Konfirmity
Layer 7 of 7 — Physical Security

// physical security

The layer everyone forgets until the auditor asks

L7 checks that a physical security policy exists and that the evidence behind it is being collected. It is the layer that is quietly missing on the morning of an audit.

// what it watches

What this layer watches

Physical Security reports “Set Up” until the right integration is connected, because until then there is nothing honest to say about it. A platform that showed you green here would be describing an environment it cannot see.

  • Whether an active physical security policy exists at all
  • Biometric access systems and the enrolment records behind them
  • CCTV monitoring of secured areas
  • Entry and exit registers with timestamps and identification

// what turns it red

What turns it red

Each row is a live measurement on your own environment, not a checklist item. The third column is the part a compliance-first tool cannot offer.

What is measuredWhat it saysWhere clicking it takes you
Whether an active physical security policy exists at allSet Up PolicyThe documents library
Open evidence tasks for entry and exit registers with timestamps and identificationN Tasks OpenThe controls surface for your framework, filtered to L7 evidence
Open evidence tasks for biometric access systems and enrolment recordsN Tasks OpenThe same filtered control view
Open evidence tasks for CCTV monitoring of secured areasN Tasks OpenThe same filtered control view
Open evidence tasks for photographic evidence of secured areasN Tasks OpenThe same filtered control view
Records of issued access cards, tracked as evidence against the control they satisfyN Tasks OpenThe task record and its attached artefact

This table is not the whole check

Physical security requirements differ sharply by framework, by premises and by whether you run your own facilities. What this layer asks of you is set when your controls are scoped.

See how deep we go

// getting to green

What it takes to go green

  1. Publish a physical security policy. Until one is active, the layer reports nothing else.
  2. Evidence tasks are raised against the controls that need them, with the specific artefact named.
  3. Someone on site collects the artefact and attaches it to the task.
  4. The layer clears when the policy is active and no physical security evidence task is open.

// the evidence

The evidence this produces

None of this is collected for the auditor's benefit. It is the by-product of work that had to happen anyway, which is why it holds up when someone checks.

  • Physical and environmental security evidence for ISO 27001, SOC 2 and PCI DSS — see the ISO 27001 guide
  • Dated access registers and enrolment records rather than a description of them
  • Photographic evidence of secured areas, attached to the control it satisfies

// questions this answers

Physical security coverage, answered directly

Why does L7 report nothing until a policy exists?

Because the policy is the thing the evidence supports. Until an active physical security policy is published, Konfirmity shows Set Up Policy and reports nothing else about the layer.

What evidence does physical security actually require?

Access registers for entry and exit with timestamps and identification, biometric system records, records of issued access cards or biometric enrolments, and photographic evidence of secured areas. Each is raised as a task against the control that needs it.

Which frameworks care about this layer?

ISO 27001, SOC 2 and PCI DSS all carry physical and environmental security requirements. It is the layer most often discovered missing on the morning of an audit.

// keep reading

Where this goes deeper

Want to see this one live?

Book 30 minutes and we will walk through “The layer everyone forgets until the auditor asks” in the actual platform, using your environment as the example.

Book a demo