SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.7.2Physical entry

Control who can physically enter secure areas using suitable entry controls, so only authorized people reach sensitive spaces.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Physical access and visitor controls
How access to the premises and restricted areas is controlled (cards, keys, register), and how visitors are handled.
From the Sekit evidence catalog

In practice

This control lives or dies on the badge or lock system matching the access list, not on the hardware itself. A ten-person office with a coded smart lock and a spreadsheet of who has the code can pass, while a company with an expensive badge reader fails if former employees still hold active cards. Auditors pull the access review log and the visitor register together, then check whether a recent leaver's access was revoked the day they left, not weeks later at the next scheduled review.

Common gaps

A former employee's badge was still active two months after their last day, because the access review only runs annually and nobody triggered an off-cycle revocation.
Visitors sign a paper register at reception but are never escorted past the lobby, so the escort rule in the policy is not followed in practice.
The door code for the server room has not changed since it was installed, even though several contractors who no longer work with the company know it.

Questions your auditor will ask

How quickly is physical access removed when someone leaves the company?
Keys, badges and alarm codes are revoked the same day someone leaves or changes role, ahead of the scheduled periodic review.
How are visitors managed once they enter the building?
Visitors are registered, badged and escorted per the visitor management policy, recorded in the physical access and visitor controls evidence.
What mechanism controls entry to the server room or records room?
Entry uses a per-person revocable mechanism, such as a badge reader or coded smart lock, with entry records kept where feasible.
How often are physical access rights reviewed?
Access rights, including who holds keys, badges and alarm codes, are reviewed on a set schedule in addition to any leaver-triggered revocation.

Where regulation demands it

NIS2 art. 13.3 requires perimeter and physical access control for the premises hosting network and information systems.
ENS mp.if.2 requires identification of the people who access restricted areas.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.7.2?”
Also via MCP, free with account