Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC6.4Physical access restrictionsSOC 2Logical and Physical Access Controls

Official Requirement

The entity restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

If you run on-prem infrastructure, you need to show that the physical location is locked down. Who has a key or badge? Is there a log of entries? What happens when someone's employment ends, is their physical access revoked along with their logical access? For cloud-only companies, you delegate this to your cloud provider and demonstrate that via their SOC 2 or ISO 27001 report.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Physical access controls and entry logging for data center / server room

Implementation steps

  1. Implement badge or key card access for the server room, physical key access with a sign-in log is acceptable for smaller environments
  2. Log all entries: who entered, date, time, purpose, keep the log for the audit observation period
  3. Restrict server room access to staff who operationally need it; do not grant blanket access to all IT staff
  4. Revoke physical access cards simultaneously with logical access when staff depart; document this in offboarding tickets

Tools / systems

Evidence artifacts

Evidence frequency: Access log maintained continuously; access list reviewed quarterly; offboarding evidence collected per event