Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

98 controls

03.10.02Monitoring physical accessITSP.10.171Physical protection

Official Requirement

A. Monitor physical access to the facility where the system resides to detect and respond to physical security incidents. B. Review physical access logs [Assignment: organization-defined frequency] and upon occurrence of [Assignment: organization-defined events or potential indications of events].

Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3

In Plain English

Your facility must have monitoring in place to detect unauthorized physical access attempts or incidents. This includes cameras, badge reader logs, and intrusion detection. Physical access logs must be reviewed regularly and whenever a security event occurs.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Physical access monitoring and log review

Implementation steps

  1. Install and maintain surveillance cameras and badge readers at all facility entry and exit points
  2. Configure physical intrusion detection alarms for server rooms, data centers, and other sensitive areas
  3. Collect and store physical access logs from badge readers and alarm systems for the defined retention period
  4. Review physical access logs at the defined frequency and investigate any anomalies or security incidents

Tools / systems

Evidence artifacts

Evidence frequency: Continuous monitoring; weekly or defined-frequency log reviews; per-event incident investigation