INF-018 Physical Access and Environmental Protection
Description
Physical access to each office or facility the organisation occupies is restricted to authorised persons, granted from an approved access list that is reviewed at defined intervals and revoked on departure. Entry and exit at controlled points is recorded by an auditable access control system and visitors are recorded and escorted. Access records and alarms are reviewed at defined intervals, with anomalies raised through the incident process. Premises are monitored for unauthorised entry by intrusion detection and surveillance equipment. Fire detection, fire suppression and environmental protection appropriate to the facility are in place and maintained. For facilities the organisation does not operate, including cloud data centres, a current attestation from the operator is held and reviewed at defined intervals, with the physical and environmental controls inherited from it recorded against the requirements they satisfy. A maintenance record exists for each facility the organisation operates, listing the repairs and modifications made to the physical components that enforce its security boundary, with the component, the work done, the date and the person or contractor who performed it named on each entry. For a facility the organisation does not operate, the operator attestation covers the same ground.
Rationale
Offices exist even for a provider that owns no servers, physical access is tested in every SOC 2 examination and ISO 7.1 to 7.6 cannot be excluded from a statement of applicability without justification. Before S4 the library said nothing about either half, so twenty-nine source controls sat unmapped. The inheritance record is what makes the data centre half honest: the provider does not perform those controls, it obtains evidence that its operator does and records which requirement each inherited control answers. VND-004 holds the selection, configuration and exit process for cloud providers and VND-006 holds the periodic review of vendor security posture in general; the record here is narrower, naming the physical and environmental controls inherited and the report they come from. INF-017 holds the devices that leave the building. If the universal-scope work reaches a physical domain (PLAN Phase U3), this control is its seed. A door, a lock, a wall and the access hardware on them are the mechanism the access list is enforced by. Without a maintenance history an investigation cannot tell a forced entry from a repaired one, and a lock change made outside the record is an unrecorded grant of access to everyone holding the new key. The record is narrow on purpose: it covers the components that enforce the boundary, not the facilities queue in general, and for a provider running on somebody else's infrastructure it reaches only its own premises.
Applicability (9 profiles)
164.310(a) puts facility access controls in the rule directly. One of the two gaps is closed: 164.310(a)(2)(iv) now has a home, a maintenance record of repairs and modifications to the physical components that enforce the facility boundary, with the component, the work, the date and the person or contractor on each entry, and the operator attestation covering a facility the organisation does not operate. The other gap stands: 164.310(a)(2)(i) wants an emergency route into the facility in support of restoring lost data, when the normal approval path may be unavailable, and no control states it.
Annex points 13.1 and 13.2 add supporting utilities and environmental thresholds: electricity, telecommunications, water, gas, sewage, ventilation and air conditioning protected and monitored, redundancy considered, emergency supply contracts concluded, minimum and maximum control thresholds determined and events outside them reported. For a provider running on a third party facility the substance is inherited, and the control's attestation route is what evidences it, so the delta is that the attestation has to be read against this list rather than against a generic physical security expectation.
Framework Mappings (53)
| DCS-01 | Physical and Environmental Security Policy and Procedures | full |
| DCS-04 | Secure Area Policy and Procedures | full |
| DCS-08 | Controlled Physical Access Points | full |
| DCS-10 | Secure Area Authorization | full |
| DCS-11 | Surveillance System | partial |
| DCS-12 | Adverse Event Response Training | informative |
| DCS-13 | Cabling Security | informative |
| DCS-14 | Environmental Systems | partial |
| DCS-15 | Secure Utilities | informative |
| DCS-16 | Equipment Location | informative |
| LOG-13 | Access Control Logs | full |
| DCS-01 | Physical and Environmental Security Policy and Procedures | full |
| DCS-04 | Secure Area Policy and Procedures | full |
| DCS-08 | Controlled Physical Access Points | full |
| DCS-10 | Secure Area Authorization | full |
| DCS-11 | Surveillance System | partial |
| DCS-12 | Adverse Event Response Training | informative |
| DCS-13 | Cabling Security | informative |
| DCS-14 | Environmental Systems | partial |
| DCS-15 | Secure Utilities | informative |
| DCS-16 | Equipment Location | informative |
| LOG-13 | Access Control Logs | full |
| HIPAA-164.308.a.3.ii.A | Authorization and/or Supervision | informative |
| HIPAA-164.310.a.1 | Facility Access Controls | full |
| HIPAA-164.310.a.2.i | Contingency Operations | partial |
| HIPAA-164.310.a.2.ii | Facility Security Plan | full |
| HIPAA-164.310.a.2.iii | Access Control and Validation Procedures | partial |
| HIPAA-164.310.a.2.iv | Maintenance Records | full |
| HIPAA-164.310.c | Workstation Security | informative |
| HIPAA-164.310.d.1 | Device and Media Controls | informative |
