A.7.2 Physical
Physical entry
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (12)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-2mostlyaligns with — The ISO control's requirement to manage, periodically review, and revoke physical access authorizations directly supports the NIST objective of authorizing physical access based on position and need.
- PE-3mostlycovers — Both controls require physical access control mechanisms, visitor management, and monitoring of entry points to prevent unauthorized entry into facilities containing sensitive assets.
- PE-6mostlyaligns with — Both emphasize ongoing monitoring of physical access through logs, audit trails, and surveillance of entry/exit points to detect unauthorized activity.
- PE-7mostlyaligns with — The detailed visitor authentication, escorting, and purpose-limited access procedures in the ISO guidance map to NIST's requirement for visitor control and access restrictions.
- PE-8mostlyaligns with — Maintaining and protecting physical access logs and visitor records fulfills the same objective as NIST's visitor access records control.
- PE-16partialaligns with — Controls over delivery and loading areas, including inspection of incoming materials and segregation of shipments, address the same physical access risks NIST targets for delivery and removal of assets.
Aligned NIST CSF 2.0 outcomes (5)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-06fullcovers — The ISO control establishes, monitors, and enforces physical access to facilities and sensitive areas through authentication, logging, visitor controls, and key management, directly satisfying the CSF outcome for managing and monitoring physical access commensurate with risk.
- PR.IR-01mostlyaligns with — By isolating delivery areas, securing emergency exits, and segregating physical zones, the control prevents unauthorized logical or physical entry into environments where information assets reside, supporting the CSF outcome of protecting networks and environments from unauthorized access.
- PR.PS-04mostlyaligns with — The requirement to maintain protected physical and electronic access logs and audit trails for all entries provides the log records that the CSF outcome expects to be generated and made available for continuous monitoring.
- ID.AM-05partialaligns with — Physical access restrictions and monitoring are applied with greater rigor to areas holding higher-value or sensitive assets, reflecting the CSF outcome that assets should be prioritized and protected according to classification and criticality.
Related weaknesses / CWE (12)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1263fullprevents — Specifies physical entry controls that prevent unauthorized actors from reaching protected information or assets.
- CWE-284mostlyprevents — Physical entry controls enforce explicit authorization and authentication at every access point, directly stopping unauthorized actors from reaching information-processing assets.
- CWE-1191partialmitigates — Physical entry controls reduce the chance of an attacker reaching the chip but do not enforce on-chip debug authorization.
- CWE-1278partialmitigates — Entry controls limit who can reach facilities where reverse-engineering could occur.
- CWE-1300partialmitigates — Entry controls reduce opportunities for physical observation of emissions.
- CWE-200partialprevents — Restricting and monitoring physical access reduces the chance that sensitive information stored or processed on-site will be exposed to unauthorized individuals.
- CWE-552partialmitigates — Segregating delivery/loading zones and controlling external doors prevents external parties from reaching directories or resources that should remain inaccessible.
- CWE-285nonenone — Requiring authorization, periodic review, and revocation of physical access rights prevents incorrect or excessive permissions from being granted or retained.
- CWE-287nonenone — Visitor identity verification and logging of entry/exit times establish reliable authentication before physical access is granted.
- CWE-306nonenone — Mandatory use of access cards, biometrics, or two-factor authentication ensures that critical physical areas cannot be entered without proper authentication.
Mitigated MITRE ATT&CK techniques (4)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1200mostlyprevents — Physical access controls and visitor authentication reduce the chance an adversary can physically introduce hardware such as USB devices or rogue peripherals into the facility.
- T1052partialmitigates — Requiring authorization and inspection of personnel and deliveries makes it harder for an attacker to physically remove data on removable media.
- T1052.001partialprevents — Physical screening and access restrictions at entry/exit points directly impede the covert exfiltration of data over USB.
- T1091partialprevents — Controlled entry points and inspection of incoming material limit the ability to deliver malware via removable media that is later used for lateral movement.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.