Control 7.2 intersects with supplier and vendor risk more broadly — a courier is, functionally, an unvetted third party with physical access, and the same due-diligence instinct that governs supplier relationships applies here even though the interaction lasts ninety seconds.

"Deliveries are the blind spot in almost every physical security program I've reviewed. Everyone locks down the front door and forgets that the loading dock is a second front door with no receptionist and a lot more foot traffic." — Devon Track, Facilities Security Manager, Halcyon Biotech

Defending Against Tailgating and Piggybacking

Tailgating (following an authorized person through a door without badging in) and piggybacking (a variant where the authorized person knowingly, if unwittingly-negligently, holds the door) are the single most common way physical entry controls actually fail. The technology can be flawless and the process still collapses at the point where a badge reader meets ordinary human politeness — nobody wants to be the person who lets a door slam in a stranger's face.

Defense

How It Works

Relative Cost

Effectiveness

Security awareness training with physical scenarios

Staff practice declining to hold doors and challenging unbadged individuals

Low

Medium — decays without reinforcement

"Challenge culture" policy, backed by management

Explicit permission (and expectation) to politely challenge anyone without a visible badge

Low

Medium–High, if genuinely reinforced

Turnstiles / optical turnstiles

Physically permit one badge-in per one person-through

Medium–High

High

Mantrap / interlocking vestibule

Second door only unlocks after first door fully closes and locks

High

Very high

Door-held-open alarms

Alerts security if a controlled door stays open beyond a set threshold

Low–Medium

Medium — detective, not preventive

Video analytics / tailgating detection cameras

AI-assisted detection of two people crossing on one badge event

Medium–High

Medium–High, improving rapidly

Badge-back / anti-passback logic

System rejects a badge attempting to badge in twice without an intervening badge-out

Low (software config)

Medium — catches shared-credential misuse

No single row in that table is sufficient on its own. The strongest programs combine a cultural layer (challenge culture, reinforced training) with a structural layer (turnstiles or mantraps at the highest-sensitivity boundaries) and a detective layer (door alarms, video analytics) that catches what the first two miss. Sable's failure was the absence of all three at once: no reinforced culture (employees were never trained to question a courier), no structural barrier past the front door, and no detection mechanism that would have flagged an eleven-minute unauthorized presence in the network closet.

Where Control 7.3 Fits

It's worth being precise about the boundary between these three controls, because organizations frequently blur them in their documentation and auditors notice. Control 7.1 defines where your perimeters are. Control 7.2 governs how people cross those perimeters. Control 7.3 — securing offices, rooms and facilities — governs what happens inside the space once someone has legitimately crossed: physical security for offices, rooms and facilities shall be designed and implemented. That covers room-level design decisions such as whether sensitive work happens in rooms visible from public corridors, how meeting rooms used for confidential discussions are positioned, where server rooms sit relative to exterior walls and plumbing risk, and how individual offices, cabinets, and archive rooms are hardened beyond the general office footprint.

Sable's network closet is a useful illustration of where these controls hand off to one another. Control 7.1 should have required Sable to formally designate that closet as a Secure zone with its own defined boundary. Control 7.2 should have required a proper entry mechanism — not a shared sticky-note PIN — governing who crosses that boundary. Control 7.3 would then govern the room itself: was it built with slab-to-slab walls, was it free of unrelated foot traffic like the mailroom, did it have appropriate fire suppression that wouldn't damage equipment, and was equipment sited away from windows and water lines — the last point overlapping with the equipment-level protections covered under equipment security and maintenance in Controls 7.8–7.13. This article focuses its depth on the first two questions — the boundary and the crossing point — because they're the foundation everything else sits on. For the room-by-room implementation detail on server rooms, executive offices, records rooms, and shared facilities, see the dedicated walkthrough on securing offices, rooms, and facilities under Control 7.3.

It's also worth flagging two closely related controls you'll encounter as you build out the rest of the physical theme, both of which extend naturally from the work in this article: Physical Security Monitoring (Control 7.4), which governs the CCTV and surveillance layer that watches the entry points you've just controlled, and Working in Secure Areas (Control 7.6), which governs staff behavior once inside a secure zone — things like no unsupervised work by third parties and no photography. Neither has a dedicated deep-dive published yet, but they're a natural next read once your perimeters and entry points are in place. Once someone is legitimately at a desk inside a Controlled or Restricted zone, the baton passes again — this time to the clear desk and clear screen policy under Control 7.7, which governs what's left visible or unlocked once the entry control has already done its job.

