What an auditor, or Sekit's evidence engine, asks for.
Physical access and visitor controls
How access to the premises and restricted areas is controlled (cards, keys, register), and how visitors are handled.
From the Sekit evidence catalog
In practice
This control lives or dies on the badge or lock system matching the access list, not on the hardware itself. A ten-person office with a coded smart lock and a spreadsheet of who has the code can pass, while a company with an expensive badge reader fails if former employees still hold active cards. Auditors pull the access review log and the visitor register together, then check whether a recent leaver's access was revoked the day they left, not weeks later at the next scheduled review.
Common gaps
A former employee's badge was still active two months after their last day, because the access review only runs annually and nobody triggered an off-cycle revocation.
Visitors sign a paper register at reception but are never escorted past the lobby, so the escort rule in the policy is not followed in practice.
The door code for the server room has not changed since it was installed, even though several contractors who no longer work with the company know it.
Questions your auditor will ask
How quickly is physical access removed when someone leaves the company?
Keys, badges and alarm codes are revoked the same day someone leaves or changes role, ahead of the scheduled periodic review.
How are visitors managed once they enter the building?
Visitors are registered, badged and escorted per the visitor management policy, recorded in the physical access and visitor controls evidence.
What mechanism controls entry to the server room or records room?
Entry uses a per-person revocable mechanism, such as a badge reader or coded smart lock, with entry records kept where feasible.
How often are physical access rights reviewed?
Access rights, including who holds keys, badges and alarm codes, are reviewed on a set schedule in addition to any leaver-triggered revocation.
Where regulation demands it
NIS2 art. 13.3 requires perimeter and physical access control for the premises hosting network and information systems.
ENS mp.if.2 requires identification of the people who access restricted areas.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.