The Control Auditors Check First
An unlocked server closet undoes a lot of good encryption. Physical safeguards are an explicit requirement under the HIPAA Security Rule and NIST 800-53, and they're among the easiest findings for an auditor to document. We assess the physical layer and the identity layer together, because in practice they fail together.
PHYSICAL SAFEGUARDS
Facility, Device, and Media Controls
Facility Access Controls
Badge systems, visitor logs, and entry procedures reviewed against who actually needs access to which spaces.
Server Room & Data Center Review
Locks, surveillance, environmental controls, and rack-level access for the spaces holding your most sensitive systems.
Workstation Security
Screen positioning, automatic lock policies, and clean-desk practices in areas where sensitive data is visible.
Device & Media Disposal
Documented chain of custody for hardware retirement, drive sanitization, and secure media destruction.
IDENTITY & ACCESS MANAGEMENT
Least Privilege, Actually Enforced
Most organizations grant access well and revoke it poorly. We focus on the full lifecycle, because stale accounts are how a minor incident becomes a major one.
- Role-Based Access Review: We map who has access to what today, and flag every permission that no longer matches the person's role.
- Joiner / Mover / Leaver Process: Documented provisioning and — critically — de-provisioning, so access ends the day employment or a role does.
- Privileged Account Controls: Separate admin credentials, MFA enforcement, and monitoring on the accounts that can do the most damage.
- Audit Logging & Periodic Recertification: Access logs that are actually reviewed, on a documented cadence your auditor can verify.
STANDARDS ALIGNMENT
Mapped to the Requirements You're Measured Against
HIPAA Physical Safeguards
Facility access, workstation use and security, and device/media controls are named standards under the Security Rule — we assess against each one directly.
NIST 800-53 (AC & PE Families)
Our review follows the Access Control and Physical & Environmental Protection control families, giving you evidence that maps cleanly to federal expectations.
SOC 2 Common Criteria
Logical and physical access controls sit in the mandatory Security criteria of every SOC 2 report — this work feeds directly into that examination.