Physical Security & Access Control Assessment
Document ID: ASSESS-PHYS-004
Facility Type: Financial Services Branch Office
Audit Target: Physical Data Migration & Secure Hardware Decommissioning Project
Framework Alignment: SOC 2 (Trust Services Criteria CC6.4), HIPAA Physical Safeguards (§ 164.310)
1. Zoning & Perimeter Access Control Matrix
The facility is architecturally divided into three security tiers to restrict unauthorized access to Sensitive Personal Information (SPI) and financial records.
| Security Zone | Rooms Included | Access Control Mechanism | Authorized Personnel |
| Zone 1: Public / Low Security | Main Reception Parlor, Conference Room | Perimeter door kept locked; doorbell intake system used for screening. | Clients (Escorted), Contractors, All Staff |
| Zone 2: Operational / Medium Security | Mailroom, Workroom, Lunchroom | Unlocked during business hours; keyed physical locks applied at night. | Internal Staff; Contractors (Project-specific) |
| Zone 3: Restricted / High Security | File Room, Regional Manager Office, Salesmen Private Offices | Keyed physical locks (24/7); regional office lacks administrative master keys. | Assigned Keyholders Only; Contractors (Escorted/Supervised) |
2. Contractor Access & Escort Protocols
- Credentialing Constraints: Third-party contractors are strictly barred from possessing physical keys, master fobs, or perimeter security alarm codes.
- Active Supervision Mandate: Contractors cannot independently access Zone 3 areas. The Office Manager must manually unlock the Central File Room for active work cycles. Individual Salesmen must be physically present to unlock their private offices to allow contractor document harvesting.
3. Physical Security Gap Analysis & Vulnerability Log
This section identifies specific operational vulnerabilities discovered during the office walkthrough and maps them to industry risks and corrective mitigations.
Finding 1: Key Management Obscuration Vulnerability
- Vulnerability Description: The physical key to the building’s main mailroom is stored inside an unlocked desk drawer at the Office Manager’s station. While hidden from plain sight (“security through obscurity”), it lacks a physical lock control.
- Associated Risk: Unauthorized internal staff or unescorted contractors could locate the key, granting them undetected access to incoming sensitive client checks, contracts, and financial statements.
- Corrective Mitigation: Relocate the mailroom key exclusively to the Office Manager’s primary biometric or keyed lock drawer.
Finding 2: Unsecured Document Ingestion (The “Under-Door” Protocol)
- Vulnerability Description: Per request of the high-volume sales agent, incoming mail containing unredacted financial documentation is pushed underneath his office door when he is traveling, accumulating in an exposed pile on the office floor.
- Associated Risk: Physical documents resting on the floor can be easily viewed or compromised through the door gap by cleaning staff, contractors, or unauthorized personnel. This violates clean-desk principles and data containment policies.
- Corrective Mitigation: Install a secure, locked drop-box on the exterior of the agent’s private office door, or hold mail at the central Office Manager station until the agent signs for it upon return.
Finding 3: Building Security Service Oversight Gaps
- Vulnerability Description: The business park security guards conduct random vehicular perimeter sweeps only 4 times per day, and the main building lobby lacks an official sign-in ledger for visitors or vendors.
- Associated Risk: Tailgating or unauthorized building entry could occur between patrol intervals, making retrospective incident response difficult due to a lack of a physical visitor logging trail.
- Corrective Mitigation: Implement a local, manual visitor sign-in/sign-out logbook at the front reception desk for all contractors participating in the document migration project.
Leave a Reply