GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

INF-018 Physical Access and Environmental Protection

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Physical access to each office or facility the organisation occupies is restricted to authorised persons, granted from an approved access list that is reviewed at defined intervals and revoked on departure. Entry and exit at controlled points is recorded by an auditable access control system and visitors are recorded and escorted. Access records and alarms are reviewed at defined intervals, with anomalies raised through the incident process. Premises are monitored for unauthorised entry by intrusion detection and surveillance equipment. Fire detection, fire suppression and environmental protection appropriate to the facility are in place and maintained. For facilities the organisation does not operate, including cloud data centres, a current attestation from the operator is held and reviewed at defined intervals, with the physical and environmental controls inherited from it recorded against the requirements they satisfy. A maintenance record exists for each facility the organisation operates, listing the repairs and modifications made to the physical components that enforce its security boundary, with the component, the work done, the date and the person or contractor who performed it named on each entry. For a facility the organisation does not operate, the operator attestation covers the same ground.

Rationale

Offices exist even for a provider that owns no servers, physical access is tested in every SOC 2 examination and ISO 7.1 to 7.6 cannot be excluded from a statement of applicability without justification. Before S4 the library said nothing about either half, so twenty-nine source controls sat unmapped. The inheritance record is what makes the data centre half honest: the provider does not perform those controls, it obtains evidence that its operator does and records which requirement each inherited control answers. VND-004 holds the selection, configuration and exit process for cloud providers and VND-006 holds the periodic review of vendor security posture in general; the record here is narrower, naming the physical and environmental controls inherited and the report they come from. INF-017 holds the devices that leave the building. If the universal-scope work reaches a physical domain (PLAN Phase U3), this control is its seed. A door, a lock, a wall and the access hardware on them are the mechanism the access list is enforced by. Without a maintenance history an investigation cannot tell a forced entry from a repaired one, and a lock change made outside the record is an unrecorded grant of access to everyone holding the new key. The record is narrow on purpose: it covers the components that enforce the boundary, not the facilities queue in general, and for a provider running on somebody else's infrastructure it reaches only its own premises.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

164.310(a) puts facility access controls in the rule directly. One of the two gaps is closed: 164.310(a)(2)(iv) now has a home, a maintenance record of repairs and modifications to the physical components that enforce the facility boundary, with the component, the work, the date and the person or contractor on each entry, and the operator attestation covering a facility the organisation does not operate. The other gap stands: 164.310(a)(2)(i) wants an emergency route into the facility in support of restoring lost data, when the normal approval path may be unavailable, and no control states it.

NIS2 Cloud Provider (EU)stablerequiredrole duty

Annex points 13.1 and 13.2 add supporting utilities and environmental thresholds: electricity, telecommunications, water, gas, sewage, ventilation and air conditioning protected and monitored, redundancy considered, emergency supply contracts concluded, minimum and maximum control thresholds determined and events outside them reported. For a provider running on a third party facility the substance is inherited, and the control's attestation route is what evidences it, so the delta is that the attestation has to be read against this list rather than against a generic physical security expectation.

Framework Mappings (53)

DCS-01Physical and Environmental Security Policy and Proceduresfull
DCS-04Secure Area Policy and Proceduresfull
DCS-08Controlled Physical Access Pointsfull
DCS-10Secure Area Authorizationfull
DCS-11Surveillance Systempartial
DCS-12Adverse Event Response Traininginformative
DCS-13Cabling Securityinformative
DCS-14Environmental Systemspartial
DCS-15Secure Utilitiesinformative
DCS-16Equipment Locationinformative
LOG-13Access Control Logsfull
DCS-01Physical and Environmental Security Policy and Proceduresfull
DCS-04Secure Area Policy and Proceduresfull
DCS-08Controlled Physical Access Pointsfull
DCS-10Secure Area Authorizationfull
DCS-11Surveillance Systempartial
DCS-12Adverse Event Response Traininginformative
DCS-13Cabling Securityinformative
DCS-14Environmental Systemspartial
DCS-15Secure Utilitiesinformative
DCS-16Equipment Locationinformative
LOG-13Access Control Logsfull
HIPAA-164.308.a.3.ii.AAuthorization and/or Supervisioninformative
HIPAA-164.310.a.1Facility Access Controlsfull
HIPAA-164.310.a.2.iContingency Operationspartial
HIPAA-164.310.a.2.iiFacility Security Planfull
HIPAA-164.310.a.2.iiiAccess Control and Validation Procedurespartial
HIPAA-164.310.a.2.ivMaintenance Recordsfull
HIPAA-164.310.cWorkstation Securityinformative
HIPAA-164.310.d.1Device and Media Controlsinformative
7.1Physical security perimetersfull
7.11Supporting utilitiesinformative
7.12Cabling securityinformative
7.2Physical entryfull
7.3Securing offices, rooms and facilitiesfull
7.4Physical security monitoringfull
7.5Protecting against physical and environmental threatspartial
7.6Working in secure areaspartial
7.8Equipment siting and protectionpartial
NIS2-CIR-11.1Access Control Policyinformative
NIS2-CIR-13.1Supporting Utilitiespartial
NIS2-CIR-13.2Protection Against Physical and Environmental Threatspartial
NIS2-CIR-13.3Perimeter and Physical Access Controlpartial
PE-13Fire Protectionpartial
PE-13(1)Fire Protection | Detection Systems — Automatic Activation and Notificationpartial
PE-13(2)Fire Protection | Suppression Systems — Automatic Activation and Notificationpartial
PE-14Environmental Controlspartial
PE-2Physical Access Authorizationspartial
PE-3Physical Access Controlpartial
PE-6Monitoring Physical Accesspartial
PE-6(1)Monitoring Physical Access | Intrusion Alarms and Surveillance Equipmentpartial
PE-8Visitor Access Recordspartial
CC6.4Physical Access to Facilities and Protected Information Assetsfull