| 7.1 | Physical security perimeters | full |
| 7.11 | Supporting utilities | informative |
| 7.12 | Cabling security | informative |
| 7.2 | Physical entry | full |
| 7.3 | Securing offices, rooms and facilities | full |
| 7.4 | Physical security monitoring | full |
| 7.5 | Protecting against physical and environmental threats | partial |
| 7.6 | Working in secure areas | partial |
| 7.8 | Equipment siting and protection | partial |
| NIS2-CIR-11.1 | Access Control Policy | informative |
| NIS2-CIR-13.1 | Supporting Utilities | partial |
| NIS2-CIR-13.2 | Protection Against Physical and Environmental Threats | partial |
| NIS2-CIR-13.3 | Perimeter and Physical Access Control | partial |
| PE-13 | Fire Protection | partial |
| PE-13(1) | Fire Protection | Detection Systems — Automatic Activation and Notification | partial |
| PE-13(2) | Fire Protection | Suppression Systems — Automatic Activation and Notification | partial |
| PE-14 | Environmental Controls | partial |
| PE-2 | Physical Access Authorizations | partial |
| PE-3 | Physical Access Control | partial |
| PE-6 | Monitoring Physical Access | partial |
| PE-6(1) | Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment | partial |
| PE-8 | Visitor Access Records | partial |
| CC6.4 | Physical Access to Facilities and Protected Information Assets | full |
Evidence (4)
Export from the physical access control system showing the current authorised access list per site and the entry and exit events for the period.
Example: Badge system export for the London and Dublin offices, 1 June to 31 August 2026, with the access list per door group and every badge event.
Test: Export the access list and the event log from the access control system and reconcile against the workforce list. Verify: (1) every holder of an active credential is a current employee, contractor or approved visitor, (2) credentials of leavers were revoked on or before their last day, (3) the access list was reviewed within the defined interval by a named approver, (4) out-of-hours and failed entry events in the period were reviewed, (5) any anomaly raised was carried into the incident process.
Visitor register and the record of the periodic review of physical access, alarms and surveillance, with the anomalies found and what was done about each.
Example: Visitor register for Q3 2026 and the quarterly physical access review record signed by the facilities owner on 2026-09-05.
Test: Request the visitor register and the most recent access review record. Verify: (1) every visitor entry names the visitor, the host and the times of arrival and departure, (2) visitors to areas holding information assets were escorted, (3) the review covers access records, alarm events and surveillance coverage, (4) each anomaly has a recorded outcome, (5) the review took place within the defined interval.
Current attestation from each infrastructure operator, with the record mapping the physical and environmental controls inherited from it to the requirements they satisfy.
Example: Cloud provider SOC 2 Type II report covering 1 October 2025 to 30 September 2026, read on 2026-09-10, with the inherited controls record listing each physical control relied on and the report section that carries it.
Test: Request the operator attestation and the inherited controls record. Verify: (1) the attestation is current and covers the period under review with no gap, (2) it covers the regions and services the production environment actually uses, (3) the inherited controls record names each physical or environmental requirement relied on and the section of the report that evidences it, (4) exceptions and complementary user entity controls in the report have a recorded response, (5) the review is dated within the defined interval and names a reviewer.
Facility security maintenance log for each facility the organisation operates, covering repairs and modifications to the physical components that enforce the security boundary.
Example: Facility security maintenance log for the London and Dublin offices, 1 January to 30 June 2026, with eleven entries.
Test: Verify: (1) a maintenance log exists for each facility the organisation occupies and is named in the physical security standard, (2) each entry names the component, the work performed, the date and the person or contractor who performed it, (3) every change to access hardware in the period appears in the log and in the access list review that followed it, (4) work performed by a contractor shows the authorisation under which the contractor was on site, (5) for facilities the organisation does not operate, a current operator attestation covers physical maintenance and is dated inside the review interval.
Questions (3)
Is physical access to each office the organisation occupies restricted to an approved access list?
A serviced or shared office still has an access list; it is held by the building operator and the organisation approves who is on it. Answer for the space the organisation controls.
Which of the following are in place at the premises the organisation occupies?
Answer for the space the organisation occupies, not for the cloud data centre. What the infrastructure operator does is covered by the attestation question. The maintenance record covers the doors, locks, walls, barriers and access hardware that enforce the boundary; a general facilities ticket queue counts only where the security work can be identified inside it.
How are the physical controls of the infrastructure operator evidenced?
Options run from strongest to weakest. The step most often missed is the last one in the strongest option: writing down which of your requirements each inherited control answers, so that a gap is visible when the report changes.