Under active development Content is continuously updated and improved

1500.01500.0

>Control Description

The Supplier shall, unless prohibited by applicable law, restrict and monitor all physical access to facilities where Data is stored or processed to its authorised Personnel by implementing industry standard physical access controls. Examples of such controls include but are not limited to: i) Swipe card technology ii) Monitored CCTV iii) Remotely monitored alarm systems iv) On-premise security guards v) Photographic access credentials vi) Visitor escort vii) Physical access logs viii) Authorised access lists. The Supplier shall review physical access logs regularly or in the event of a physical or cybersecurity incident.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.