ISO 27001 A.7.2 and the BSI building blocks of layer INF require evidence of who has access to sensitive areas and that authorisations are withdrawn on departure or role change. The locking system itself knows who can unlock, but not why. The register closes that gap with four building blocks: the locking system as the bracket, the access area as what gets unlocked, the authorisation group as a bundle of areas, and the authorisation as the assignment to a person.
An authorisation that no longer applies is withdrawn. Date, reason and whether the medium came back remain on record. A deleted record proves nothing: in an audit it cannot be told apart from an authorisation that never existed.
2
The cockpit answers the audit questions
Expired but not withdrawn, groups with an overdue review, areas with high protection needs. The first is the classic finding with contractors and temporary staff.
3
Vendor-neutral, with a path to integration
Mechanical systems, electronic ones and mixed estates are handled alike. Two fields are prepared for later reconciliation: the leading system and its reference there.
Capabilities
Capabilities in detail
Locking systems mechanical, electronic or hybrid, with vendor and site
Access areas as door, room, cabinet, gate or barrier with location
Protection needs per area, high levels appear in the cockpit
Authorisation groups with an owner and a review date
Authorisation via a group or directly on an area
Medium with identifier so a lost transponder stays blockable
Grant with date and reason, expiry, withdrawal with a mandatory reason
Flag for whether the medium was returned
Cockpit and dashboard widgets, plus distribution of areas by protection need
A separate right for granting access, kept apart from group maintenance
Result
Evidence that authorisations were withdrawn on departure, including whether the key came back.
Experience Physical Access live
Schedule a no-obligation demo – we will show you the module with your own use cases.