SIAS-PHY-01 Physical access control for applicant-operated facilities
- Mandatory
- Yes
- Severity
- High
- Applies
- Conditional — the applicant operates offices, server rooms or data centers housing in-scope systems, network equipment or media
- SecurityInspect Verified profiles
- None
Control objective
Only authorized, identifiable people can enter the areas that house in-scope systems, network equipment or media, visitors are recorded and escorted, and entry can be reconstructed afterwards.
Testable requirement
- (a)The applicant shall define the physical security perimeter of each area that houses in-scope systems, network equipment or media (for example server rooms, network closets and media storage) and record it in a written facility security plan with a floor plan.
- (b)The applicant shall control entry to those areas with a mechanism that identifies the individual (for example badges, key cards or biometrics), or with keys whose custody is recorded in a key log by name.
- (c)The applicant shall grant access to those areas only to named individuals with a documented business need, approved by the area owner, and shall revoke it by the end of the individual's last working day or on a change of role. The applicant shall review the access list at least every 6 months.
- (d)The applicant shall register every visitor to those areas (name, organization, host, purpose and times in and out), escort visitors at all times and keep visitor records for at least 90 days.
- (e)The applicant shall keep entry records (electronic access logs or, where those are not available, video) for at least 90 days.
- (f)The applicant shall record repairs and modifications to physical security components such as locks, doors and readers.
Applicability and scope
Conditional — the applicant operates offices, server rooms or data centers housing in-scope systems, network equipment or media. Marking it not applicable needs a written rationale approved by the quality reviewer. Offices where staff only use laptops to reach cloud-hosted systems do not make this control applicable; those devices are covered by SIAS-PHY-02. SecurityInspect Verified profiles: not included.
Pass criteria
- 1.Each secure area has a defined perimeter and an entry mechanism that identifies the individual, or a named key log (M1, M3).
- 2.No departed or unauthorized person holds active access, and access for each sampled termination was revoked by the end of the last working day (A1, A2, M2).
- 3.The access list was reviewed in the last 6 months (A3, M4).
- 4.Sampled visitor records are complete, visitor records cover at least 90 days, and escort was observed or confirmed (A3, M4, I2).
- 5.Entry records cover at least 90 days (A3).
- 6.The inspection found no propped doors, disabled locks or other bypass (M3).
- 7.The facility security plan exists, and repairs and modifications to physical security components are recorded (M1, M5).
Severity
High. Standard escalation triggers apply; none is specific to this control.
Informative framework mappings
- HIPAA Security Rule
- §164.310(a)(1), §164.310(a)(2)(ii), §164.310(a)(2)(iii), §164.310(a)(2)(iv)
- PCI DSS v4.0.1
- 9.2, 9.3
- Trust Services Criteria
- CC6.4
- ISO/IEC 27001:2022
- A.7.1, A.7.2, A.7.3, A.7.4
- Theme (SecurityInspect wording)
- attributable, reviewed entry to secure areas
SIAS-PHY-02 Workstation and portable device physical protection
- Mandatory
- No
- Severity
- Medium
- Applies
- All scopes
- SecurityInspect Verified profiles
- None
Control objective
Devices used to reach in-scope systems or data lock themselves when left alone, are handled sensibly outside the office, and can be locked or wiped remotely when lost.
Testable requirement
- (a)The applicant shall enforce, through central device management, automatic screen lock after no more than 15 minutes of inactivity on workstations and laptops and no more than 5 minutes on mobile devices.
- (b)The applicant's workstation-use rules shall cover clear desks for printed Restricted material, screen privacy in public places and not leaving devices unattended in vehicles or public places.
- (c)Every laptop and mobile device that can reach sensitive data shall be enrolled for remote lock and wipe.
- (d)The applicant shall require workforce members to report a lost or stolen device within 24 hours, and shall then lock or wipe it, revoke its sessions and credentials as needed, and assess whether an incident occurred.
- (e)The applicant shall block writing sensitive data to removable storage on managed devices, or allow it only to approved encrypted devices.
- Encryption at rest on devices is scored under SIAS-CRY-02, and endpoint protection under SIAS-NET-03. This control covers physical handling, remote lock and wipe, and loss response.
Applicability and scope
All scopes. It cannot be marked not applicable. It covers workstations, laptops, mobile devices and removable media used to reach or administer in-scope systems or data, including in home offices. SecurityInspect Verified profiles: not included.
Pass criteria
- 1.Screen lock is enforced at no more than 15 minutes on workstations and laptops and 5 minutes on mobile devices, at least 95% of managed devices conform, and each device that does not has an open ticket (A1, M2).