Building an Entry-Control Scheme by Zone

Pulling Control 7.1's zone model and Control 7.2's mechanisms together, here's the reference scheme we use with clients building this out for the first time. It's a starting template, not a mandate — the standard doesn't prescribe exact mechanisms, only proportionality.

Zone

Entry Mechanism

Visitor Policy

Escort Required?

Logging

Review Cadence

Public

None (open access)

N/A

No

CCTV only

Annual

Reception / Transition

Staffed desk, sign-in sheet or digital kiosk

Sign in, show ID, receive visitor badge

No (contained to reception area)

Visitor log, CCTV

Quarterly

Controlled (general office)

Proximity badge reader

Escorted only, badge visible at all times

Yes

Badge access log

Quarterly

Restricted (finance, HR, execs, labs)

Encrypted smart card, role-based

Pre-approved and escorted, logged separately from general visitor log

Yes, by role-authorized staff

Badge access log, reviewed monthly

Monthly

Secure (server room, data center, vault)

Two-factor: badge + biometric or badge + PIN

No unescorted visitors under any circumstance; contractors logged individually

Yes, by named authorized personnel only

Badge log + CCTV + entry/exit register, reviewed weekly

Weekly to monthly, per risk

Delivery / loading dock

Separate entry, dock staff sign-in

Couriers never proceed past drop point

Yes, if any progression beyond dock

Delivery log, CCTV

Quarterly

Two things stand out when clients see this table for the first time. First, the review cadence tightens as sensitivity increases — a Secure zone's access log reviewed only annually is functionally the same as not reviewing it at all, because by the time an anomaly surfaces, the exposure window has already closed. Second, "escort required" isn't a box to tick once; it needs a named accountable role in each zone, or it degrades into the same politeness failure that let Sable's intruder through the front door.

Visitor Management Flow

The process itself, end to end, is worth diagramming rather than just describing, because the failure points cluster at the handoffs between steps rather than within any single step.

Visitor Type

Special Rule

Contractor (recurring, e.g., HVAC/cleaning)

Background-checked and issued a longer-term but still distinct badge; access limited to zones relevant to their work

Delivery / courier

Stops at loading dock or reception; never issued a badge that permits Controlled-zone access

Auditor (internal or certification body)

Full facility access under escort, logged with unusual specificity since they'll review the log itself

Interview candidate

Reception and designated interview room only; never left unattended in the Controlled zone

Vendor technician (on-site system work)

Escorted to the specific Restricted or Secure zone only, with work logged alongside entry/exit times

Executive guest / board member

Still badges in and is still logged — status is not an exemption from Control 7.2

That last row trips up more organizations than any other. Exempting executives or "VIP" visitors from the standard process is one of the fastest ways to undermine an otherwise solid entry-control scheme, because it signals — to staff and to an auditor sampling the logs — that the policy is optional rather than universal.

"I tell every client the same thing before their first Stage 2 audit: if your CEO doesn't badge in like everyone else, don't bother printing the visitor policy, because the auditor will find the gap in about four minutes." — Grace Nakamura, Physical Security Consultant, Meridian Risk Partners

Evidence and Audit Logs for Controls 7.1–7.2

Certification bodies don't take your word for any of this — they sample it. An auditor will typically pull a date range of badge access logs, cross-reference it against the visitor log and HR's current employee roster, and ask you to explain any discrepancy: a badge that fired for someone who left the company two months ago, a visitor logged in with no corresponding sign-out, a Secure-zone entry with no matching work ticket. The evidence has to exist, has to be retrievable on demand, and has to actually reconcile.

