What an auditor, or Sekit's evidence engine, asks for.
Physical access and visitor controls
How access to the premises and restricted areas is controlled (cards, keys, register), and how visitors are handled.
From the Sekit evidence catalog
In practice
For most SMEs the secure area in question is the server room or a records room, and the practical test is whether visitor and contractor rules change in practice once someone crosses that threshold. A visitor register at reception is not enough if a delivery contractor is later left alone in the server room to fix a cooling unit. Auditors ask to see the escort rule applied to that specific area, and whether anyone besides IT staff has ever been logged entering it unaccompanied.
Common gaps
The visitor policy requires an escort in restricted areas, but a maintenance contractor was left alone in the server room to service the air conditioning unit.
No log distinguishes visitors who reached only the reception area from those who entered the server or records room, so escort compliance cannot be checked for the areas that matter.
Staff routinely prop the server room door open during equipment installs, defeating the entry control the secure-area rules assume is always in effect.
Questions your auditor will ask
What rules apply once a visitor or contractor is inside a secure area rather than only the lobby?
The visitor management policy requires registration, badging and escort specifically in areas holding equipment or personal data, not only at reception.
Is the escort rule for secure areas followed in practice, not only on paper?
Every visitor is registered, badged and escorted consistently, and the physical access and visitor controls evidence shows this applied to the server or records room specifically.
How is a contractor working alone in the server room, such as for maintenance, handled?
The visitor policy treats a contractor the same as any other visitor: they are registered, badged and escorted rather than left unaccompanied in a restricted area.
Where regulation demands it
NIS2 art. 13.3 requires perimeter and physical access control for areas holding network and information systems.
ENS mp.if.2 requires identification of the people present in areas that need protection.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.