- 2.Every laptop and mobile device that can reach sensitive data is enrolled for remote lock and wipe, or access from it is technically limited as confirmed under M4 (A1, A2, M4).
- 3.For every loss report in the look-back, a lock or wipe was started within 24 hours of the report (A3, M3).
- 4.Removable storage is blocked or limited to approved encrypted devices on managed devices (A1, M2).
- 5.The walkthrough or remote check found no unattended unlocked session and no printed Restricted material left out, or each case found is recorded as a finding (M5).
- 6.Interviewed workforce members described a loss-reporting route that matches the rules (I2).
Severity
Medium. Standard escalation triggers apply; none is specific to this control.
Informative framework mappings
- HIPAA Security Rule
- §164.310(b), §164.310(c)
- PCI DSS v4.0.1
- No direct mapping
- Trust Services Criteria
- CC6.4
- ISO/IEC 27001:2022
- A.7.7, A.7.8, A.7.9
- Theme (SecurityInspect wording)
- locked, recoverable, carefully handled devices
SIAS-PHY-03 Physical media and equipment disposal
- Mandatory
- Yes
- Severity
- Medium
- Applies
- Conditional — physical media or equipment store in-scope data
- SecurityInspect Verified profiles
- None
Control objective
No in-scope data leaves the applicant's control on a discarded, re-used, returned or repaired device or on paper.
Testable requirement
- (a)The applicant shall maintain a disposal and re-use procedure that requires media and equipment holding in-scope data to be sanitized or destroyed before disposal, re-use outside the scope, return to a lessor or vendor, or repair by an outside party. The method shall be chosen by classification from a recognized sanitization standard (for example NIST SP 800-88 Rev. 2) and shall cover laptops, drives, servers, network devices holding configurations, printers and copiers with storage, backup media and paper records.
- (b)The applicant shall hold media and equipment awaiting disposal in a locked location, listed in an inventory.
- (c)The applicant shall record every disposal: asset identifier or serial number, data classification, method, date, the person responsible and how the result was verified. Where a third party destroys the items, the applicant shall obtain a certificate of destruction that lists serial numbers.
- (d)The applicant shall verify sanitization for each batch, by its own check of at least one item or by relying on the destruction provider's verification report.
- (e)Failed drives shall be kept, or sanitized before return, when replaced under warranty.
- (f)The applicant shall keep disposal records for at least 3 years.
Applicability and scope
Conditional — physical media or equipment store in-scope data. Marking it not applicable needs a written rationale approved by the quality reviewer. Sanitization of media inside a cloud or hosting provider's facilities is assessed under SIAS-PHY-05, not here. SecurityInspect Verified profiles: not included.
Pass criteria
- 1.The procedure sets methods by classification and media type, based on a recognized sanitization standard (M1).
- 2.Every asset disposed of in the look-back has a matching disposal record or certificate with its serial number, and no asset remains unmatched at decision (A1, M2).
- 3.Items awaiting disposal are held in a locked location with an inventory (M3).
- 4.Every recorded method matches the procedure for its classification (A3).
- 5.Every read check performed found no recoverable data (M4).
- 6.Disposal records cover at least 3 years, or the whole period since the procedure began if shorter (A2).
Severity
Medium. Standard escalation triggers apply; none is specific to this control.
Informative framework mappings
- HIPAA Security Rule
- §164.310(d)(1), §164.310(d)(2)(i), §164.310(d)(2)(ii)
- PCI DSS v4.0.1
- 9.4
- Trust Services Criteria
- CC6.5
- ISO/IEC 27001:2022
- A.7.10, A.7.14
- Theme (SecurityInspect wording)
- sanitized, recorded disposal and re-use
SIAS-PHY-04 Environmental and utility protection
- Mandatory
- No
- Severity
- Low
- Applies
- Conditional — the applicant operates server rooms or data centers housing in-scope systems
- SecurityInspect Verified profiles
- None
Control objective
In-scope equipment in applicant-run server rooms is protected against power loss, fire, heat, water and cabling damage, and the protections are maintained.
Testable requirement
- (a)The applicant shall protect in-scope equipment with an uninterruptible power supply sized for a controlled shutdown or transfer to a generator, and shall test it (and any generator) at least every 12 months or on the manufacturer's schedule if shorter.
- (b)The applicant shall provide fire detection and fire suppression suitable for electronic equipment, inspected at least every 12 months.
- (c)The applicant shall monitor temperature and humidity and send alerts to a monitored contact.
- (d)The applicant shall install leak detection where there is a water risk (for example under a raised floor or near plumbing).
