Compliance Framework Alignment
ISO/IEC 27001:2022 — A.7.1 to A.7.14 (Physical controls) NIST SP 800-88 Rev. 1 — media sanitisation (Clear / Purge / Destroy) This policy operationalises ISO/IEC 27001:2022 Annex A physical controls 7.1–7.14, and, where selected, maps to SOC 2 CC6.4/CC6.5 and PCI DSS v4.0.1 Requirement 9. It sets the physical and environmental safeguards for Acme Technologies Pvt Ltd ; it does not itself certify compliance, which depends on operating the controls and retaining evidence.
ACME TECHNOLOGIES PVT LTD PHYSICAL & ENVIRONMENTAL SECURITY POLICY
Effective Date [Effective Date]
Next Review 12 months from the effective date
Policy Owner Head of Security / Facilities (Chief Information Security Officer )
Security Contact security@acme.example 1. Purpose and Scope
This Physical & Environmental Security Policy establishes the requirements Acme Technologies Pvt Ltd applies to prevent unauthorised physical access, damage, interference, loss or theft of information, information-processing facilities and supporting assets. This policy applies to all premises owned, leased or used by Acme Technologies Pvt Ltd — offices, server rooms, data centres, storage areas and secure zones — and to all personnel, contractors, visitors and third parties who access them, together with all equipment, media and information assets located there. This policy takes effect on [Effective Date] and is reviewed at least annually (next review: 12 months from the effective date) or after any significant physical security incident, relocation or change in the threat environment.
2. Security Zones and Physical Perimeters
Facilities are classified into layered security zones, each protected by a defined perimeter (ISO 27001 A.7.1): (a) Public — reception and common areas open to visitors; (b) Restricted — general work areas accessible only to authenticated personnel; (c) Secure — server rooms, network/telecom rooms, storage of sensitive media and, where applicable, the cardholder data environment (CDE); and (d) Critical — data-centre floors and areas holding regulated or 'confidential' assets. Perimeters use physically sound construction — solid walls extending slab-to-slab, protected doors, and alarmed or reinforced windows on ground and accessible floors. The strength of each perimeter is commensurate with the classification of assets held within, and no single control is relied upon alone (defence in depth).
3. Physical Entry Controls, Badges and Access Rights
Entry to Restricted, Secure and Critical zones is controlled by individually assigned badges or credentials on a least-privilege, need-to-know basis (ISO 27001 A.7.2; SOC 2 CC6.4; PCI DSS 9.2–9.3). Access rights are formally authorised by the asset/area owner before issue, are role-based, and are reviewed at least quarterly. Badges must be worn visibly at all times, are never shared, and are revoked immediately on termination or role change (target: same business day, and no later than 24 hours). Tailgating is prohibited; Secure and Critical zones require anti-passback or mantrap controls where feasible. Where a cardholder data environment exists, publicly accessible network jacks are disabled or restricted (PCI DSS 9.2.2) and access to networking hardware and telecommunication lines is restricted (PCI DSS 9.2.3). A physical access log (electronic or manual) is retained for at least 90 days.
4. Visitor Management
All visitors are pre-authorised where possible, identity-verified against government photo ID on arrival, issued a visibly distinct temporary badge, and recorded in a visitor register capturing name, organisation, host, purpose, and time in/out (ISO 27001 A.7.2; PCI DSS 9.3.2–9.3.4). Visitors and other non-employees are escorted at all times within Restricted, Secure and Critical zones and are never left unattended near information-processing equipment or media. Visitor badges are physically distinguishable from personnel badges, are surrendered on departure or expiry, and the register is retained for at least three months. Deliveries and loading/collection areas are isolated from Secure zones so that couriers cannot access sensitive areas (ISO 27001 A.7.2).
5. Physical Security Monitoring (CCTV and Alarms)
Entry and exit points to Secure and Critical zones, and other sensitive areas, are continuously monitored (ISO 27001 A.7.4; PCI DSS 9.2.1). CCTV coverage is deployed at these points; recorded footage is protected from tampering, access to it is restricted to authorised personnel, and it is retained for 90 days (minimum 90 days) unless a longer statutory or contractual retention applies. Intruder-detection alarms cover perimeter doors and Secure zones outside working hours, are tested at least annually, and generate alerts to a monitored point. Monitoring data (CCTV, access logs, alarms) is correlated on suspicion of a physical incident and is itself treated as sensitive personal data under applicable privacy law.
6. Securing Offices, Rooms and Facilities
Offices, rooms and facilities housing sensitive information or systems are sited and configured to minimise exposure (ISO 27001 A.7.3). Directories, internal phone books and signage do not identify the location of information-processing facilities to the public. Doors and windows to Secure areas are locked when unattended; keys and access codes are controlled and inventoried. Facilities holding personal data are configured so that screens, whiteboards and documents are not visible from public areas or through external windows, supporting Acme Technologies Pvt Ltd 's obligations as a data controller/processor under applicable data-protection law.
