Skip to main content

Physical Security Policy

Last updated: January 15, 2026

Physical Security Policy

Document owner: Director of Operations, with CISO as co-owner Version: 3.0 Effective date: January 1, 2026 Last updated: January 15, 2026 Classification: Public — Trust Center Review cadence: Annual review; updates for facility changes Company: Acme Cloud, Inc. Address: 1200 Market Street, Suite 400, San Francisco, CA 94103, USA Primary contacts: trust@acmecloud.com | security@acmecloud.com | privacy@acmecloud.com


Definitions and Key Terms

TermDefinition
Physical SecurityMeasures designed to protect personnel, hardware, software, networks, and data from physical actions and events that could cause serious loss or damage
Access ControlPhysical systems and procedures that restrict entry to facilities, areas, or assets to authorized individuals
Perimeter SecuritySecurity measures protecting the outermost boundaries of a facility or site
Defense in DepthA layered approach to security using multiple security controls to protect assets
Badge AccessElectronic access control using proximity cards, smart cards, or similar credentials
MantrapA small space with two interlocking doors used to prevent unauthorized entry through tailgating
TailgatingUnauthorized entry gained by following an authorized person through a secured entrance
Visitor ManagementProcedures for controlling and monitoring non-employee access to facilities
Video SurveillanceUse of cameras and recording systems to monitor and record activity in facilities
Environmental ControlsSystems that monitor and maintain appropriate environmental conditions (temperature, humidity, etc.)
Intrusion Detection System (IDS)Systems that detect unauthorized entry or breach attempts
Clean Desk PolicyRequirements for securing sensitive information and equipment when not in use
Secure DisposalProper destruction of media and documents containing sensitive information
Data CenterA facility housing computer systems and associated components
Cabling SecurityProtection of network and power cabling from damage, interception, or interference
Emergency ResponseProcedures for responding to physical security incidents and emergencies
Escort RequirementRequirement that visitors be accompanied by authorized personnel in secure areas
Security ZoneAn area with defined security requirements and access restrictions
Asset TaggingAssignment of unique identifiers to physical assets for tracking and inventory
Biometric AccessAccess control using biological characteristics such as fingerprints or facial recognition
Key ControlManagement of physical keys including issuance, tracking, and recovery
Security GuardPersonnel dedicated to protecting facilities and personnel
Alarm SystemElectronic systems that detect and alert to unauthorized access or environmental hazards

Scope and Purpose

This Physical Security Policy establishes Acme Cloud, Inc.'s requirements for protecting physical facilities, assets, personnel, and information systems from unauthorized physical access, damage, theft, and environmental hazards. The policy scope encompasses all physical locations where Acme Cloud conducts business, stores assets, or processes information, including corporate offices, shared workspaces, employee home offices (for applicable controls), and cloud infrastructure hosting facilities. The purpose is to provide a safe and secure physical environment that protects employees, visitors, equipment, and information assets while enabling efficient business operations.

Physical Environment Overview

Location TypeCountDescriptionSecurity Level
Corporate Headquarters1San Francisco office (co-working space)Medium
European Office1Dublin office (co-working space)Medium
Employee Home Offices~320Remote employee workspacesVariable
Cloud Infrastructure3AWS regions (us-east-1, us-west-2, eu-west-1)High (AWS managed)
No Data Centers0No company-operated data centersN/A

Applicability Matrix

Control AreaCorporate OfficeCo-Working SpaceHome OfficeCloud Provider
Facility Access ControlAcme Cloud responsibilityShared responsibilityEmployee responsibilityAWS responsibility
Visitor ManagementAcme Cloud responsibilityCo-work providerEmployee responsibilityAWS responsibility
Video SurveillanceAcme Cloud/ProviderCo-work providerN/AAWS responsibility
Environmental ControlsAcme Cloud/ProviderCo-work providerN/AAWS responsibility
Equipment SecurityAcme Cloud responsibilityAcme Cloud responsibilityEmployee responsibilityAWS responsibility
Media DisposalAcme Cloud responsibilityAcme Cloud responsibilityAcme Cloud guidanceAWS responsibility

Security Zone Classification

Zone Definitions

ZoneDescriptionAccess LevelControlsExamples
Public ZoneAreas accessible to the general public without authenticationOpenBasic surveillance; reception presenceBuilding lobby; common corridors
Reception ZoneAreas where visitors are received and processedControlledReception desk; visitor sign-in; waiting areaOffice reception; meeting room lobbies
Workplace ZoneGeneral work areas for employeesBadge accessBadge readers; visitor escort requiredOpen office areas; break rooms
Restricted ZoneAreas with sensitive equipment or informationEnhanced accessBadge access + PIN or biometric; audit loggingServer rooms; executive offices
High-Security ZoneAreas requiring maximum protectionStrict accessMulti-factor authentication; mantrap; 24/7 monitoringN/A for current facilities