- (e)The applicant shall protect power and network cabling in the room against damage and interception (for example with conduits and locked patch panels).
- (f)The applicant shall maintain equipment as the manufacturer recommends, record the maintenance and escort outside maintenance personnel.
Applicability and scope
Conditional — the applicant operates server rooms or data centers housing in-scope systems. Marking it not applicable needs a written rationale approved by the quality reviewer. SecurityInspect Verified profiles: not included.
Pass criteria
- 1.An uninterruptible power supply protects in-scope equipment and was tested in the last 12 months (A2, M1).
- 2.Fire detection and suppression are present and were inspected in the last 12 months (M1, M2).
- 3.Temperature and humidity are monitored with alerts, and each out-of-range alert in the look-back received a response (A1, M3).
- 4.Leak detection is installed wherever the room has a raised floor or nearby plumbing (M1).
- 5.Cabling in the room is protected, and maintenance records are current (M1, M2).
Severity
Low. Standard escalation triggers apply; none is specific to this control.
Informative framework mappings
- HIPAA Security Rule
- No direct mapping
- PCI DSS v4.0.1
- No direct mapping
- Trust Services Criteria
- A1.2
- ISO/IEC 27001:2022
- A.7.5, A.7.11, A.7.12, A.7.13
- Theme (SecurityInspect wording)
- power, fire, climate and cabling protection
SIAS-PHY-05 Hosting provider physical assurance
- Mandatory
- Yes
- Severity
- Medium
- Applies
- Conditional — in-scope systems are hosted in third-party facilities (reviewing a provider's independent assurance reports is evidence, not a SIAS claim about the provider)
- SecurityInspect Verified profiles
- None
Control objective
Where in-scope systems run in someone else's facility, the applicant has current, independent evidence that the facility is physically protected, has read it, and has taken on the responsibilities the provider leaves to its customers.
Testable requirement
- (a)The applicant shall identify every third-party facility provider that hosts in-scope systems (IaaS, PaaS, colocation or managed hosting), with the services and regions or facilities used.
- (b)At least every 12 months, the applicant shall obtain current independent assurance covering the physical and environmental safeguards of the facilities or services it uses. Examples are an independent third-party assurance report (such as a SOC 2 Type 2 report) or an ISO/IEC 27001 certificate issued by an accredited certification body, where the scope includes those facilities or services. Where no independent assurance exists, a documented on-site inspection under a contractual inspection right is required instead.
- (c)The applicant shall review each report or certificate and record: that its scope covers the services and regions used; that its period is current (a report period ending more than 12 months before the review needs a provider bridge letter or statement covering the gap); each exception it reports and the applicant's assessment of it; and the customer responsibilities it lists, each assigned to an owner in the applicant's control set.
- (d)The applicant shall record the reviewer, the date, the conclusions and any follow-up, and shall escalate adverse results to the security owner.
- (e)For colocation of applicant-owned equipment, the applicant shall keep the list of its people authorized at the provider current, review it at least every 6 months, and be able to obtain the provider's entry records for its space.
- (f)The contract with each provider shall include physical security obligations and notification of physical security incidents that affect the applicant's equipment or data.
Applicability and scope
Conditional — in-scope systems are hosted in third-party facilities (reviewing a provider's independent assurance reports is evidence, not a SIAS claim about the provider). Marking it not applicable needs a written rationale approved by the quality reviewer. SaaS suppliers used as in-scope components are assessed under the SIAS-TPR controls, and a condition is recorded once, against the most specific control. SecurityInspect Verified profiles: not included.
Pass criteria
- 1.Every provider hosting in-scope systems is identified, with the services and regions or facilities used (A1).
- 2.For each provider, independent assurance covering physical and environmental safeguards for the services used is current (a period ending within 12 months of the review, or a bridge letter), or a documented inspection under requirement (b) exists (A2, M1).
- 3.Each review is recorded with conclusions, and each reported exception has been assessed (M1, M2).
- 4.Customer responsibilities are identified and assigned, and the sampled ones are implemented (M2).
- 5.For colocation, the authorized-people list was reviewed in the last 6 months and includes no departed person (A3).
- 6.Each provider contract includes physical security obligations and incident notification (M4).
Severity
Medium. Standard escalation triggers apply; none is specific to this control.
Informative framework mappings
- HIPAA Security Rule
- §164.310(a)(1)
- PCI DSS v4.0.1
- 12.8
- Trust Services Criteria
- CC6.4, CC9.2
- ISO/IEC 27001:2022
- A.5.19, A.5.22
- Theme (SecurityInspect wording)
- evidence-based review of hosting facilities