Evidence Artifact

What It Proves

Typical Retention

Badge access control system logs

Who entered which zone, when, matched to an individual credential

12 months minimum; longer if regulatory requirements apply

Visitor sign-in / sign-out log (paper or digital)

Non-employee access, host accountability, dwell time

12 months minimum

CCTV footage of entry points

Independent corroboration of badge/visitor logs; catches tailgating badge logs miss

30–90 days typical, longer for Secure zones if storage allows

Perimeter and zone diagram (from Control 7.1 work)

Formal definition of where perimeters and zones exist

Current version always available; prior versions retained for change history

Badge issuance and deactivation register

Timely provisioning and, critically, timely revocation on termination

Life of employment plus retention period after

Access review records (periodic recertification of who has access to what)

Access rights still match current role/need

Per review cycle, typically retained 2+ years

Delivery / loading dock log

Third-party access at the dock, separate from main entry

12 months minimum

Incident and near-miss reports (tailgating attempts, propped doors, lost badges)

The program actually detects and responds to failures, not just prevents them

Per incident management policy

Two of these deserve extra emphasis because they're the ones auditors dig into hardest. Badge deactivation timing is a perennial finding — organizations are generally good at issuing badges promptly and bad at revoking them the same day someone leaves, and an auditor who cross-references your HR termination list against your badge system will find every gap. And access reviews are frequently treated as a paperwork exercise rather than a real reconciliation; a review that rubber-stamps the existing access list without anyone actually checking it against current roles provides almost no assurance value, even though it technically satisfies "we conducted a review."

What Happens During the Audit Itself

For Stage 1, expect a documentation review: does a zone diagram exist, does a physical entry procedure exist, does a visitor procedure exist, and do they reference each other consistently. Gaps here are cheap to fix if caught early, which is exactly why the internal audit dry run in the implementation timeline above matters — it's far less expensive to discover a missing procedure yourself than to receive it as a formal Stage 1 finding with a remediation deadline attached.

Stage 2 is where the physical walkthrough happens. A competent auditor will ask to see a Secure zone in person, request the badge log for a date range they choose (not one you volunteer), and cross-reference a small sample of entries against your HR roster and your visitor log. They will also, more often than clients expect, simply watch the front door for ten or fifteen minutes to see whether the challenge culture you documented actually exists in practice — whether staff badge in individually, whether a held door gets questioned, whether a visitor without a badge gets stopped. Surveillance audits, conducted annually to maintain certification, repeat a lighter version of this sampling indefinitely, which is the real argument against treating any of this as a one-time project: the evidence has to keep being true, not just be true once.

Common Mistakes We See

After walking dozens of organizations through this pair of controls, the same handful of failure patterns show up again and again — often in combination, the way they did at Sable Analytics.

Mistake

Why It Happens

Fix

No formal perimeter diagram exists

Perimeters "feel obvious" to people who work there every day

Produce an actual floor plan with zones marked and keep it version-controlled

Reception desk unstaffed during shift changes or breaks

Staffing costs and lunch coverage get deprioritized

Overlap shifts or route front-door access through a badge reader during gaps

Doors propped open for convenience (deliveries, HVAC work, smoke breaks)

Auto-closers are seen as an annoyance, not a control

Door-held-open alarms; enforce as a disciplinary matter, not a suggestion

Shared or generic badges/PIN codes for contractors

Feels faster than individual provisioning

Individually issued, individually revocable credentials — no exceptions

Badges not deactivated promptly on termination

HR offboarding and facilities/IT aren't linked processes

Integrate badge deactivation into the termination checklist as a same-day step

Visitors indistinguishable from staff

No distinct visitor badge design, or badges not enforced visually

Bright, clearly marked, time-expiring visitor badges — and a culture that checks for them

"VIP" exemptions from entry procedures

Deference to seniority

Zero exceptions in policy and in practice, full stop

Loading dock treated as low-risk because it's "just deliveries"

Attention concentrated on the main entrance

Separate the dock as its own zone with its own log and escort rule

Zone boundaries drawn once and never revisited

Office moves, renovations, and new leases outpace documentation

Re-validate the zone diagram on any facilities change and at least annually otherwise

7.1/7.2/7.3 treated as one undifferentiated "physical security" bucket in the SoA

Faster to write, harder to evidence separately

Document each control's scope and evidence independently, even if the narrative overlaps

Roles and Ownership

Perimeters and entry controls fail almost as often from unclear ownership as from missing technology — someone has to be accountable for the zone diagram, someone else for the badge system, and it should be written down which is which. This is a direct extension of the work covered in roles and responsibilities in information security under Controls 5.2–5.4: physical security ownership deserves the same explicit assignment as any information security responsibility.

