Why Physical Security is a Compliance Control
ISO/IEC 27001:2022 Annex A.7 dedicates an entire control domain to physical and environmental security — covering secure areas, physical entry controls, protecting equipment, and clear desk/screen policies. CERT-In requires that critical IT infrastructure be housed in physically secured environments with access logging. The RBI Cybersecurity Framework mandates physical access controls for all data centres and server rooms handling financial data. Physical security is not separate from information security — it IS information security at its most basic level.
Physical Security Audit Checklist
| Control Area | What Auditors Check | Common Gap |
|---|---|---|
| Access Control | Badge/biometric entry, visitor log, escorting policy | No visitor log, tailgating |
| CCTV Coverage | All entry points, server aisles, 90-day retention | Dead zones, <30-day retention |
| Environmental | Temperature/humidity alerts, fire suppression, UPS | No environmental monitoring |
| Secure Disposal | Hard drive destruction certificates, DoD wipe records | Old drives in storage, no records |
| Clear Desk | Policy documented, screen lock enforced, paper shredding | Policy exists, not enforced |
The Server Room: Minimum Physical Security Standards
A server room or data centre handling regulated data must meet these minimum physical standards: dedicated locked room with access restricted to authorised personnel only, electronic access log with timestamps and identity records retained for minimum 12 months, CCTV covering all access points with footage retained for minimum 90 days, temperature monitoring with automated alerts if ambient exceeds 27°C, UPS with minimum 30-minute runtime and generator backup for critical environments, and a no-food/drink policy enforced with signage.
Secure Equipment Disposal
DPDP Act 2023 and ISO 27001:2022 A.7.14 require that storage media containing sensitive data be sanitised before disposal or reuse. This means documented evidence of either: physical destruction (witnessed hard drive shredding with certificate), or cryptographic erasure (using tools like Blancco with audit trail), or NIST 800-88 compliant wiping for less sensitive media. Keeping decommissioned servers with intact hard drives in a storage room is a direct compliance finding.
Physical Security Included in Every IGaaS Assessment
InfraVeritas 360 conducts on-site physical security assessments as part of every IGaaS engagement — checking access controls, CCTV, environmental monitoring, and disposal practices against ISO 27001 and CERT-In requirements.
Book a Physical Security Assessment →