A.7.2 Physical
Physical entry
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (18)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-2mostlyaligns with — The ISO control's requirement to manage, periodically review, and revoke physical access authorizations directly supports the NIST objective of authorizing physical access based on position and need.
- PE-2mostlycovers — A.7.2's requirement to ensure only authorized physical access is achieved in large part by developing/maintaining an access list, issuing credentials, periodic review, and timely removal — exactly the steps in PE-2 — but a residual of PE-2 (formal approval step and explicit parameter-driven review frequency) sits outside what A.7.2 directly mandates.
- PE-3mostlycovers — Both controls require physical access control mechanisms, visitor management, and monitoring of entry points to prevent unauthorized entry into facilities containing sensitive assets.
- PE-6mostlyaligns with — Both emphasize ongoing monitoring of physical access through logs, audit trails, and surveillance of entry/exit points to detect unauthorized activity.
- PE-7mostlyaligns with — The detailed visitor authentication, escorting, and purpose-limited access procedures in the ISO guidance map to NIST's requirement for visitor control and access restrictions.
- PE-8mostlyaligns with — Maintaining and protecting physical access logs and visitor records fulfills the same objective as NIST's visitor access records control.
- PE-16partialaligns with — Controls over delivery and loading areas, including inspection of incoming materials and segregation of shipments, address the same physical access risks NIST targets for delivery and removal of assets.
- PE-16covers — A.7.2's requirement to ensure authorized physical access to information and assets directly accounts for the 'authorize and control items entering and exiting the facility' slice of PE-16, but does not address maintaining records of system components (the second distinct requirement in PE-16).
- PE-6covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PE-8covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (8)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-06fullcovers — The ISO control establishes, monitors, and enforces physical access to facilities and sensitive areas through authentication, logging, visitor controls, and key management, directly satisfying the CSF outcome for managing and monitoring physical access commensurate with risk.
- PR.IR-01mostlyaligns with — By isolating delivery areas, securing emergency exits, and segregating physical zones, the control prevents unauthorized logical or physical entry into environments where information assets reside, supporting the CSF outcome of protecting networks and environments from unauthorized access.
- PR.PS-04mostlyaligns with — The requirement to maintain protected physical and electronic access logs and audit trails for all entries provides the log records that the CSF outcome expects to be generated and made available for continuous monitoring.
- ID.AM-05partialaligns with — Physical access restrictions and monitoring are applied with greater rigor to areas holding higher-value or sensitive assets, reflecting the CSF outcome that assets should be prioritized and protected according to classification and criticality.
- ID.AM-05implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-04implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related weaknesses / CWE (9)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1191mitigates — Physical entry controls reduce the chance of an attacker reaching the chip but do not enforce on-chip debug authorization.
- CWE-1263prevents — Specifies physical entry controls that prevent unauthorized actors from reaching protected information or assets.
- CWE-1278mitigates — Entry controls limit who can reach facilities where reverse-engineering could occur.
- CWE-1300mitigates — Entry controls reduce opportunities for physical observation of emissions.
- CWE-200prevents — Restricting and monitoring physical access reduces the chance that sensitive information stored or processed on-site will be exposed to unauthorized individuals.
- CWE-284prevents — Physical entry controls enforce explicit authorization and authentication at every access point, directly stopping unauthorized actors from reaching information-processing assets.
- CWE-552mitigates — Segregating delivery/loading zones and controlling external doors prevents external parties from reaching directories or resources that should remain inaccessible.
Mitigated MITRE ATT&CK techniques (123)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1052detects — A.7.2 requires monitoring of physical access logs, visitor supervision, inspection of belongings/deliveries, and reporting of anomalies such as unescorted visitors or tampering, which can surface some instances of physical-medium exfiltration (e.g., via logged USB insertion or suspicious visitor behavior) but does not broadly instrument or detect the data-copy act itself across all entry points or air-gapped scenarios.
- T1052prevents — A.7.2's physical entry controls (badges, visitor supervision, delivery segregation, inspections, restricted areas) stop many insider/visitor uses of removable media for exfiltration but leave open authorized users on air-gapped systems and uninspected personal devices, so only a slice of the technique is prevented.
- T1052.001prevents — Physical screening and access restrictions at entry/exit points directly impede the covert exfiltration of data over USB.