Responsibility

Typical Owner

Backup / Escalation

Perimeter and zone diagram (Control 7.1)

Facilities manager or head of security

CISO or security committee, for sign-off

Badge/entry system administration (Control 7.2)

IT or facilities, depending on org size

Security operations, for anomaly review

Visitor management (front-of-house)

Reception / office management

Facilities manager during coverage gaps

Badge issuance and deactivation

HR (trigger) + IT/Facilities (execution)

Security, if timeliness breaches SLA

Access log review

Security operations or internal audit function

CISO

Loading dock and delivery oversight

Facilities or warehouse management

Security, for incident escalation

Reception and front-of-house staff deserve a specific mention here, because they function as a live entry control, not just an administrative role. Vetting the people who staff that desk matters — the same logic covered under screening and background checks in Control 6.1 applies to anyone with standing authority to wave someone past a physical boundary, including outsourced reception or guard staff, who are sometimes overlooked because they're contractors rather than employees.

A Realistic Implementation Timeline

Clients starting from zero — no zone diagram, no formal entry-control scheme, badge logs nobody has ever pulled for review — consistently ask the same question: how long does this actually take? The honest answer depends heavily on whether you're retrofitting an existing occupied facility or specifying controls for a new lease, but the sequencing below is close to what we run with most mid-sized organizations.

Phase

Typical Duration

Key Activities

Primary Owner

Assessment and mapping

Weeks 1–2

Walk the facility, draw the zone diagram, inventory existing locks/readers/cameras, identify undefined boundaries (Sable's network closet problem)

Facilities manager + security lead

Gap analysis

Week 2–3

Compare current state against the zone-by-zone scheme, prioritize gaps by asset sensitivity, estimate cost

Security lead, with facilities input

Procurement and installation

Weeks 3–10

Order and install badge readers, biometric units, mantraps, door hardware, or signage as needed; longer for mantraps or structural wall work

Facilities, with vendor support

Process build

Weeks 4–8 (parallel to installation)

Draft visitor management procedure, badge issuance/deactivation workflow, delivery/dock procedure

Security lead, HR, facilities

Staff rollout and training

Weeks 8–10

Train reception and facilities staff on new procedures; brief all staff on challenge culture and badge policy

Security awareness / training owner

Evidence baseline

Weeks 10–12

Run the new process for a full cycle, pull the first badge/visitor log reconciliation, correct gaps before the audit sees them

Security lead / internal audit

Internal audit dry run

Week 12–13

Sample logs the way an external auditor would; fix findings before Stage 1

Internal audit function

Twelve to thirteen weeks is a reasonable planning horizon for an organization with one or two facilities and no structural construction required. Add meaningfully more time — often two to four months — if the gap analysis surfaces a need for a mantrap, a reinforced server room wall, or a full badge-system replacement, since procurement and installation lead times for access-control hardware routinely run six to ten weeks on their own before a single door is fitted.

A budget note worth flagging early: the single biggest line-item variance we see between clients isn't the hardware, it's whether reception needs to move from single coverage to overlap-shift coverage to close the gap that let Sable's intruder through. That's a recurring labor cost, not a one-time capital expense, and it belongs in the business case alongside the badge readers.

Case Studies

Case Study 1: Sable Analytics — Closing the Gap After the Fact

The remediation Priya Chandrasekaran led at Sable Analytics after the courier-jacket intrusion became, eighteen months later, the case her team used to win back the health plan contract they'd lost. The fix wasn't exotic: Sable formally mapped its zones for the first time, reclassifying the network closet as a Secure zone with slab-to-slab walls (closing the drop-ceiling gap that had also existed unnoticed), installing an encrypted smart-card reader with a PIN as a second factor, and physically separating the mailroom's foot traffic from that hallway entirely. Reception was staffed with an overlap shift so the desk was never empty, and a door-held-open alarm was added to the front entrance. Over the following fourteen months, Sable logged zero unauthorized entries into any Restricted or Secure zone, achieved ISO 27001 certification nine months after starting the remediation, and — most importantly to the board — won back the $1.4-million contract on the strength of a physical security walkthrough the health plan's own assessors conducted on-site.

