Physical Security
Does the physical estate hold when it is tested? Badge readers, visitor systems and environmental sensors already record what happened at the door. They are almost never held against the identity and incident record, and physical remediation is almost never re-measured. This IO domain correlates the two, then remeasures the defined condition after the work is completed and reports whether the measure improved, remained flat, regressed or was inconclusive.
Where the boundary sits.
The boundary with Resiliency is deliberate. Resiliency asks whether the organisation keeps operating after disruption; this asks whether physical access behaves as designed and whether a physical remediation held. Where a physical event and a digital one describe the same person, the correlation happens in IO rather than in a retrospective.
The signals read, and the work prescribed against them.
The summary of each is on the surface. Open one for the specific dimensions behind it.
SignalsWhat IO reads for this domain6 signal and evidence families, correlated deterministically rather than inferred.
- Access-control events by person, door and time
- Access held but never used, and access that outlived the role
- Visitor and contractor records against the sponsor who approved them
- Sensor and reader health, including coverage gaps
- Physical access events correlated with the identity record
- Incident records naming a physical cause
PlaybooksWhat IO prescribes4 representative playbooks, each gated on prerequisites and maturity.
- Revoke physical access that outlived the role or the contract
- Close the doors where access is held and never exercised
- Repair reader and sensor coverage gaps in the highest-consequence zones
- Tighten contractor and visitor sponsorship where approval cannot be traced
SeatsWho lands here first3 seats read this domain before anyone else does.
- Security operations
- Governance, risk and compliance
- COO
What has to move for this to have worked.
Stale physical access revoked, and whether it stayed revoked
Reader and sensor coverage across in-scope zones, held separate from pass rate
Physical remediation re-measured from the same source after the work completed
Measurement and privacy boundary
IO uses the minimum event, identity-reference and system-health metadata required for the defined measure. The standard Physical Security IO domain does not require IO to retain raw camera footage. It does not score people or assign behavioural risk ratings to individuals. A badge event records that a system observed an event; it does not establish authorisation, intent or misconduct.
Correlations support governed investigation and prioritisation. They do not independently establish compliance, causation or complete physical-control effectiveness. Physical Security domain results are reported as performance and verification outcomes, not as maturity findings.
Retention, access, privacy and investigation requirements remain governed by the customer's approved policies and applicable law.
Observed behaviour, reported culture and completed learning held as one position, and re-measured on the behaviour, not the completion record.
Detections that arrive from tooling rather than a colleague's message, and where the identity pressure is actually landing.
Which AI tools are really in use, what data reaches them, and whether the written guardrails are the ones in force.
See it before you talk to anyone.
Two quarters of recorded activity across sixteen seats. One click, no install.