Skip to main content
Category: Access and Identity Management

Physical Access Control

Also known as: PACS, Physical Access Control System, PACS
Simply put

Physical access control refers to the systems, technologies, and policies that manage who can enter or exit a building, room, or secure area. It typically works by authenticating a person or vehicle and then authorizing or denying their entry to a protected space. The goal is to restrict access so that only permitted individuals can reach designated areas of a facility.

Formal definition

Physical access control encompasses the electronic systems, technologies, and policies that regulate the ability of people or vehicles to enter or move within protected areas by performing authentication and authorization at access control points. A physical access control system (PACS) is the electronic implementation of these controls, designed to authorize or prevent entry to a building or specific portions of a facility. In compliance contexts, physical access controls are commonly evaluated as part of the controls covered under a SOC 2 examination's Common Criteria and may correspond to physical security reference controls within ISO/IEC 27001 Annex A, though the specific control mapping depends on scope and the framework applied.

Why it matters

Physical access control is a foundational layer of security because many logical and technical safeguards can be undermined if an unauthorized person gains physical entry to a facility, server room, or workspace. Restricting who can reach sensitive equipment and information reduces the risk of theft, tampering, and unauthorized data access, and it supports the broader principle that access should be limited to those with a legitimate need.

In compliance contexts, physical access controls are commonly evaluated as part of the controls covered under a SOC 2 examination's Common Criteria, and they may correspond to physical security reference controls within ISO/IEC 27001 Annex A. However, the specific control mapping depends on scope and the framework applied, and satisfying the physical security expectations of one framework does not automatically satisfy the other. A SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS, so physical access controls are assessed within those boundaries rather than as a universal guarantee.

Because these controls typically govern who can enter or exit buildings, rooms, and secure areas, weaknesses in them can have downstream effects on the effectiveness of other controls. For this reason, auditors and certification bodies often examine physical access as part of a layered security posture rather than treating it in isolation.

Who it's relevant to

Compliance Managers
Compliance managers responsible for SOC 2 or ISO 27001 scope need to understand how physical access controls map to their applicable criteria. In SOC 2 these are typically evaluated under the Common Criteria, while in ISO 27001 they may correspond to physical security reference controls in Annex A selected through the Statement of Applicability. The specific mapping depends on scope and framework, and one framework's coverage does not automatically satisfy the other.
Auditors and Certification Bodies
CPA firms performing a SOC 2 examination and certification bodies assessing an ISMS often review physical access controls as part of a facility's overall security posture. In a SOC 2 Type I the focus is on the suitability of design at a point in time, whereas in a Type II both design and operating effectiveness are assessed over the defined review period. Findings are limited to the controls and scope actually examined.
Security Engineers
Security engineers implementing and maintaining a PACS handle the authentication and authorization mechanisms at access control points, along with the integration of those systems into broader security operations. Their work directly affects whether the control functions as designed and can be evidenced during an audit or certification assessment.
GRC Professionals
Governance, risk, and compliance professionals use physical access control as an input to risk assessment and control selection. In an ISO 27001 context, physical security controls are informed by risk assessment and documented in the Statement of Applicability, while in SOC 2 they contribute to the evidence supporting the Common Criteria. GRC teams help ensure boundaries between frameworks and scope are clearly documented.

Inside PACS

Perimeter and Entry Controls
Physical barriers and access points such as locked doors, gates, turnstiles, and reception areas that restrict entry to facilities housing information systems and sensitive assets.
Authentication Mechanisms
Methods used to verify the identity of individuals seeking physical entry, which may include badge or key card systems, biometric readers, PIN pads, or a combination depending on scope and risk assessment.
Access Authorization and Provisioning
Processes for granting, modifying, and revoking physical access rights based on role and need, typically supported by approval workflows and periodic access reviews.
Monitoring and Surveillance
Controls such as video surveillance, visitor logs, and entry/exit audit trails that record physical access events for later review and investigation.
Visitor and Third-Party Management
Procedures for registering, escorting, and restricting visitors, contractors, and vendors within secured areas.
Relationship to Framework Criteria
Within SOC 2, physical access is addressed under the Security category (the Common Criteria); within ISO/IEC 27001, physical security is addressed through relevant Annex A reference controls selected via the Statement of Applicability, with control groupings and numbering depending on the edition (for example, the 2022 revision restructured Annex A into 93 controls across four themes, versus 114 in the 2013 version).

Common questions

Answers to the questions practitioners most commonly ask about PACS.

