ISO 27001 Physical Entry Log Template

by Poorva Dange

Introduction

Information is the lifeblood of any organization. Beyond protecting digital information, companies must also ensure that the physical spaces where this information resides are secure. ISO 27001 , the globally recognized standard for an Information Security Management System (ISMS), contains a set of physical security controls. One of the fundamental aspects of a successful physical security program under ISO 27001 is the physical entry log. A physical entry log provides an important control by verifying who has entered a company's secure or controlled area. In this article, we will explore the physical entry log, its ISO 27001 requirements, and look into why and how companies can benefit from them.

ISO 27001 Physical Entry Log Template

A.11.1.2: What does ISO27001 say about physical security?

ISO 27001 Annex A is the list of mandatory and optional controls for an ISMS.

Annex A.11 Physical and environmental security is all about the physical safeguards, procedures, and measures that organizations must implement to protect information.

A.11.1.2 Physical entry controls describes the necessary steps that should be taken to secure offices, the controlled areas, and information processing facilities against unauthorized entry.

A.11.1.1 Physical security perimeter establishes that secure areas should be protected by an appropriate perimeter.

A physical entry log is also connected to A.11.1.3 Securing offices, rooms and facilities and A.11.1.4 The protection of information processing facilities against external threats like sabotage or damage.

Finally, according to A.11.1.6 Delivery and loading areas, organizations must secure these areas against unauthorized entry as well.

As mentioned above, Annex A.11.1.2 requires that secure areas be protected by physical entry controls.

Organizations that are required to prepare a physical entry log are obliged to demonstrate to the ISO 27001 auditor how they ensure that only authorized personnel can enter a particular secure area.

Without a physical entry log, companies would be hard-pressed to show the auditor who was in the building at all times, which compromises their information security management practices.

ISO 27001 Physical Entry Log: Why do you need it?

A physical entry log not only helps companies comply with Annex A.11.1.2, but also helps organizations achieve the following:

Showcasing Compliance and Facilitating Audits

As mentioned above, a physical entry log controls and records who comes and goes from the organization's building(s).

The presence of a well-maintained log is, first and foremost, a demonstration of compliance with ISO 27001 Annex A.11.1.2.

Not only that, but it also provides the auditor with a physical control audit trail, demonstrating that the company's information security management practices are adequate and effective.

Incident Forensics

A good physical log can be used during an incident investigation.

Suppose, for instance, that a network attack, intrusion, or data breach occurs.

Investigators will be interested in finding out who was in the building or who had access to the affected area(s).

A physical entry log goes a long way to finding answers, as it demonstrates exactly who was at the scene at the time when the incident occurred

Deterrence and Accountability

Requiring visitors and staff members to sign in and out also acts as a deterrent and a motivator for following physical security policies.

Furthermore, creating a system where people have to sign in and out motivates staff to ensure that visitors do not have free access to the building, without having to ask for permission before entering.

Visitor Management

Creating a standardized physical entry log template and having it followed by visitors is a great way to impress first-time guests, notify the organization's host(s) of the visitor's imminent arrival, and even help with emergency evacuations by keeping track of who is present in the building.

Information Fields in ISO 27001 Physical Entry Log Template

When creating an entry log, organizations will have to decide which information fields to include.

Although companies can choose what they want to include in their entry log, most physical entry log templates will have a similar structure, namely:

Information fields:

  • Date and time in/out: This information shows the exact or approximate date and time of arrival and departure of the visitor/personnel.

  • Name of the visitor/personnel: Ideally, the person's full name should appear here.

  • Company: The name of the company (for visitors) or department (for staff members) the visitor belongs to.

  • Reason for visit: A brief message about the reason for the visit and/or the area the visitor is to be escorted to.

  • Host/contact person: This one applies to visitors only and indicates the name of the host/contact person at the company who is responsible for the visitor.

  • Identification: This data field is for visitors only and indicates what kind of ID (driver's license, passport, etc.) is presented, along with the ID's partial number (for privacy reasons).

  • Signature: Signing the physical entry log is a way for the visitor/personnel to confirm that they have entered/exited the building and that the contact person has been informed of their entry.

Note: Some of the aforementioned fields may be relevant for visitors only (e.g., Reason for visit and Host/contact person) or for staff members only (e.g., Company).

Furthermore, organizations with heightened physical (and/or information) security needs may want to include the following fields in their physical entry log:

  • Access to specific area (if the company covers several different areas).

  • Escort detail.

  • Assets (e.g., laptops, tools) declaration (for visitors or contractors).

  • Badge number issued/returned (in organizations that use temporary badges).

  • Security briefing acknowledgment.

ISO 27001 Implementation Toolkit

Designing and Deploying a Physical Entry Log

Having discussed the basic information fields that all entry log templates should have, let us turn our attention to designing and deploying a physical entry log.

Although some of the fields can be automated (e.g., date/time), most would require manual input by a person.

