Chapter 6
Administrative & Physical Controls
Examine the non-technical safeguards that underpin every security program — policies, procedures, human-resource controls, security awareness training, physical access restrictions, and incident-response preparedness.
Security Policies & Procedures Review
Why Policies Matter in a Cybersecurity Audit
Administrative controls form the governance backbone of any information security program. While technical controls enforce rules at the system level, administrative controls define what those rules should be, who is responsible for them, and how compliance is measured. During an audit, you must evaluate whether the organization has established, communicated, and enforced a comprehensive set of security policies and procedures. A policy that exists only on paper — never reviewed, never enforced — provides no real protection and may actually increase legal liability by demonstrating awareness of risk without corresponding action.
- Information Security Policy: The overarching policy that defines the organization's commitment to security, assigns roles and responsibilities, and establishes the policy hierarchy. It should be approved by executive leadership and reviewed at least annually.
- Acceptable Use Policy (AUP): Defines acceptable and prohibited uses of organizational IT resources, including workstations, email, internet access, removable media, and cloud services. Employees should acknowledge this policy upon hire and annually thereafter.
- Access Control Policy: Establishes the principles governing user access to systems and data — including least privilege, separation of duties, role-based access, and the processes for granting, modifying, and revoking access.
- Data Classification and Handling Policy: Defines data classification levels (e.g., public, internal, confidential, restricted) and specifies handling requirements for each level, including storage, transmission, retention, and disposal.
- Incident Response Policy: Outlines the organization's approach to detecting, responding to, containing, eradicating, and recovering from security incidents. It should define severity levels, escalation paths, and communication protocols.
- Change Management Policy: Establishes the process for requesting, reviewing, approving, implementing, and documenting changes to IT systems and infrastructure to prevent unauthorized or destabilizing modifications.
Evaluating Policy Quality and Effectiveness
Finding that a policy document exists is only the first step. Auditors must assess whether each policy is complete, current, enforceable, communicated, and actually followed. A well-written policy that no one reads or follows is worse than no policy at all because it creates a false sense of governance. Evaluate policies against the following criteria to determine their effectiveness.
| Criterion | What to Look For | Red Flags |
|---|---|---|
| Currency | Last review date within 12 months; reflects current technology and threats | Policy last updated three or more years ago; references obsolete technology |
| Ownership | Named policy owner responsible for maintenance and enforcement | No designated owner; generic attribution to 'IT Department' |
| Approval | Formal approval by appropriate authority (CISO, board, management) | No evidence of executive approval or sign-off |
| Communication | Evidence that employees have received and acknowledged the policy | No acknowledgment records; employees unaware of policy existence |
| Enforcement | Documented consequences for non-compliance; evidence of enforcement actions | No enforcement mechanism; known violations without consequences |
Security Awareness Training & HR Controls
The Human Element in Cybersecurity
Human error remains one of the leading causes of security breaches. Phishing attacks, weak passwords, misconfigurations, and social engineering all exploit the human element. Security awareness training transforms employees from potential vulnerabilities into an active layer of defense. During a cybersecurity audit, you must evaluate whether the organization has a structured, ongoing security awareness program that goes beyond a checkbox exercise and genuinely changes employee behavior.
- Training Frequency: Is training conducted at least annually for all employees? Is additional training provided upon hire and when policies change? Is role-specific training provided for high-risk positions such as administrators, developers, and executives?
- Training Content: Does the training cover current threats like phishing, ransomware, and social engineering? Is it updated to reflect the evolving threat landscape? Does it include organization-specific scenarios?
- Phishing Simulations: Does the organization conduct regular phishing simulations to test employee awareness? Are results tracked over time to measure improvement? Are employees who fail simulations provided with additional training?
- Completion Tracking: Is there a system to track training completion and send reminders for overdue training? What is the completion rate? How are non-compliant employees handled?
- Effectiveness Measurement: Does the organization measure training effectiveness beyond completion rates? Are metrics like phishing simulation click rates, incident reporting rates, and security question scores tracked over time?
Human Resource Security Controls
HR controls address the security risks associated with the employee lifecycle — from hiring through termination. These controls ensure that the right people are given appropriate access, that they understand their security responsibilities, and that access is promptly revoked when employment ends. Gaps in HR security controls are a common source of audit findings, particularly around the termination process where delays in revoking access create windows of vulnerability.