Does a SOC 2 report certify that our physical access controls are compliant?
No. SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, resulting in a report rather than a certificate. The report attests only to the physical access controls and, in a Type II engagement, their operating effectiveness over the defined review period. It does not issue a certification and does not guarantee freedom from breaches. ISO/IEC 27001, by contrast, produces a certification issued by an accredited certification body, but that covers only the defined scope of the ISMS.
Are physical access controls one of the Trust Services Criteria categories, like Availability or Confidentiality?
No. Physical access is addressed within the Security category (the Common Criteria), which is the only required Trust Services Criteria category; Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on scope. Physical access controls are also referenced within ISO 27001 through Annex A reference controls selected via the Statement of Applicability, but the Trust Services Criteria and Annex A controls should not be conflated, they are distinct structures within distinct frameworks.
How are physical access controls evaluated differently in a SOC 2 Type I versus a Type II engagement?
In a Type I engagement, the assessor evaluates the suitability of the design of physical access controls at a point in time. In a Type II engagement, the assessor evaluates both the design and the operating effectiveness of those controls over a defined review period, the length of which varies and is set by scoping decisions rather than a fixed duration. In practice, a Type II typically involves reviewing evidence such as access logs or badge records across the period rather than a single point-in-time observation.
How do physical access controls fit into an ISO 27001 Statement of Applicability?
Under ISO 27001, the certifiable requirements are in clauses 4 through 10, while Annex A lists reference controls that are selected via a Statement of Applicability and informed by risk assessment. Physical access controls would typically be considered during that risk-based selection, with the organization documenting in the Statement of Applicability whether each relevant Annex A control is applicable and how it is implemented. Because Annex A was restructured in the 2022 revision, the specific control references depend on which edition your ISMS is aligned to, so the version should be specified when citing them.
What kinds of evidence do assessors typically expect for physical access controls?
Expectations vary by auditor, certification body, and scope, but assessors commonly look for evidence that demonstrates both design and, for a SOC 2 Type II, operating effectiveness over the review period. This can include documented procedures, records of access provisioning and de-provisioning, and logs or records showing the controls functioned as described. The exact evidence expected depends on the engagement, so it is best confirmed with the CPA firm or certification body during scoping rather than assumed.
If our physical access controls satisfy SOC 2, do they automatically satisfy ISO 27001?
Not automatically. Mapping between SOC 2 and ISO 27001 is possible but partial, and satisfying one framework does not automatically satisfy the other. The two frameworks have different structures, scopes, and evaluation mechanisms, SOC 2 is a CPA attestation against the Trust Services Criteria, while ISO 27001 is a certification against management system requirements with risk-based control selection. Physical access controls may address similar concerns in both, but each framework should be evaluated against its own requirements and scope.

Common misconceptions

Implementing physical access controls guarantees that a facility cannot be breached.
No control set guarantees freedom from breaches. Physical access controls reduce risk within their defined scope; a SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS.
The physical access controls required by SOC 2 and ISO 27001 are the same and satisfying one automatically satisfies the other.
The frameworks address physical security differently and mapping between them is partial. SOC 2 evaluates physical access under the Trust Services Criteria (Common Criteria), while ISO 27001 uses Annex A reference controls selected via the Statement of Applicability. Satisfying one framework does not automatically satisfy the other, and the Trust Services Criteria are not the same as Annex A controls.
A specific physical control, such as biometric entry, is universally mandatory for compliance.
In most engagements, the appropriate controls depend on the auditor or certification body, the defined scope, the applicable criteria, and the results of a risk assessment. Neither framework mandates a single specific physical control unless the standard itself requires it; the selected measures typically vary by organization and scope.

Best practices

Base physical access control selection on a documented risk assessment and scope definition, since the appropriate mechanisms typically vary by facility, criteria, and engagement.
Maintain formal provisioning, modification, and revocation processes for physical access rights, and perform periodic access reviews to confirm that access aligns with current roles and need.
Retain entry/exit audit trails, visitor logs, and surveillance records sufficient to demonstrate operating effectiveness over the review period for a SOC 2 Type II examination or to support ISO 27001 evidence requirements.
For ISO 27001, ensure physical security controls selected are reflected in the Statement of Applicability and justified against the risk assessment, and specify the Annex A edition when documenting control references.
Implement escort and registration procedures for visitors, contractors, and vendors accessing secured areas, and clearly document the boundaries of what physical scope is and is not covered.
Coordinate physical access evidence with the licensed CPA firm performing the SOC 2 examination or the accredited certification body performing the ISO 27001 assessment, recognizing that each attests or certifies only to the controls and scope covered.