unified
UC-PHYS-01 — Restrict physical access to facilities and secure areas
Define physical security perimeters and secure areas, and authorize, issue, and periodically review physical access credentials so only authorized personnel can enter facilities, offices, and sensitive locations such as data centers and backup media storage. Enforce entry controls at every access point, escort and log visitors, and apply defined rules for working in secure areas. Maintain physical access audit logs for entries and exits at controlled access points, and secure, inventory, and rotate physical access devices such as keys, combinations, and badges when compromised or when personnel change. Revoke or adjust physical access promptly upon termination or role change.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Physical & Environmental Security
- type
- preventive
- category
- physical
Details
- unified_id
- UC-PHYS-01
- title
- Restrict physical access to facilities and secure areas
- statement
- Define physical security perimeters and secure areas, and authorize, issue, and periodically review physical access credentials so only authorized personnel can enter facilities, offices, and sensitive locations such as data centers and backup media storage. Enforce entry controls at every access point, escort and log visitors, and apply defined rules for working in secure areas. Maintain physical access audit logs for entries and exits at controlled access points, and secure, inventory, and rotate physical access devices such as keys, combinations, and badges when compromised or when personnel change. Revoke or adjust physical access promptly upon termination or role change.
- domain
- Physical & Environmental Security
- control_type
- preventive
- control_category
- physical
- members
- framework
- nist-800-53
- control_id
- PE-2
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PE-3
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.7.1
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.7.2
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.7.3
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.7.6
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC6.4
- coverage
- full
- relationship
- superset_of
- framework
- hipaa
- control_id
- HIPAA-164.310
- coverage
- partial
- delta
- also covers workstation use/security and device and media controls
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-PHYS-01 — Restrict physical access to facilities and secure areas maps_to CC6.4 — The entity restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives.
- framework
- soc2
- control_id
- CC6.4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-PHYS-01 — Restrict physical access to facilities and secure areas maps_to A.7.6 — Working in secure areas
- framework
- iso-27001
- control_id
- A.7.6
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-PHYS-01 — Restrict physical access to facilities and secure areas mitigates Inadequate physical protection and access controls
- strength
- primary
- rationale
- Perimeters, entry controls, credential issuance/review, and visitor escort are the direct defense against unauthorized physical access, including tailgating.
- UC-PHYS-01 — Restrict physical access to facilities and secure areas maps_to A.7.1 — Physical security perimeters
- framework
- iso-27001
- control_id
- A.7.1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-PHYS-01 — Restrict physical access to facilities and secure areas mitigates Physical and cyber-physical attacks on facilities and infrastructure
- strength
- related
- rationale
- Restricting entry to facilities and secure areas keeps intruders from reaching interior systems/infrastructure to commit arson or sabotage.
- UC-PHYS-01 — Restrict physical access to facilities and secure areas maps_to PE-3 — Physical Access Control
- framework
- nist-800-53
- control_id
- PE-3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-PHYS-01 — Restrict physical access to facilities and secure areas
- UC-PHYS-01 — Restrict physical access to facilities and secure areas maps_to A.7.3 — Securing offices, rooms and facilities
- framework
- iso-27001
- control_id
- A.7.3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 SoA Review & Controls Assessment oversees UC-PHYS-01 — Restrict physical access to facilities and secure areas
- UC-PHYS-01 — Restrict physical access to facilities and secure areas maps_to A.7.2 — Physical entry
- framework
- iso-27001
- control_id
- A.7.2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-PHYS-01 — Restrict physical access to facilities and secure areas maps_to HIPAA-164.310 — Physical safeguards (facility access controls, workstation use/security, device and media controls)
- framework
- hipaa
- control_id
- HIPAA-164.310
- coverage
- partial
- delta
- also covers workstation use/security and device and media controls
- relationship
- intersects_with
- source_version
- 45 CFR Parts 160/164 (Security, Privacy, Breach Notification)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Facility Access Administration & Monitoring operates UC-PHYS-01 — Restrict physical access to facilities and secure areas
- UC-PHYS-01 — Restrict physical access to facilities and secure areas maps_to PE-2 — Physical Access Authorizations
- framework
- nist-800-53
- control_id
- PE-2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Control Assessment & POA&M Remediation tests UC-PHYS-01 — Restrict physical access to facilities and secure areas
- UC-PHYS-01 — Restrict physical access to facilities and secure areas mitigates Theft of equipment, media or unattended devices
- strength
- primary
- rationale
- Controlling and promptly revoking physical access prevents unauthorized persons from reaching and removing equipment or media.
- SOC 2 Trust Services Readiness tests UC-PHYS-01 — Restrict physical access to facilities and secure areas