Zone Access Requirements

ZoneAuthenticationAuthorizationMonitoringEscort Policy
PublicNoneNoneSurveillanceNone
ReceptionSign-inReception approvalSurveillance; receptionStaff presence
WorkplaceBadgeEmployee statusSurveillance; access logsRequired for visitors
RestrictedBadge + PIN/biometricManager approval + access listSurveillance; access logs; alertsAlways escorted
High-SecurityMulti-factor + approvalExplicit authorization per access24/7 monitoring; real-time alertsContinuous escort

Office Facility Security

San Francisco Headquarters

Security ControlImplementationProviderVerification
Building AccessKey card access to building; doorman during business hoursBuilding managementAnnual assessment
Office Suite AccessBadge access system; Acme Cloud administeredAcme CloudMonthly access review
Video SurveillanceBuilding common areas; office entry pointsBuilding + Acme CloudWeekly review
ReceptionStaffed during business hours; visitor check-inAcme CloudDaily operation
After-Hours AccessBadge access only; logged and monitoredAcme CloudAccess log review
Alarm SystemIntrusion detection; after-hours armedAcme CloudMonthly testing

Dublin European Office

Security ControlImplementationProviderVerification
Building AccessKey card access; security receptionCo-work providerAnnual assessment
Office Suite AccessBadge access to dedicated spaceCo-work providerMonthly access review
Video SurveillanceCommon areas; entry pointsCo-work providerProvider SLA
Shared FacilitiesShared meeting rooms; break areasCo-work providerSecure asset handling
Environmental ControlsHVAC; fire suppressionCo-work providerProvider compliance
Emergency ProceduresBuilding evacuation plan; assembly pointsCo-work providerAnnual drill

Office Security Metrics

MetricSan FranciscoDublinTarget
Access card auditsQuarterlyQuarterly100% coverage
Terminated employee badge deactivation<4 hours<4 hours<8 hours
Visitor log retention12 months12 months12 months
Security incident response<30 minutes<30 minutes<1 hour
Surveillance footage retention90 days90 days90 days

Access Control

Badge Access System

ComponentDescriptionManagement
Badge IssuancePhoto ID badges issued upon hire; temporary badges for contractorsHR + Office Manager
Badge ProgrammingAccess levels programmed per role and approvalOffice Manager
Badge TrackingCentral database of all active badgesOffice Manager
Lost Badge ReportingImmediate reporting required; badge disabled within 4 hoursEmployee + Office Manager
Badge ReturnRequired upon termination; deactivation within 4 hoursHR + Office Manager
Badge ExpirationContractor badges expire on contract end dateAutomated

Access Level Matrix

Role/GroupPublicReceptionWorkplaceRestrictedHours
Full-Time EmployeeYesYesYesAs approved24/7
Part-Time EmployeeYesYesYesAs approvedBusiness hours
Contractor (onsite)YesYesYesAs approvedContract hours
Visitor (escorted)YesYesEscortedEscorted if approvedBusiness hours
Building VendorYesYesEscortedNoScheduled
Cleaning StaffYesYesYesNoAfter hours
Emergency RespondersAllAllAllAllEmergency only

Access Provisioning Process

StepActivityOwnerTimeline
1Access request submitted via ITSMRequesterDay 0
2Manager approval for standard accessManagerDay 0-1
3CISO approval for restricted accessCISODay 0-2
4Badge programmingOffice ManagerDay 1-2
5Badge issuance with photoOffice ManagerDay 1-3
6Access testing verificationEmployeeDay of issuance

Access Removal Process

Termination TypeBadge DeactivationBadge CollectionSystem Update
Voluntary (planned)Last day of employmentFinal day collectionSame day
Involuntary (immediate)Within 4 hoursImmediate collectionWithin 4 hours
Contractor EndContract end dateContract end dateSame day
Leave of AbsencePer security assessmentRetained by employee or collectedDocumented

Visitor Management

Visitor Types and Requirements

Visitor TypePre-RegistrationID VerificationBadge TypeEscort RequiredAccess Scope
Business VisitorRequired (24h)Government IDVisitor badgeYesReception + approved areas
Interview CandidateRequiredGovernment IDVisitor badgeYesReception + interview rooms
Vendor/ContractorRequiredGovernment IDContractor badgePer areaAs contracted
Delivery PersonnelNot requiredNot requiredN/ALimited to receptionReception only
Emergency ResponderNot requiredUniform/IDN/AAs neededAll areas
Auditor/InspectorRequiredGovernment IDAuditor badgePer areaAs authorized