"The health plan's assessor asked me to show him our zone diagram before he asked to see a single server. I used to think physical security was the boring part of this job. I don't anymore." — Priya Chandrasekaran, VP of Security, Sable Analytics

Case Study 2: Halcyon Biotech — When Badges Aren't Enough

Halcyon Biotech, a 340-person biotech firm running wet-lab research alongside a compound library worth tens of millions in R&D investment, discovered during a routine penetration test that its proximity badge system used unencrypted RFID credentials that could be cloned with a sub-$50 handheld reader from roughly six inches away — close enough to achieve in a crowded elevator or hallway without the badge holder noticing. The lab's Restricted and Secure zones, holding both physical compound samples and the electronic lab notebooks describing them, relied entirely on that badge system. Halcyon replaced badge readers at every Restricted and Secure zone door with encrypted smart cards paired with a biometric second factor for the compound library specifically, and instituted a badge-back / anti-passback rule that flags any credential used to badge in twice without an intervening exit. The firm's internal risk assessment, built for its cyber-insurance renewal, estimated the cloning vulnerability as carrying a reasonably foreseeable exposure north of $4 million in IP loss had it been exploited before discovery — a number the insurer used to justify a lower premium once the fix was verified.

Case Study 3: Continental Freight Systems — The Loading Dock Nobody Watched

Continental Freight Systems, a regional logistics operator, treated its warehouse loading dock as operationally separate from its "real" security perimeter, which the team had focused entirely on the administrative office wing. Over roughly a year, inventory shrinkage on high-value electronics pallets ran well above industry benchmarks, and an internal investigation traced a portion of it to drivers and dock workers moving freely between the dock and adjacent warehouse aisles with no log, no escort rule, and cameras pointed at the wrong angle to capture pallet movement. Continental redefined the dock as its own zone under Control 7.1, added a dock sign-in log and camera coverage aligned to the actual pallet staging area, and required warehouse staff — not drivers — to move freight past the dock boundary. Shrinkage costs attributable to the dock area dropped by an estimated $310,000 in the following year, and the finding, once remediated, became a positive note in Continental's next customer security audit rather than an open item.

How This Maps to Other Frameworks

If your organization is pursuing or maintaining more than one certification — a common position for vendors selling into both enterprise and regulated markets — it helps to know that physical perimeter and entry requirements aren't unique to ISO 27001. The underlying expectations are broadly consistent across frameworks, even though the language and audit mechanics differ.

Framework

Physical Security Requirement

How It Compares to ISO 27001 7.1–7.2

ISO/IEC 27001:2022

Controls 7.1 (perimeters) and 7.2 (physical entry)

Baseline used throughout this article

SOC 2

Common Criteria addressing physical access controls

Similar intent — restrict and log physical access to systems — evaluated via evidence sampling over a review period rather than a point-in-time audit

PCI DSS

Requirement 9: restrict physical access to cardholder data

More prescriptive about specific mechanisms (e.g., visitor badges, media handling) but conceptually aligned with zone-based entry control

The practical upshot: an organization that builds a genuine, evidenced zone model and entry-control scheme for ISO 27001 is doing roughly 80% of the work a SOC 2 or PCI DSS physical security assessment will also demand. The evidence artifacts — badge logs, visitor logs, zone diagrams, review records — are largely reusable across frameworks, which is one of the stronger arguments for treating this as core operational hygiene rather than a compliance checkbox exercise done once and shelved.

Physical Security as a Trust Signal, Not Just a Checkbox

It's tempting to treat perimeters and entry controls as the least glamorous section of an ISO 27001 implementation — badges and door hardware next to threat intelligence and cryptography can feel like a step down in sophistication. That framing gets it backwards. Every enterprise customer running a vendor security review, every cyber insurer pricing a policy, and every certification auditor treats physical access as a leading indicator of how seriously an organization takes security overall, precisely because it's so visible and so easy to verify on a site visit. A company that can produce a clean zone diagram, a reconciled badge log, and a visitor process with zero exceptions is telling a prospective customer something that's hard to fake: that the discipline runs deeper than the parts of security that live only on a screen.

That's the real business case here. Sable Analytics didn't lose its contract because of a technical control gap that only a specialist would notice — it lost it because a client's own security assessor walked the floor and couldn't get a straight answer about where the secure area started. Getting Controls 7.1 through 7.3 right closes that gap permanently, and it does so with some of the least expensive controls in the entire Annex A catalogue: a diagram, a badge policy, a visitor log, and a culture that doesn't hold the door for strangers.

