Guides
Access control, explained without the sales pitch.
What your badges actually are, why a leaver’s card still opens the door, and what SOC 2, ISO 27001 and TIA-942 expect of the physical layer.
CredentialsCan prox cards be cloned? What 125 kHz badges mean for your officeYes, in seconds. How 125 kHz proximity badges get copied, how to tell whether your building still accepts them, and what to move to instead.CredentialsMIFARE Classic vs DESFire EV3 vs Seos: which access card is actually secure?Compare the access card technologies in most offices: which can be cloned with commodity tools, which cannot, and what matters more than the card.DeprovisioningWhy a terminated employee’s badge still works, and how to test for itBadge deprovisioning fails at the join between HR, the identity provider and the access control system. Where it breaks, and a test you can run this week.ComplianceSOC 2 CC6.4: physical access controls and the evidence auditors ask forWhat SOC 2 criterion CC6.4 covers, what evidence auditors typically request, where companies get exceptions, and how cloud-hosted firms scope it.ComplianceISO 27001 Annex A.7: the 14 physical controls, explainedAll 14 physical security controls in ISO/IEC 27001:2022 Annex A.7, what each asks for in plain English, and what an assessor looks at on site.Data centersData center physical security assessment: a layer-by-layer checklistA layer-by-layer checklist for data center and colocation physical security, from the perimeter to the cabinet door and the shredder.