Organizations can choose between using paper and/or digital logbooks for their staff and visitors.

Pros and cons:

Paper logbook

Pros:

  • Easy to design and set up.

Cons:

  • Hard to read.

  • Privacy issues (all visitors can see other visitors' personal information)

Digital logbook (tablet computer or dedicated system)

Pros:

  • More privacy (each visitor can only see their personal information).

  • More accurate (reduced errors).

  • Easier analysis/reporting.

Cons:

  • A slightly steeper learning curve.

  • Increased costs.

As mentioned above, one of the advantages of a digital log book is increased privacy and convenience, at the cost of increased complexity and expense.

Note that the physical entry log can and should be customized according to a company's needs.

For example, for corporations whose employees are mostly staff and are not regularly visited by outsiders, the reason for the visit and the host may be more important.

By contrast, if the company is a data center that is frequently visited by third parties (e.g., contractors), then those fields can be deemed less important, while other fields (e.g., information about the equipment brought in by the visitor) gain increased importance.

Companies can also consider how the physical entry log fits into the greater information security context.

Some questions to ask:

  • How will this information be stored and processed?

  • Will the physical log be connected to the organization's access control system? Or a separate visitor management system?

  • What are the data retention policies of the organization, and how is personal data of visitors protected?

The ISO 27001 standard requires that organizations have documented data retention policies in place. Companies will also have to delete any personal data of visitors in accordance with data protection laws, such as the General Data Protection Regulation ((GDPR).

Once the fields have been decided upon, companies will also have to train the appropriate personnel on how to complete the physical entry log correctly and securely.

It is important that they understand why the information is being collected, how it should be completed and stored securely, and what to do if inappropriate information is provided.

ISO 27001 Implementation Toolkit

Maintaining and Auditing the Physical Entry Log

Once the physical entry log is deployed, companies will have to ensure that it is actively used and that the entries are completed correctly.

Organizations can and should perform regular audits of their log to check for appropriate use.

Companies can also consider implementing mechanisms to keep track of changes to the entries.

Since the physical log will hold personal information of visitors, it would be important to secure it (if it is paper-based) or ensure the integrity of the digital data.

Finally, organizations should consider the physical entry log a living document that requires periodic reviews.

Physical entry logs are important components of any company's information security management system.

They provide the auditor with assurance that an organization's physical security measures are in place and operating effectively.

Furthermore, the physical log can help organizations identify security weaknesses and become more aware of the potential information security incidents affecting their business.

A well-designed physical entry log also enables organizations to comply with ISO 27001 requirements and, therefore, maintain and demonstrate their commitment to information governance.

This control is particularly useful in providing the auditor with an audit trail showing that only authorized personnel can enter the organization's secure area. With that being said, let's discuss how to build a physical entry log.

A Tool for More Than Just Compliance

Having discussed why a physical entry log is useful and necessary for organizations, we can summarize its benefits as follows:

  • Provides confidence and assurance that the organization complies with Annex A.11.1.2 (Physical entry controls) of ISO 27001.

  • Helps companies identify and address potential physical security and information security incidents.

  • Offers increased information security by giving the company valuable situational awareness about who is in the building at any given time.

  • Assists organizations to keep a useful log of staff and visitor movements that can be used to improve physical security at the workplace.

The ISO 27001 framework requires that companies take appropriate measures to ensure physical security. Organizations can use the physical entry log to not only accomplish this goal but also to protect their information assets from unauthorized access by outsiders. As can be seen, implementing a proper physical entry log is essential to a company's information security management system (ISMS). It is a great way to demonstrate to the ISO 27001 auditor that the company takes its physical and information security seriously.


Implement ISO Faster with a Complete Documentation System

You're currently viewing a single template. Most ISO implementations require a complete set of policies, procedures, and records. Choose what fits your needs.
BEST FOR single ISO STANDARD

ISO Toolkit for Your Standard

Audit ReadyToolkits

Pick your toolkit from 8 ready-to-use ISO toolkits available: ISO 27001, 9001, 14001, 45001, 22301, 20000, and 42001 (AI Governance).

✔ Complete ISO documentation framework
✔ Policies, procedures, templates, and records
✔ Risk management & internal audit templates
✔ Management Review and Nonconformance
✔ ISO Standard Mapped Implementation Plan

💡 All toolkits come with instant download, one-time payment, and unlimited email & chat support.

View ISO Toolkits Collection →
BEST FOR MULTIPLE ISO STANDARDS

ISO PowerPack Bundle

All 8 ISO Toolkits in One Power Pack

Designed for teams, organizations, and consultants managing multiple ISO implementations across projects and clients.

✔ Unlimited internal and client use
✔ Deliver ISO services from day one
✔ Impress clients and auditors
✔ Skip months of document creation
✔ Grow your consulting business

💡All the benefits of our ISO toolkits combined in one powerful bundle — save over $1,000 compared to buying the toolkits individually.

View ISO PowerPack →