The most common answer to a physical security question is "we are cloud-native, it does not apply". That answer covers the data centre and nothing else. Your offices, laptops, home-working arrangements, visitors, printed material and disposal processes are all still in scope - and so is the assurance you inherit from your providers, which you have to evidence rather than assume.
What the cloud actually removes
Using a major cloud provider transfers data centre physical security to them. What it leaves with you:
- Evidence of their controls. You are relying on a third party, so you need their audit report - typically SOC 2 Type II or ISO 27001 - reviewed and retained, not just referenced. Assessors ask when you last read it, and whether you checked the report period covers yours.
- Everything on your own premises - offices, meeting rooms, comms cabinets, any remaining server room.
- Endpoints, which now hold or reach the same data the data centre used to.
- Home and remote working, which moved a large part of this domain into places you do not control.
Perimeters and entry
- Defined secure areas with progressively stronger controls - reception, general office, restricted rooms. The point is layering, not fortification.
- Access control on entry, with badge records retained. Those logs are the evidence, and they only exist if the system retains them for long enough.
- Access rights reviewed periodically, exactly like logical access. Badge access to the comms room accumulates the same way admin rights do - and it is almost never reviewed.
- Revocation on departure, tied to the same HR trigger as system access. A returned laptop and a still-active badge is a common finding.
- Tailgating. The control that defeats every badge reader. Address it through awareness and layout rather than pretending it does not happen - and note that a polite culture makes it worse, which is worth saying out loud in training.
Cover every control domain, not just the technical ones
GRC Copilot tracks physical, HR and supplier controls alongside your technical ones, with owners and evidence for each - so nothing sits unassigned until fieldwork.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Visitors and third parties
A visitor log, escorting in restricted areas, visible identification, and the same treatment for contractors and delivery personnel. The failure mode is consistent: engineers attending to fix equipment get unescorted access to exactly the areas that matter most, because they are there in a professional capacity. Maintenance visits belong in the log like any other.
Equipment
- Siting - screens not visible from windows or public areas; equipment away from obvious environmental hazards.
- Cabling and comms cabinets secured. An unlocked cabinet in a shared building is a network tap waiting to happen.
- Off-site equipment authorised and tracked, which is now most equipment.
- Secure disposal. Certificates of destruction for drives and media, and evidence that decommissioned devices were wiped. Retain the certificates - this is a routine evidence request and the paperwork is easily lost.
- Unattended equipment and clear desk / clear screen. Modest controls, but auditors do walk the floor during site visits, and a sensitive document left on a printer during a tour is a memorable finding.
Environmental controls
Where you still hold equipment: fire detection and suppression, temperature and humidity monitoring, power protection and continuity, water ingress detection, and evidence of maintenance and testing. If everything is with a provider, this reduces to reviewing their assurance report - but say so explicitly in your Statement of Applicability rather than leaving the control blank.
Remote and home working
The part most policies still under-address, because it is genuinely harder:
- Full-disk encryption on every device that leaves the office - the single most effective control here, and the one that turns a lost laptop into a non-event.
- Screen locking with a short timeout.
- Guidance on working in public spaces and on video calls in shared homes.
- Handling and disposal of printed material at home, which is realistically about telling people not to print.
- Loss and theft reporting, with a route people will actually use.
Encryption is what makes the rest proportionate. A lost encrypted laptop is an asset replacement; a lost unencrypted one may be a notifiable breach. That single distinction justifies the whole endpoint programme.
Frequently asked questions
We have no office. Does this apply?
Partly. Data centre and office controls fall away or transfer, but endpoints, remote working, disposal and provider assurance remain. Mark the rest not applicable with a documented justification rather than silently.
What evidence do auditors ask for?
Badge access logs and reviews, visitor logs, provider audit reports with evidence you reviewed them, destruction certificates, encryption status across the fleet, and often a physical walkthrough.
Are visitor logs really necessary?
Yes - they are among the most consistently sampled physical records, and they matter during an investigation. Digital sign-in is fine; a notebook nobody fills in is not.
How do we control a home office?
You control the device and set expectations for the environment. Encryption, screen lock, MDM and clear guidance are the realistic scope - do not write policy you cannot verify.
Key takeaways
- Cloud transfers the data centre only - and you must evidence the provider's assurance, not assume it.
- Review physical access rights like logical ones; badge access accumulates the same way.
- Keep destruction certificates and visitor logs - both are routinely sampled.
- Full-disk encryption is what makes the endpoint and remote-working risk proportionate.