DEV Community

Cover image for ISO 27001 and Physical Access Control: An IT Manager's Checklist
Vika Beckerman
Vika Beckerman

Posted on

ISO 27001 and Physical Access Control: An IT Manager's Checklist

Why Physical Access Belongs on Your ISO 27001 Checklist

When IT managers prepare for an ISO 27001 audit, the instinct is to focus on firewalls, encryption, and access permissions inside applications. But Annex A of the standard is explicit: physical and environmental security (A.7 in the 2022 revision) is a core control domain, not an afterthought. Auditors will ask who can physically walk into your server room, your finance office, or your HR archive — and whether you can prove it with logs, not just a badge reader that "should" be working.

This is where a lot of otherwise well-run IT departments get caught out. Application access control might be airtight, with MFA, role-based permissions, and quarterly access reviews. Meanwhile the door to the server room runs on a decade-old badge system that nobody has audited, with no record of who's been issued a credential or when access was last reviewed.

The Checklist: What Auditors Actually Look For

1. Documented physical security perimeters. You need a clear definition of secure zones — server rooms, network closets, executive offices, HR file storage — and a stated policy for who can access each.

2. Access provisioning tied to a formal process. Every credential (badge, biometric enrollment, mobile wallet key) issued should map to an approval record. Auditors will sample a handful of employees and ask you to produce the request and approval for their access level.

3. Timely deprovisioning. This is the single most common finding in physical security audits: former employees or contractors whose badges were never deactivated. ISO 27001 expects access revocation within a defined, short window of termination — not "whenever facilities gets around to it."

4. Access logs with adequate retention and integrity. You need to show entry/exit records for sensitive zones, protected from tampering, retained long enough to support an investigation, and reviewed periodically — not just captured and forgotten.

5. Periodic access reviews. Annex A requires that access rights be reviewed at regular intervals. For physical access, that means periodically checking who currently holds a badge or biometric enrollment against who should, and revoking anything that doesn't match a current, approved need.

6. Visitor and contractor management. Temporary access needs its own trail — sign-in records, escort requirements for sensitive areas, and time-bound credentials that expire automatically rather than needing manual follow-up.

7. Integration between physical access and HR/IT identity systems. The strongest audit evidence is a single source of truth: when someone is terminated in HR, their badge and biometric credentials are revoked automatically, not through a separate manual ticket to facilities.

Where the Gaps Usually Show Up

Most physical access control systems were bought and installed years before anyone thought about ISO 27001. They exist in isolation from HR systems, run on their own onboarding/offboarding workflow, and generate logs that live on hardware nobody checks unless there's an incident. That disconnect is exactly what auditors are trained to probe.

This is a big part of why access control and attendance are converging into single platforms. TimeClock 365 ties badge, biometric, RFID, and mobile wallet-based door entry directly to the same system used for HR attendance — so provisioning and deprovisioning happen once, in one place, and the audit trail is unified instead of split across a door controller and a separate identity system. Organizations using this model report a 90% reduction in unauthorized access incidents, largely because access revocation is no longer a manual, easy-to-forget step handled outside HR's core process.

A Pre-Audit Self-Check

Run through this before your next ISO 27001 assessment:

  • Can you produce, right now, a list of everyone with active badge or biometric access to your server room?
  • Is that list current, or does it still include people who left six months ago?
  • Do you have documented approval records for physical access grants, not just the access itself?
  • Are physical access logs retained, protected from tampering, and reviewed on a schedule?
  • Is deprovisioning automatic when HR marks someone as terminated, or does it depend on a separate manual step?

If the answer to that last question is "manual step," you've found your highest-priority fix. It's the finding auditors flag most often, and it's the one that's easiest to eliminate by connecting physical access control to your existing HR and IT identity workflows rather than running it as an island.

Close the Gap Before the Auditor Finds It

ISO 27001 compliance for physical access isn't about buying new hardware — it's about making sure provisioning, logging, and deprovisioning are tied to one auditable process instead of scattered across systems that don't talk to each other. TimeClock 365 unifies door access and attendance so your audit trail is complete by design.

Start a free trial and see how unified access control simplifies your next ISO 27001 review.

Top comments (0)