Physical Security Policy
Document control
| Field | Value |
|---|---|
| Document status | Active policy document |
| Owner | Security / Operations |
| Approver | Management |
| Review frequency | Annual or on material change |
| Classification | Customer-shareable |
Purpose
Protect company premises, devices, documents, and work areas from unauthorized physical access, loss, theft, or damage.
Premises access
Access to offices and restricted areas should be limited to authorized personnel. Visitors should be accompanied or logged where appropriate.
Device and document protection
Devices must be secured when unattended. Sensitive documents should not be left exposed in public or shared areas. Printed sensitive information should be minimized and disposed securely.
Remote work
Remote workers must protect devices from unauthorized access, use screen locks, avoid public exposure of sensitive information, and report loss/theft promptly.
Visitors and vendors
Visitors and vendors should access only areas and information required for their purpose. Sensitive discussions or screens should not be exposed to unauthorized visitors.
Incident reporting
Lost devices, unauthorized access, theft, or physical security weaknesses must be reported promptly.
Evidence to maintain
Visitor logs where applicable, device inventory, access records, incident reports, and disposal records.