Visitor Registration Process

StepActivityResponsibilitySystem
1Employee pre-registers visitorEmployee hostVisitor management system
2Visitor receives confirmationAutomatedEmail with instructions
3Visitor arrives; signs inReceptionVisitor log
4ID verificationReceptionVisual verification
5Visitor badge issuedReceptionBadge system
6Host notifiedReception/SystemPage/notification
7Host escorts visitorEmployee hostN/A
8Visitor signs out; badge returnedReceptionVisitor log

Visitor Log Requirements

Data ElementCollectedRetentionAccess
Visitor nameYes12 monthsSecurity + authorized
Company/affiliationYes12 monthsSecurity + authorized
Host employeeYes12 monthsSecurity + authorized
Time in/outYes12 monthsSecurity + authorized
Areas accessedYes12 monthsSecurity + authorized
Government ID typeYes12 monthsSecurity only
SignatureYes12 monthsSecurity only

Video Surveillance

Surveillance Coverage

AreaCoverageRecordingRetentionAccess
Building entrances24/7Continuous90 daysSecurity team
Office entry points24/7Continuous90 daysSecurity team
Reception areaBusiness hoursContinuous90 daysSecurity team
Common areas24/7Continuous90 daysSecurity team
Server/network closets24/7Motion-activated90 daysSecurity team
Emergency exits24/7Motion-activated90 daysSecurity team

Surveillance System Requirements

RequirementSpecificationRationale
Camera ResolutionMinimum 1080pClear identification
Night VisionRequired for exterior/dark areas24-hour coverage
Recording StorageEncrypted; redundantData protection
Retention PeriodMinimum 90 daysInvestigation support
Access ControlRole-based; loggedAccountability
Privacy SignagePosted at entry pointsLegal compliance

Video Footage Access

PurposeAuthorization RequiredApproval AuthorityDocumentation
Security investigationSecurity team requestCISO or Director of OpsIncident ticket
HR investigationHR requestCPO or General CounselHR case file
Law enforcement requestSubpoena/warrantGeneral CounselLegal case file
Insurance claimInsurance requestCFOClaim documentation
Routine reviewScheduled reviewSecurity team leadReview log

Equipment Security

Asset Management

Asset TypeTaggingInventoryTrackingDisposal
LaptopsAsset tag + serialITSM inventoryMDMCertified recycler
Mobile devicesITSM registrationITSM inventoryMDMCertified recycler
MonitorsAsset tagOffice inventoryManualCertified recycler
Network equipmentAsset tag + configNetwork inventoryNMSCertified recycler
Printers/copiersAsset tagOffice inventoryManualCertified recycler
Servers (if any)Asset tagInfrastructure inventoryCMDBCertified recycler

Equipment Security Controls

ControlImplementationVerification
EncryptionFull-disk encryption required on all devicesMDM enforcement
Screen LockAuto-lock after 5 minutes inactivityMDM enforcement
BIOS/Firmware PasswordRequired on all company devicesConfiguration baseline
Cable LocksAvailable for office useOptional but provided
Secure StorageLockable cabinets for sensitive itemsOffice inventory
Theft PreventionGPS tracking on laptopsMDM capability

Equipment Check-Out/In

ProcessRequirementTracking
New hire issuanceDocumented receipt; asset assignmentITSM ticket
Equipment replacementTrade-in documented; new asset assignedITSM ticket
Remote work equipmentShipping tracked; receipt confirmationShipping + ITSM
Termination returnVerified return; asset recoveryExit checklist
Lost/stolen reportingImmediate report; remote wipeSecurity incident

Remote Work Physical Security

Home Office Security Requirements

RequirementDescriptionVerification
Secure WorkspaceDedicated work area; not publicly visibleEmployee attestation
Screen PrivacyScreen not visible to unauthorized personsEmployee attestation
Device StorageSecure storage when not in useEmployee attestation
Document HandlingSensitive documents secured; shredding availableTraining + attestation
Network SecuritySeparate or secured home network; no public WiFi for sensitive workSecurity training
Visitor AwarenessWork not visible to visitorsEmployee responsibility

