// physical security
The layer everyone forgets until the auditor asks
L7 checks that a physical security policy exists and that the evidence behind it is being collected. It is the layer that is quietly missing on the morning of an audit.
// what it watches
What this layer watches
Physical Security reports “Set Up” until the right integration is connected, because until then there is nothing honest to say about it. A platform that showed you green here would be describing an environment it cannot see.
- Whether an active physical security policy exists at all
- Biometric access systems and the enrolment records behind them
- CCTV monitoring of secured areas
- Entry and exit registers with timestamps and identification
// what turns it red
What turns it red
Each row is a live measurement on your own environment, not a checklist item. The third column is the part a compliance-first tool cannot offer.
| What is measured | What it says | Where clicking it takes you |
|---|---|---|
| Whether an active physical security policy exists at all | Set Up Policy | The documents library |
| Open evidence tasks for entry and exit registers with timestamps and identification | N Tasks Open | The controls surface for your framework, filtered to L7 evidence |
| Open evidence tasks for biometric access systems and enrolment records | N Tasks Open | The same filtered control view |
| Open evidence tasks for CCTV monitoring of secured areas | N Tasks Open | The same filtered control view |
| Open evidence tasks for photographic evidence of secured areas | N Tasks Open | The same filtered control view |
| Records of issued access cards, tracked as evidence against the control they satisfy | N Tasks Open | The task record and its attached artefact |
This table is not the whole check
Physical security requirements differ sharply by framework, by premises and by whether you run your own facilities. What this layer asks of you is set when your controls are scoped.
// getting to green
What it takes to go green
- Publish a physical security policy. Until one is active, the layer reports nothing else.
- Evidence tasks are raised against the controls that need them, with the specific artefact named.
- Someone on site collects the artefact and attaches it to the task.
- The layer clears when the policy is active and no physical security evidence task is open.
// the evidence
The evidence this produces
None of this is collected for the auditor's benefit. It is the by-product of work that had to happen anyway, which is why it holds up when someone checks.
- Physical and environmental security evidence for ISO 27001, SOC 2 and PCI DSS — see the ISO 27001 guide
- Dated access registers and enrolment records rather than a description of them
- Photographic evidence of secured areas, attached to the control it satisfies
// questions this answers
Physical security coverage, answered directly
Why does L7 report nothing until a policy exists?
Because the policy is the thing the evidence supports. Until an active physical security policy is published, Konfirmity shows Set Up Policy and reports nothing else about the layer.
What evidence does physical security actually require?
Access registers for entry and exit with timestamps and identification, biometric system records, records of issued access cards or biometric enrolments, and photographic evidence of secured areas. Each is raised as a task against the control that needs it.
Which frameworks care about this layer?
ISO 27001, SOC 2 and PCI DSS all carry physical and environmental security requirements. It is the layer most often discovered missing on the morning of an audit.
// keep reading
Where this goes deeper
Want to see this one live?
Book 30 minutes and we will walk through “The layer everyone forgets until the auditor asks” in the actual platform, using your environment as the example.