Physical Access Control
Physical access control refers to the systems, technologies, and policies that manage who can enter or exit a building, room, or secure area. It typically works by authenticating a person or vehicle and then authorizing or denying their entry to a protected space. The goal is to restrict access so that only permitted individuals can reach designated areas of a facility.
Physical access control encompasses the electronic systems, technologies, and policies that regulate the ability of people or vehicles to enter or move within protected areas by performing authentication and authorization at access control points. A physical access control system (PACS) is the electronic implementation of these controls, designed to authorize or prevent entry to a building or specific portions of a facility. In compliance contexts, physical access controls are commonly evaluated as part of the controls covered under a SOC 2 examination's Common Criteria and may correspond to physical security reference controls within ISO/IEC 27001 Annex A, though the specific control mapping depends on scope and the framework applied.
Why it matters
Physical access control is a foundational layer of security because many logical and technical safeguards can be undermined if an unauthorized person gains physical entry to a facility, server room, or workspace. Restricting who can reach sensitive equipment and information reduces the risk of theft, tampering, and unauthorized data access, and it supports the broader principle that access should be limited to those with a legitimate need.
In compliance contexts, physical access controls are commonly evaluated as part of the controls covered under a SOC 2 examination's Common Criteria, and they may correspond to physical security reference controls within ISO/IEC 27001 Annex A. However, the specific control mapping depends on scope and the framework applied, and satisfying the physical security expectations of one framework does not automatically satisfy the other. A SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS, so physical access controls are assessed within those boundaries rather than as a universal guarantee.
Because these controls typically govern who can enter or exit buildings, rooms, and secure areas, weaknesses in them can have downstream effects on the effectiveness of other controls. For this reason, auditors and certification bodies often examine physical access as part of a layered security posture rather than treating it in isolation.
Who it's relevant to
Inside PACS
Common questions
Answers to the questions practitioners most commonly ask about PACS.