Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

98 controls

03.10.07Physical access controlITSP.10.171Physical protection

Official Requirement

A. Enforce physical access authorizations at entry and exit points to the facility where the system resides by: 1. verifying individual physical access authorizations before granting access to the facility 2. controlling ingress and egress with physical access control systems, devices or guards. B. Maintain physical access audit logs for entry or exit points. C. Escort visitors and control visitor activity. D. Secure keys, combinations, and other physical access devices. E. Control physical access to output devices to prevent unauthorized individuals from obtaining access to specified information.

Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3

In Plain English

Your facility must have physical access controls at every entry and exit point -- badge readers, guards, or other mechanisms that verify authorization before granting entry. Keep audit logs of who enters and exits. Visitors must be escorted, their activity monitored, and visit records maintained. Keys, combinations, and codes must be secured. Printers and other output devices must be in controlled areas to prevent unauthorized access to printed materials.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Physical access control enforcement

Implementation steps

  1. Install and maintain badge readers or other access control devices at all entry and exit points; verify authorization before granting physical access
  2. Configure access control systems to log all entry and exit events; retain logs for the defined period
  3. Implement a visitor escort policy: require visitor sign-in, issue temporary badges, assign escorts, log activities, and collect badges at departure
  4. Secure keys and combinations in a key management safe; place printers and other output devices in physically restricted areas

Tools / systems

Evidence artifacts

Evidence frequency: Continuous access logging; per-event visitor management; quarterly key inventory