"Clients ask me all the time which controls give them the best return for the least spend. Physical entry controls, every time. A properly configured badge system and a visitor policy that's actually enforced costs a fraction of what a single breach notification runs, and it's usually the first thing a savvy customer's security team checks." — Tomas Rehak, CISO, Vantage Rail Logistics

If you're building out this part of your ISMS, start with the zone diagram — everything else in this article depends on it existing first. From there, our ISO 27001 Mandatory Documents Checklist will show you exactly which physical security artifacts your auditor will expect to see, and the Annex A — All 93 Controls at a Glance cheat sheet keeps the full physical theme (and the other 90 controls) on one page while you work through implementation. If you're earlier in the process and still sizing the effort, The Complete ISO 27001 Implementation Guide walks through sequencing physical controls alongside the rest of your ISMS build, our ISO 27001 Gap Analysis Tool will flag exactly where your current perimeter and entry setup falls short of certification readiness, and the Internal Audit Checklist gives you the sampling approach to test your own badge and visitor logs before an external auditor does it for you.


Frequently asked questions

Do Controls 7.1 and 7.2 apply to a small office of 15 people, or only to large facilities?

They apply regardless of headcount. A 15-person office still has assets worth protecting and still needs a defined perimeter and an entry control appropriate to its risk — that might be as simple as a locked suite door and a sign-in sheet for visitors, but it still needs to be documented and evidenced, not assumed.

Do we need a mantrap or biometric system to pass certification?

No. The standard requires controls proportionate to risk, not a specific technology. A well-run badge and visitor system with a strong challenge culture can satisfy Control 7.2 for most organizations. Mantraps and biometrics earn their cost in data centers, labs, and other genuinely high-consequence secure zones, not as a universal requirement.

How many security zones should we have?

Most office-based organizations land on three to five zones — public, reception/transition, controlled, and one or two higher-sensitivity zones (restricted, secure) depending on what they hold. More zones than that usually signals overcomplication; fewer than three usually means sensitive assets aren't actually separated from general office space.

How does Control 7.2 relate to Control 5.15 (access control)?

They're complementary but distinct. Control 5.15, part of the access control policy covered under Controls 5.15–5.18, governs the rules for granting access broadly — to systems, information, and physical space alike. Control 7.2 is the physical-world implementation of entry specifically: the badge reader, the guard, the mantrap. A mature ISMS documents both and shows they're consistent with each other — for example, that a person's physical badge access matches their logical system access based on the same role.

Is a receptionist enough entry control for a small company?

It can be, provided the desk is reliably staffed, visitors are actually logged and badged, and there's a fallback (a locked door, a badge reader) for the gaps when the desk is empty — lunch, shift changes, after hours. A receptionist alone, with no fallback for coverage gaps, is exactly the failure pattern that let an unauthorized person into Sable Analytics's building.

Do remote or home offices need a defined perimeter?

Yes, if the employee handles information or assets in scope for the ISMS. The perimeter is smaller — often just a locked room, cabinet, or safe rather than a building — but Control 7.1's requirement to define and use a perimeter still applies, and it should be reflected in remote working guidance rather than treated as out of scope by default.

What evidence should we have ready before a certification audit?

At minimum: a current zone diagram, badge access logs for a representative period, a visitor log, badge issuance/deactivation records showing timely revocation, and any incident or near-miss reports related to physical entry. Auditors typically sample rather than review everything, but incomplete or inconsistent records in any of these categories is a fast path to a nonconformity.

How is Control 7.3 different from 7.1 and 7.2, and do we need all three documented separately?

es, document them separately even though they overlap in practice. Control 7.1 defines the boundary, Control 7.2 controls the crossing point, and Control 7.3 governs what happens to the space itself once someone is legitimately inside — room construction, equipment siting, and facility-specific hardening. Treating all three as a single undifferentiated "physical security" narrative in your Statement of Applicability is a common and easily avoidable finding.

30

About the author

Cybersecurity Expert

Satish Kumar writes about cybersecurity, offensive security, and practical defense strategies on PentesterWorld.

Related Articles

Comments (0)

No comments yet. Be the first to share your thoughts!