N.3.01 Physical access security
Control Overview
This control mandates that the organization defines, designs, and implements appropriate physical security perimeters and entry barriers to protect its sites, buildings, offices, and critical spaces. The objective is to prevent unauthorized individuals from gaining physical access to assets, infrastructure, or paper records, which could lead to data theft, tampering, or operational disruption. These physical safeguards must be designed based on a formal risk assessment and structured into tiered security zones.
Applicability Status
- Applicable for anDREa: NO
Justification & Strategic Approach
anDREa operates as a fully remote organization with no physical corporate offices, server rooms, or data centers under its direct physical control. All company-wide collaboration occurs in virtual environments, and all production workloads run natively inside public cloud infrastructure (Microsoft Azure).
Consequently, traditional physical security controls targeting corporate perimeters, entry gates, and secure rooms are Not Applicable. Physical security of the underlying hardware infrastructure is managed entirely by the cloud service provider (Microsoft), whose data centers maintain rigorous, independently audited physical protections (e.g., ISO/IEC 27001, SOC 2).
To address the risks associated with personnel operating from distributed locations, anDREa compensates for the lack of a physical corporate perimeter through stringent technical and organizational guardrails under our Remote Working framework.
Compensating Controls & Mappings
Because physical perimeters are absent, the risk of data exposure in physical environments is systematically neutralized using the following ISO/IEC 27001-mapped controls:
| Framework / Document Reference | Element & Identifier | Operational Implementation / Compensating Control |
|---|---|---|
| ISO/IEC 27001 | A.06.07 - Remote working | Mandates strict physical behavior rules for home and remote environments, including mandatory clear-desk policies, automated inactivity screen locks, and prohibition of processing confidential data in public views. |
| ISO/IEC 27001 | A.08.01 - User end point devices | Enforces mandatory full-disk encryption (BitLocker/FileVault) and centralized Mobile Device Management (MDM) on all company-issued endpoints, ensuring that even if a device is physically stolen from a remote location, data remains completely inaccessible. |
| ISO/IEC 27001 | A.05.15 - Access control | Mandates strong logical boundaries, enforcing conditional access policies and Multi-Factor Authentication (MFA) so that physical possession of a device alone does not grant access to the platform. |
Audit Summary
- Compliance Status: Not Applicable (Exempt via Architecture)
- Gaps Identified: None. The justification for non-applicability is technically and organizationally sound. Risks regarding physical asset loss or compromise are fully mitigated by strong technical endpoint controls, ubiquitous encryption, and strict remote-work behavioral standards.