HLD Group
Physical security policy
Physical access to facilities, equipment, and media.
Last updated: 24 July 2026
Version 1.1 · Review cycle: 365 days · View all frameworks
1. Purpose
This policy defines the physical and environmental controls that protect HLD Group personnel, facilities, equipment, and information from unauthorised physical access, damage, and interference. Physical security underpins information security: a control is only as strong as the physical protection around the systems that enforce it.
2. Scope
This policy applies to all offices, co-working facilities, and any data centre space under HLD Group control, and to equipment and media used for company business including in remote and home-working settings. Cloud data centres are operated by our providers under their own certified physical security programmes, which we assess through the Vendor Management Policy.
3. Definitions
- Secure area — a physical space with access restricted to authorised people
- Clear desk and clear screen — practices that prevent exposure of sensitive information
- Tailgating — following an authorised person through a controlled entrance without authenticating
- Environmental controls — protections against fire, power loss, flooding, and climate
4. Physical access controls
- Access to offices and secure areas is controlled and granted on a least-privilege basis
- Access rights are provisioned, reviewed, and revoked in line with the identity lifecycle
- Visitors are registered, escorted in sensitive areas, and identifiable
- Personnel are trained not to permit tailgating and to challenge unaccompanied strangers
5. Environmental protection
- Fire detection and suppression appropriate to the facility
- Uninterruptible power and, where warranted, backup power for critical equipment
- Climate control for equipment rooms, and protection against water and flooding
- Monitoring and alerting for environmental conditions in critical areas
6. Equipment and media handling
- Equipment is inventoried, encrypted, and physically secured against theft
- Clear desk and clear screen practices apply to sensitive information
- Media is securely stored and, at end of life, sanitised or destroyed under the Asset Management Policy
- Portable equipment and media taken off-site are encrypted and protected against loss
7. Remote and home working
Personnel working outside company premises apply proportionate physical safeguards for equipment and information, consistent with the Remote Work Policy, including securing devices and preventing overlooking of sensitive material.
8. Framework alignment
- ISO/IEC 27001:2022 Annex A controls 7.1 to 7.14 (physical and environmental security)
- NIST SP 800-53 Rev. 5 control family PE (Physical and Environmental Protection)
- SOC 2 Trust Services Criteria CC6.4
- PCI DSS v4.0 Requirement 9 where cardholder data is in scope
9. Roles, exceptions, and review
Facilities and IT share responsibility under the CISO. Exceptions require documented CISO approval with compensating controls and an expiry date. This policy is reviewed at least annually and on any change of premises.
Related frameworks
For contractual attestations or audit packs, contact [email protected].