- T1052.001detects — A.7.2 requires monitoring of physical access, logs/audit trails, visitor supervision, inspection of belongings and deliveries, and reporting of anomalies, which can surface suspicious USB device use or introduction in controlled areas but does not broadly instrument or guarantee detection of the exfiltration technique itself (especially on air-gapped systems or once data is already on the device).
- T1078prevents — A.7.2's physical-entry controls (badges, visitor supervision, access revocation, monitored reception, double doors) stop abuse of physical credentials or unescorted physical presence but leave the dominant logical/remote credential-abuse vectors (VPNs, RDP, cloud accounts, inactive accounts, domain pivots) untouched.
- T1091prevents — Controlled entry points and inspection of incoming material limit the ability to deliver malware via removable media that is later used for lateral movement.
- T1091detects — A.7.2 requires monitoring of physical access logs, inspecting incoming deliveries (including for tampering), and supervising visitors/personnel at entry points, which can surface suspicious removable media or USB devices being brought in; this is a genuine but minority slice of the technique (initial delivery of tainted media), not the execution or lateral movement on air-gapped systems.
- T1195detects — A.7.2 requires inspection of incoming deliveries for tampering/hazardous materials and registration of deliveries, which can surface evidence of physical supply-chain interdiction or counterfeit hardware before it enters the facility, but this is limited to physical shipments at one late stage and does not address software, development-tool, update-channel, or pre-shipment manipulation named in T1195.
- T1195prevents — A.7.2's delivery/loading-area controls (inspecting for tampering/hazards, segregating shipments, securing doors, registering deliveries) directly stop shipment-interdiction and some counterfeit/tampered hardware from reaching internal facilities, but leave all upstream supply-chain stages (development tools, source repos, update mechanisms, open-source dependencies, factory-infected images) untouched.
- T1199detects — A.7.2 requires monitoring of physical access logs, visitor supervision, authentication of visitors, and reporting of anomalies like unescorted visitors or tampering, which can surface physical third-party supply-chain compromise (e.g. physical security contractors) but does not address logical/network/third-party account abuse that dominates T1199.
- T1199prevents — A.7.2's guidelines on restricting, authorizing, monitoring, and supervising supplier/third-party physical access (including to shared buildings and infrastructure like HVAC/physical security contractors) directly stop many physical-entry vectors that adversaries would otherwise use to breach or leverage the trusted relationship, but the control is silent on logical/network/cloud delegated access, accounts, and remote IT/MS provider relationships that dominate the technique.
- T1200prevents — Physical access controls and visitor authentication reduce the chance an adversary can physically introduce hardware such as USB devices or rogue peripherals into the facility.
- T1200detects — A.7.2 requires monitoring of physical access logs, visitor supervision, inspection of deliveries/belongings, and reporting of anomalies such as unescorted visitors or tampering, which can surface some hardware additions (e.g. via entry logs, inspections, or visible badges); however, it does not instrument or observe the post-introduction abuse (DMA, keystroke injection, network tapping) once the device is inside and operating.
- T1219.003prevents — A.7.2's physical-entry controls (restricting/monitoring access to facilities, inspecting belongings, supervising visitors, securing delivery areas, managing physical keys) can stop an adversary from physically reaching and installing remote-access hardware such as a KVM device, but do not address post-compromise software use, insider installation, or remote exploitation of already-present legitimate hardware.
- T1485recovers — A.7.2's physical-entry controls (reception, visitor escort, delivery inspection, access revocation, and segregation of loading areas) limit an intruder's ability to reach and destroy data-bearing systems or media, enabling faster recovery of availability via intact backups or spares; this is a genuine but minority slice of the technique's surface (remote/cloud/wormed destruction is untouched).
- T1669prevents — A.7.2's physical-entry controls (restricted access, authentication at doors, visitor supervision, secured loading areas, visible badges, and monitoring) stop an adversary from physically approaching or entering premises to discover/connect to internal Wi-Fi, but do not address remote bridging via already-compromised dual-homed third-party systems or purely logical credential abuse against secured networks.
Prevented OWASP Web Top 10 (2025) risks (2)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A01mitigates — A.7.2 enforces physical barriers, authentication, monitoring and segregation that limit blast radius or realization paths for some physical-slice access-control failures (e.g., unauthorized facility entry that could enable tampering or theft), but has no effect on the dominant logical/web-layer members of A01:2025 such as IDOR, CSRF, path traversal in URLs, or missing function-level checks.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.