Evidence (4)

system_exporttechnicalautomated

Export from the physical access control system showing the current authorised access list per site and the entry and exit events for the period.

Example: Badge system export for the London and Dublin offices, 1 June to 31 August 2026, with the access list per door group and every badge event.

Test: Export the access list and the event log from the access control system and reconcile against the workforce list. Verify: (1) every holder of an active credential is a current employee, contractor or approved visitor, (2) credentials of leavers were revoked on or before their last day, (3) the access list was reviewed within the defined interval by a named approver, (4) out-of-hours and failed entry events in the period were reviewed, (5) any anomaly raised was carried into the incident process.

recorddocumentmanual

Visitor register and the record of the periodic review of physical access, alarms and surveillance, with the anomalies found and what was done about each.

Example: Visitor register for Q3 2026 and the quarterly physical access review record signed by the facilities owner on 2026-09-05.

Test: Request the visitor register and the most recent access review record. Verify: (1) every visitor entry names the visitor, the host and the times of arrival and departure, (2) visitors to areas holding information assets were escorted, (3) the review covers access records, alarm events and surveillance coverage, (4) each anomaly has a recorded outcome, (5) the review took place within the defined interval.

attestationdocumentmanual

Current attestation from each infrastructure operator, with the record mapping the physical and environmental controls inherited from it to the requirements they satisfy.

Example: Cloud provider SOC 2 Type II report covering 1 October 2025 to 30 September 2026, read on 2026-09-10, with the inherited controls record listing each physical control relied on and the report section that carries it.

Test: Request the operator attestation and the inherited controls record. Verify: (1) the attestation is current and covers the period under review with no gap, (2) it covers the regions and services the production environment actually uses, (3) the inherited controls record names each physical or environmental requirement relied on and the section of the report that evidences it, (4) exceptions and complementary user entity controls in the report have a recorded response, (5) the review is dated within the defined interval and names a reviewer.

recorddocumentmanual

Facility security maintenance log for each facility the organisation operates, covering repairs and modifications to the physical components that enforce the security boundary.

Example: Facility security maintenance log for the London and Dublin offices, 1 January to 30 June 2026, with eleven entries.

Test: Verify: (1) a maintenance log exists for each facility the organisation occupies and is named in the physical security standard, (2) each entry names the component, the work performed, the date and the person or contractor who performed it, (3) every change to access hardware in the period appears in the log and in the access list review that followed it, (4) work performed by a contractor shows the authorisation under which the contractor was on site, (5) for facilities the organisation does not operate, a current operator attestation covers physical maintenance and is dated inside the review interval.

Questions (3)

boolean

Is physical access to each office the organisation occupies restricted to an approved access list?

A serviced or shared office still has an access list; it is held by the building operator and the organisation approves who is on it. Answer for the space the organisation controls.

multi

Which of the following are in place at the premises the organisation occupies?

An approved access list that is reviewed and revoked on departureAn auditable access control system that records entry and exitA visitor register with escortingIntrusion detection or surveillance covering entry pointsReview of access records and alarms at defined intervalsFire detection and suppressionEnvironmental protection appropriate to the facilityA maintenance record for repairs and modifications to the physical security componentsNone of the above

Answer for the space the organisation occupies, not for the cloud data centre. What the infrastructure operator does is covered by the attestation question. The maintenance record covers the doors, locks, walls, barriers and access hardware that enforce the boundary; a general facilities ticket queue counts only where the security work can be identified inside it.

select

How are the physical controls of the infrastructure operator evidenced?

A current attestation is obtained and reviewed on a defined cycle, with the controls inherited from it recorded against the requirements they satisfyA current attestation is obtained and reviewed on a defined cycleAn attestation is held on fileThe operator's public compliance page is relied onThe operator's physical controls are not evidenced

Options run from strongest to weakest. The step most often missed is the last one in the strongest option: writing down which of your requirements each inherited control answers, so that a gap is visible when the report changes.