Physical and environmental: who owns it on each service model
The buildings, power, cooling and the disposal of storage media. On every public cloud model this is the provider's, and the evidence is its assurance report.
The split by service model
| Service model | Owner | Why, and the clause |
|---|---|---|
| Infrastructure as a service | the provider's | The data centres, power, cooling, access to the floor and the disposal of retired media are the provider's; your evidence is its assurance report, not your own inspection. ISO/IEC 27017 11.2.7 |
| Platform as a service | the provider's | The data centres, power, cooling, access to the floor and the disposal of retired media are the provider's; your evidence is its assurance report, not your own inspection. ISO/IEC 27017 11.2.7 |
| Software as a service | the provider's | The data centres, power, cooling, access to the floor and the disposal of retired media are the provider's; your evidence is its assurance report, not your own inspection. ISO/IEC 27017 11.2.7 |
| Serverless functions and event services | the provider's | The data centres, power, cooling, access to the floor and the disposal of retired media are the provider's; your evidence is its assurance report, not your own inspection. ISO/IEC 27017 11.2.7 |
| Hosted AI models and AI platforms | the provider's | The data centres, power, cooling, access to the floor and the disposal of retired media are the provider's; your evidence is its assurance report, not your own inspection. ISO/IEC 27017 11.2.7 |
The clauses each framework attaches
5 quoted| Framework | Clause |
|---|---|
| Cloud Controls Matrix v4.0.1 | CCM-DCS-09 Secure Area Authorization |
| ISO/IEC 27017:2015 | ISO/IEC 27017 11.2.7 Secure disposal or re-use of equipment |
| SOC 2 Trust Services Criteria | SOC 2 CC6.4 Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives |
| CMMC 2.0 | CMMC PE.L2-3.10.1 Limit Physical Access |
| C5 cloud criteria catalogue | C5-PS-04 Physical site access control |
CCM-DCS-09 Secure Area AuthorizationAdmit only authorised people to secure areas, restrict and monitor every entry and exit point with physical access mechanisms, and retain the access records for the period the organisation has set.
- The authorised access list per secure area and its review records
- Physical access control configuration covering ingress and egress
- Access logs retained for the defined period
- Records of access reviews and removals
- Egress not controlled or monitored, only entry
- Access list never reviewed, so leavers retain badge rights
- Retention period undefined, so logs are purged inconsistently
ISO/IEC 27017 11.2.7 Secure disposal or re-use of equipmentThe provider should arrange for secure disposal or re-use of equipment that has held customer information, so that customer data cannot be recovered from storage that is retired or reassigned to another tenant, and should tell customers about the arrangement. The customer should confirm that the provider's disposal practice meets its requirements for the information it places in the service.
- Provider media sanitisation and disposal procedure
- Disposal or destruction records
- Customer review of the provider's disposal statement
- Storage reassigned between tenants without sanitisation
- Customer requirement for certified destruction not passed to the provider
SOC 2 CC6.4 Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectivesRestricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives
- List of facilities and protected information assets in scope, including data centre space, back-up media storage and other sensitive locations
- Authorisation records showing who is permitted physical access to each location and on what basis
- Access control system configuration and badge listings for those locations, reconciled against the authorisation records
- Records of periodic review of physical access rights and of removals made as a result
- Visitor and third party access records for the same locations, including escort evidence
- Primary data centre well controlled while back-up media storage and offsite locations rely on a provider attestation with no entity level review
- Physical access rights reviewed less often than logical access, so leavers keep badge access after their accounts are disabled
- Sensitive locations such as network rooms and media handling areas omitted from the scope list entirely
CMMC PE.L2-3.10.1 Limit Physical Access Level 1 and 2Limit physical access to systems, equipment and their operating environments to authorized individuals.
- Physical access authorization list for controlled areas
- Access control mechanism evidence such as badge system configuration
- Periodic review of who holds physical access
- Access lists not reviewed so departed staff retain badges
- Server and equipment areas within general office access
- Authorization granted verbally without record
C5-PS-04 Physical site access controlControl entry at every access point using an access control system whose documented rules grant least privilege authorisations, revoke unused rights after two and six months, enforce two factor authentication for areas holding customer data, escort visitors and log all entries.
- Badge system export showing authorisation holders per security area
- Report of automatically revoked credentials with the recorded inactivity dates
- Visitor register with escort names and pass return times
- Door reader event log for a sampled high security room
- Dormant contractor badges still active well past the stated inactivity limit
- Two factor reader on the machine room door bypassed through an adjacent office door
- Visitors recorded at reception yet not tracked by the badge system inside the building
- No periodic reconciliation of badge holders against current job roles