Physical Security

Controlling who gets through the door — and who gets to the data once they're inside.

The Control Auditors Check First

An unlocked server closet undoes a lot of good encryption. Physical safeguards are an explicit requirement under the HIPAA Security Rule and NIST 800-53, and they're among the easiest findings for an auditor to document. We assess the physical layer and the identity layer together, because in practice they fail together.

Facility, Device, and Media Controls

Facility Access Controls

Badge systems, visitor logs, and entry procedures reviewed against who actually needs access to which spaces.

Server Room & Data Center Review

Locks, surveillance, environmental controls, and rack-level access for the spaces holding your most sensitive systems.

Workstation Security

Screen positioning, automatic lock policies, and clean-desk practices in areas where sensitive data is visible.

Device & Media Disposal

Documented chain of custody for hardware retirement, drive sanitization, and secure media destruction.

Least Privilege, Actually Enforced

Most organizations grant access well and revoke it poorly. We focus on the full lifecycle, because stale accounts are how a minor incident becomes a major one.

  • Role-Based Access Review: We map who has access to what today, and flag every permission that no longer matches the person's role.
  • Joiner / Mover / Leaver Process: Documented provisioning and — critically — de-provisioning, so access ends the day employment or a role does.
  • Privileged Account Controls: Separate admin credentials, MFA enforcement, and monitoring on the accounts that can do the most damage.
  • Audit Logging & Periodic Recertification: Access logs that are actually reviewed, on a documented cadence your auditor can verify.

Mapped to the Requirements You're Measured Against

HIPAA Physical Safeguards

Facility access, workstation use and security, and device/media controls are named standards under the Security Rule — we assess against each one directly.

NIST 800-53 (AC & PE Families)

Our review follows the Access Control and Physical & Environmental Protection control families, giving you evidence that maps cleanly to federal expectations.

SOC 2 Common Criteria

Logical and physical access controls sit in the mandatory Security criteria of every SOC 2 report — this work feeds directly into that examination.

Request an Access Review