- Background Checks: Are background checks conducted for all new hires? Are they more rigorous for positions with access to sensitive data or critical systems? Are checks repeated periodically for employees in high-trust positions?
- Onboarding Process: Is there a formal onboarding process that includes security orientation, policy acknowledgment, and access provisioning based on the employee's role? Are confidentiality and non-disclosure agreements signed before access is granted?
- Role Changes: When employees change roles within the organization, is their access reviewed and adjusted to match their new responsibilities? Is old access revoked, or does it accumulate over time (access creep)?
- Termination Process: Is there a documented offboarding checklist? Is access revoked within a defined timeframe (ideally on the same day or before the employee's last day)? Are company devices, badges, and keys collected? Are shared passwords changed?
Physical Access Controls & Incident Response
Physical Security as a Foundation
Physical security is often overlooked in cybersecurity audits focused on digital controls, but physical access to servers, network equipment, and workstations can bypass even the strongest technical safeguards. An attacker who gains physical access to a server room can install rogue devices, extract data from unencrypted drives, reset passwords, or cause physical destruction. Auditors must evaluate whether the organization has implemented layered physical controls that protect critical infrastructure from unauthorized physical access.
- Facility Perimeter Security: Are building entrances controlled with electronic badge readers, security guards, or both? Are visitors required to sign in and be escorted? Are exterior doors alarmed and monitored?
- Server Room and Data Center Controls: Are server rooms secured with dedicated access controls (badge, biometric, or key)? Is access restricted to authorized personnel only? Are access logs maintained and reviewed?
- Surveillance Systems: Are CCTV cameras installed at critical locations such as entrances, server rooms, and loading docks? How long is footage retained? Is footage reviewed proactively or only after incidents?
- Environmental Controls: Are server rooms equipped with fire suppression systems, temperature and humidity monitoring, water leak detection, and uninterruptible power supplies (UPS)? Are these systems tested regularly?
- Clean Desk Policy: Does the organization enforce a clean desk policy requiring employees to secure sensitive documents and lock workstations when unattended?
Incident Response Preparedness
Incident response is the organization's ability to detect, contain, eradicate, and recover from security incidents. During an audit, you evaluate not only whether an incident response plan exists but whether the organization has the people, processes, and tools to execute it effectively when a real incident occurs. An untested incident response plan provides little value during an actual breach.
- Incident Response Plan (IRP): Is there a formal, documented IRP? Does it define incident categories and severity levels? Does it establish clear roles and responsibilities for the incident response team?
- Incident Response Team: Is there a designated incident response team with defined members and alternates? Are team members trained in incident handling? Are contact details current and accessible during an emergency?
- Communication Plan: Does the IRP include internal and external communication protocols? Are escalation paths defined? Is there a plan for communicating with customers, regulators, law enforcement, and the media when required?
- Testing and Exercises: Are tabletop exercises or simulations conducted at least annually? Are lessons learned from exercises and actual incidents incorporated into the plan? Are post-incident reviews conducted after every significant incident?
- Forensic Readiness: Does the organization have the tools and procedures to preserve digital evidence during an incident? Are forensic procedures documented? Is there a relationship with an external forensics firm for incidents beyond internal capabilities?
| Maturity Level | Characteristics | Audit Expectation |
|---|---|---|
| Ad Hoc | No formal plan; incidents handled reactively on a case-by-case basis | Critical finding — immediate remediation needed |
| Documented | Formal IRP exists but has not been tested or exercised | High finding — testing and training required |
| Tested | IRP is documented and tested through tabletop exercises at least annually | Meets baseline expectations for most frameworks |
| Integrated | IRP is tested regularly, lessons learned are incorporated, and response is coordinated with business continuity and disaster recovery plans | Mature and well-managed program |
Chapter quiz
Administrative & Physical Controls Quiz
6 questions · passing score 70%
Practice scenario
Auditing a Company's Administrative Controls
You are conducting an administrative controls assessment for BrightPath Healthcare, a regional healthcare provider with 500 employees and 12 clinic locations. BrightPath handles protected health information (PHI) and must comply with HIPAA. The CISO, Maria Santos, has asked your firm to evaluate their administrative and physical security controls as part of their annual risk assessment. You are meeting with Maria and her team over two days to review policies, training records, HR processes, and physical security at the main office and one clinic location.