What an auditor, or Sekit's evidence engine, asks for.
Physical access and visitor controls
How access to the premises and restricted areas is controlled (cards, keys, register), and how visitors are handled.
From the Sekit evidence catalog
In practice
Small offices often stop at a doorbell camera and call that monitoring, but auditors want to see recording, retention and a review step, not only a lens pointed at the door. The company should be able to show camera coverage of entry points and the server room, a stated retention period consistent with Spanish data protection rules, and at least one example of footage being pulled and reviewed after a real event, such as a lost badge or an after-hours alarm.
Common gaps
Cameras cover the front door but not the server room, so an intrusion into the area holding the most sensitive equipment would go unrecorded.
Footage is overwritten after three days, shorter than the retention period stated in the CCTV policy, so incidents discovered later cannot be investigated.
The visitor log system produces a paper trail but no timestamped digital record, so arrivals and departures cannot be reconciled against badge access logs.
Questions your auditor will ask
How is camera footage of restricted areas retained and who can view it?
The CCTV policy states retention periods, covered areas and who may view footage, consistent with Spanish data protection requirements.
How do you know the surveillance system is recording rather than assumed to be working?
The camera infrastructure is checked for continuous recording, accurate time, non-default credentials and failure alerting, not assumed to be working.
What happens after a physical security event, such as an after-hours alarm?
Footage is retained per policy and reviewed under controlled access following the event, as part of the routine CCTV operating process.
How are visitor arrivals and departures recorded for later review?
Arrivals and departures are recorded in a system that produces a complete, reviewable log, not only a signature sheet at reception.
Where regulation demands it
NIS2 art. 13.2 requires protection against physical and environmental threats to network and information systems.
ENS op.mon.3 requires vigilancia, ongoing surveillance of the systems and areas that need protection.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.