7. Protecting Against Physical and Environmental Threats — Utilities, Fire, HVAC
Facilities are protected against natural and man-made environmental threats — fire, flood, power failure, extremes of temperature/humidity, and civil disturbance (ISO 27001 A.7.5, A.7.11). Supporting utilities are engineered for resilience: (a) Power — uninterruptible power supply (UPS) sized to sustain graceful shutdown or bridge to backup generation for Secure/Critical zones; (b) Fire — automatic detection and suppression appropriate to the space, with extinguishers inspected at least annually and no combustible storage in server rooms; (c) HVAC — temperature and humidity in server rooms held within manufacturer-recommended ranges (typically 18–27 °C) with monitoring and alerting; and (d) Water — leak detection under raised floors where present. Emergency shut-off, evacuation routes and utility isolation are documented, and utility, fire and environmental systems are inspected and tested on a defined schedule.
8. Working in Secure Areas
Work in Secure and Critical zones follows additional rules (ISO 27001 A.7.6): personnel are aware of the existence of, and activities within, secure areas only on a need-to-know basis; unsupervised working in secure areas is avoided where practical; vacant secure areas are physically locked and periodically checked; and personal photographic, video, audio and recording equipment (including camera-enabled mobile devices) is prohibited in Critical zones unless explicitly authorised. Third-party support and maintenance access to secure areas is granted only when required, is supervised, and is logged.
9. Clear Desk and Clear Screen
A clear-desk and clear-screen discipline applies to all personnel across all locations, including home offices (ISO 27001 A.7.7). Papers, removable media and portable devices containing sensitive information are cleared from desks and locked away when unattended and at the end of the working day. Workstations lock automatically after no more than 10 minutes of inactivity and are locked manually when left. Sensitive information is not left on printers, copiers, scanners or fax machines; secure/pull-printing is used for confidential output. Whiteboards are erased after use, and passwords or access codes are never written down in view.
10. Equipment Siting, Cabling, Maintenance and Off-Premises Assets
Equipment is sited to reduce risks from environmental threats, unauthorised viewing and interference, with sensitive displays angled away from public sightlines (ISO 27001 A.7.8). Power and telecommunications cabling carrying data or supporting services is protected from interception, interference and damage — segregated where required, and access to patch panels and cable rooms restricted (A.7.12). Equipment is maintained per manufacturer intervals by authorised personnel only; maintenance records are kept, and media is removed or sanitised before equipment leaves the premises for repair (A.7.13). Assets taken off-premises (laptops, mobiles, portable media) remain the user's responsibility, must be encrypted, are never left unattended in public or in vehicles, and are covered by the home-/remote-working and acceptable-use controls (A.7.9). Remote and home-office workers apply the same clear-desk, encryption and locking-storage standards as on-premises staff.
11. Storage Media Handling, Classification and Distribution
Removable and physical storage media (USB drives, external disks, backup tapes, and hard-copy media) containing sensitive or cardholder data are inventoried, classified, and stored in locked, access-controlled cabinets or safes (ISO 27001 A.7.10; PCI DSS 9.4.1–9.4.4). Media is checked in/out to authorised personnel only, and its movement — internal transfer or transport off-site — is logged and, for regulated data, sent by secured courier or hand-delivery with tracking so that distribution is authorised and traceable. Media stored off-site (including backups) is held in a facility whose physical security is reviewed at least annually. Use of unauthorised removable media on Acme Technologies Pvt Ltd systems is prohibited, and media is encrypted commensurate with its classification.
12. Secure Disposal and Re-use of Equipment and Media
Equipment and media are securely sanitised before disposal or re-use so that data cannot be recovered (ISO 27001 A.7.14; SOC 2 CC6.5; PCI DSS 9.4.5–9.4.7). Sanitisation follows NIST SP 800-88 Rev. 1: 'Clear' (overwrite) or 'Purge' (cryptographic erase / secure erase) for media being re-used, and 'Destroy' for end-of-life media. Electronic media at end of life is physically destroyed (shredded, disintegrated or degaussed as appropriate); hard-copy materials containing sensitive or cardholder data are cross-cut shredded, incinerated or pulped so they cannot be reconstructed, and pre-destruction material is held in secured, access-controlled containers. A certificate of destruction / sanitisation record is retained as evidence for every batch, whether performed in-house or by an approved disposal vendor bound by contract and, where applicable, a data-processing agreement.
13. Payment Devices and Cardholder Data Environments
Where Acme Technologies Pvt Ltd later handles payment-card data or deploys card-reading devices, the additional PCI DSS Requirement 9 controls apply — a maintained device inventory, periodic tamper inspection of point-of-interaction devices, and personnel training to detect and report tampering — and this policy is extended accordingly before any such device or environment goes live.
14. Roles, Incident Reporting, Compliance and Review
The Policy Owner (Chief Information Security Officer ) is accountable for this policy; facilities and security teams operate the controls, and all personnel are responsible for compliance. Suspected physical or environmental security incidents — tailgating, lost badges or media, tampering, environmental failures — are reported without delay to security@acme.example and handled under the Incident Response Policy. Non-compliance may result in disciplinary action up to termination and, for third parties, contractual consequences. Compliance is verified through access-log reviews, periodic walkthroughs and internal audit, and this policy is reviewed at least annually (next review: 12 months from the effective date) and after any material change to facilities, threats or applicable law.
Approved by
Head of Security / Facilities
______________________
Role / Title
Chief Information Security Officer
______________________