Home Office Security Checklist

CategoryRequirementEmployee Responsibility
Physical SpaceDedicated work area with door/privacyBest effort
Screen PositioningScreen not visible from windows or common areasRequired
Document StorageLockable storage for sensitive documentsRequired if applicable
Equipment SecurityDevices secured when unattendedRequired
Clean DeskSensitive materials secured end of dayRequired
ShreddingCross-cut shredding for sensitive documentsRequired
ReportingReport theft/loss immediatelyRequired

Remote Work Security Training

TopicContentFrequency
Home Office SetupSecure workspace configurationOnboarding
Device SecurityEncryption, screen lock, physical securityAnnual
Document HandlingClassification, secure disposalAnnual
Incident ReportingLost/stolen device proceduresAnnual
Travel SecurityDevice security while travelingAnnual

Cloud Infrastructure Physical Security (AWS)

AWS Physical Security Controls

Acme Cloud does not operate physical data centers. Customer data is hosted in Amazon Web Services (AWS) facilities. AWS maintains comprehensive physical security controls documented in their SOC 2 Type II reports and ISO 27001 certifications.

Control AreaAWS ImplementationVerification Method
Perimeter SecurityFencing; security personnel; vehicle barriersAWS SOC 2 report
Access ControlBiometric authentication; badge + PINAWS SOC 2 report
Visitor ManagementEscorted access only; pre-approval requiredAWS SOC 2 report
Video Surveillance24/7 monitoring; 90-day retentionAWS SOC 2 report
Environmental ControlsRedundant HVAC; fire suppressionAWS SOC 2 report
Power RedundancyUPS; backup generators; redundant feedsAWS SOC 2 report
Intrusion DetectionElectronic perimeter monitoring; alarm systemsAWS SOC 2 report
Physical DestructionDegaussing and destruction proceduresAWS media sanitization

AWS Compliance Certifications

CertificationScopeVerificationReview Frequency
SOC 2 Type IIAll AWS servicesCertificate + reportAnnual
ISO 27001Global infrastructureCertificateAnnual
ISO 27017Cloud securityCertificateAnnual
ISO 27018PII protectionCertificateAnnual
PCI DSS Level 1Payment processingAOCAnnual
FedRAMPGovernment workloadsAuthorizationAnnual

AWS Region Selection Criteria

CriterionConsiderationImplementation
Physical SecurityAWS security certificationsAll regions certified
Data ResidencyCustomer requirements; regulationsEU data in eu-west-1
Disaster RecoveryGeographic separationMulti-region deployment
AvailabilityRedundant availability zonesMulti-AZ architecture
EnvironmentalRenewable energy percentageRegion preference policy

Environmental Controls

Office Environmental Requirements

ParameterAcceptable RangeMonitoringResponse
Temperature68-76°F (20-24°C)Building HVACBuilding management
Humidity40-60% RHBuilding HVACBuilding management
Fire DetectionSmoke detectors; heat sensorsBuilding fire systemFire department
Fire SuppressionSprinkler systemBuilding fire systemAutomatic activation
Water DetectionUnder-floor sensorsBuilding managementBuilding maintenance
PowerStable supply; surge protectionElectrical systemBuilding electrician

Emergency Procedures

Emergency TypeDetectionResponseRecovery
FireSmoke/heat detectorsEvacuation; fire departmentFire department clearance
MedicalEmployee reportFirst aid; call 911Professional care
IntrusionSecurity system; observationSecurity response; policeSecurity clearance
Power OutageLoss of powerUPS for critical systems; building backupPower restoration
Natural DisasterNews; alertsEvacuation if neededDamage assessment
Severe WeatherWeather alertsShelter in place or evacuationWeather clearance

Emergency Equipment

EquipmentLocationTestingResponsibility
Fire ExtinguishersPer fire code placementMonthly inspectionBuilding management
First Aid KitsReception; break areasQuarterly inventoryOffice Manager
AEDReception areaMonthly checkOffice Manager
Emergency LightingThroughout facilityMonthly testBuilding management
Exit SignsAll exitsMonthly testBuilding management
Emergency ContactsPosted; digitalQuarterly updateOffice Manager

Numbered Policy Statements

  1. Physical Security Requirement: All Acme Cloud, Inc. facilities shall maintain physical security controls appropriate to the sensitivity of assets and information processed at each location.

  2. Access Control Mandate: Physical access to Acme Cloud facilities shall be controlled through badge access systems with access granted on a need-to-have basis and approved by appropriate management.

  3. Visitor Management: All visitors to Acme Cloud facilities must be pre-registered, sign in at reception, wear visitor badges, and be escorted by an employee at all times in secure areas.

