1500.0—1500.0
>Control Description
The Supplier shall, unless prohibited by applicable law, restrict and monitor all physical access to facilities where Data is stored or processed to its authorised Personnel by implementing industry standard physical access controls. Examples of such controls include but are not limited to:
i) Swipe card technology
ii) Monitored CCTV
iii) Remotely monitored alarm systems
iv) On-premise security guards
v) Photographic access credentials
vi) Visitor escort
vii) Physical access logs
viii) Authorised access lists.
The Supplier shall review physical access logs regularly or in the event of a physical or cybersecurity incident.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.