  4. Badge Responsibility: Employees are responsible for safeguarding their access badges. Lost or stolen badges must be reported within 4 hours and will be immediately deactivated.

  5. Termination Access Removal: Physical access credentials shall be deactivated within 4 hours of employment termination, with badges collected on the employee's final day.

  6. Video Surveillance Notice: Video surveillance is deployed in common areas and entry points. All persons entering Acme Cloud facilities consent to video recording as posted at entry points.

  7. Equipment Security: All company-issued equipment must be secured when unattended, with full-disk encryption enabled and automatic screen lock configured.

  8. Clean Desk Policy: Employees must secure sensitive documents and portable media when leaving their workstation unattended.

  9. Remote Work Security: Employees working remotely must maintain appropriate physical security for company equipment and information as defined in remote work guidelines.

  10. Secure Disposal: Electronic media and documents containing sensitive information must be disposed of using approved secure disposal methods.

  11. Incident Reporting: Physical security incidents including theft, unauthorized access attempts, and suspicious activity must be reported immediately to the security team.

  12. Emergency Preparedness: All employees must be familiar with emergency procedures including evacuation routes and assembly points.

  13. Cloud Provider Reliance: For cloud-hosted infrastructure, Acme Cloud relies on AWS physical security controls, verified through annual review of SOC 2 reports and certifications.

  14. Annual Assessment: Physical security controls shall be assessed annually, with penetration testing of physical access controls where appropriate.


Framework Appendix

Compliance Mapping

RequirementSOC 2 CriteriaISO 27001 ControlHIPAA ProvisionImplementation
Physical access controlCC6.4A.11.1.1§164.310(a)(1)Badge access system
Facility securityCC6.4A.11.1.2§164.310(a)(2)(ii)Controlled entry
Visitor managementCC6.4A.11.1.6§164.310(a)(2)(ii)Visitor logs; escorts
Equipment securityCC6.4A.11.2.1§164.310(d)(1)Asset management
Environmental controlsA1.1A.11.1.4§164.310(a)(2)(ii)Building systems
Media disposalCC6.5A.11.2.7§164.310(d)(2)(i)Secure disposal

ISO 27001 A.11 Physical Security Mapping

ISO 27001 ControlControl TitleImplementation
A.11.1.1Physical security perimeterBuilding security; office access
A.11.1.2Physical entry controlsBadge access; reception
A.11.1.3Securing offices, rooms, and facilitiesZone-based access
A.11.1.4Protecting against external threatsEnvironmental controls
A.11.1.5Working in secure areasRestricted area procedures
A.11.1.6Delivery and loading areasDelivery procedures
A.11.2.1Equipment siting and protectionEquipment security
A.11.2.3Cabling securityNetwork closet access
A.11.2.7Secure disposalCertified recycling
A.11.2.8Unattended user equipmentClean desk; screen lock
A.11.2.9Clear desk and clear screenClean desk policy

Related Trust Center documents

security overview, access control, business continuity, incident response, data retention, encryption standards


Document revision history

VersionDateAuthorSummary of changes
1.02024-06-01Legal & ComplianceInitial Trust Center publication
2.02025-03-15GRC ProgramSOC 2 Type II alignment refresh; expanded subprocessors
2.52025-09-01Security EngineeringEncryption standards update; ISO 27001 mapping
3.02026-01-15Trust Center ProgramFull procurement-grade expansion; 34-document set

Contact

Acme Cloud, Inc. 1200 Market Street, Suite 400 San Francisco, CA 94103, USA

ChannelEmailUse case
Trust & procurementtrust@acmecloud.comSecurity questionnaires, trust reviews
Securitysecurity@acmecloud.comIncidents, vulnerabilities, control questions
Privacyprivacy@acmecloud.comDSRs, privacy assessments
Legallegal@acmecloud.comContractual, DPA, legal notices

Physical Security Contacts

ContactRoleAvailabilityUse Case
Office ManagerFacilities + badge managementBusiness hoursBadge issues; facility requests
security@acmecloud.comSecurity Team24/7 (critical)Security incidents; investigations
Building SecurityBuilding management24/7Building emergencies
Emergency Services91124/7Life-threatening emergencies

Appendix: Facility Security Checklist

CategoryDailyWeeklyMonthlyAnnually
Access log review
Visitor log review
Video surveillance check
Badge system functionality
Emergency equipment inspection
Fire extinguisher inspection
Access rights review
Physical security assessment
Emergency drill
AWS SOC 2 report review

Document Version: 3.0 Last Updated: January 15, 2026

Last updated: January 15, 2026
EthicPages logoEthicPages