Physical Security & Site Protection
Protecting the site physically: perimeters, access control, visitor management, critical-area restriction, material security, insider risk, surveillance and response. Physical access is the ultimate control over product and records, because someone in the room can defeat most logical controls. It also carries specific legal obligations for controlled substances, where security and recordkeeping are federally prescribed rather than left to risk assessment.
What an explainer is not
A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.
[ POSITION IN THE FRAMEWORK ]
7 DIMENSIONS · 25 LINKSSomeone in the room defeats most logical controls, and for controlled substances the security requirements are prescribed rather than risk-based — which makes physical security the one area where a risk assessment cannot lower the bar.
06 · QUALITY MATURITY — PHYSICAL SECURITY & SITE PROTECTION, REACTIVE TO ADAPTIVE
Access is controlled at the perimeter. Inside, movement is unrestricted and visitors are escorted by convention.
Areas are zoned with access control, and controlled substance storage meets the prescribed physical requirements as installed.
Access rights follow the sensitivity of what an area holds, prescribed requirements are verified as maintained rather than as installed, and reconciliation of controlled stock is independent of the people holding it.
Physical and logical access are reconciled, so a person who cannot enter a room cannot act on its systems remotely either.
Security is designed into flows and layout, so protection does not depend on procedure or on individual vigilance.
SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →
07 · REGULATORY & EVIDENCE
GOVERNING STANDARDS · 5
Derived from the 5 standards SPEQ maps to this subject, across 4 regulatory bodies: FDA, EMA, DEA, ISO.
RECORDS & OBJECTIVE EVIDENCE
- Access control by area, aligned to the sensitivity of the materials or records held
- Controlled substance storage and recordkeeping meeting the prescribed requirements
- Independent reconciliation of controlled stock, and investigation of discrepancies
- Visitor and contractor control, including escort and area restriction
- Reconciliation between physical and logical access rights
COMMON INSPECTION FINDINGS
- Controlled substance storage meeting the requirement as installed but not as maintained
- Stock reconciliation performed by the same person who holds the keys
- Access rights accumulated as people changed role, with no review
- Visitors unescorted in areas holding product or regulated records
- Physical and logical access managed separately, so a leaver retains one of them
Physical access undercuts logical controls
Careful work goes into logical access — unique accounts, authority checks, audit trails that cannot be disabled. Much of it can be bypassed by someone standing at the machine: an unlocked workstation left logged in, a server room anyone can enter, an instrument whose local interface has no authentication, a printed batch record left where anyone can alter it.
The productive framing is that physical and logical access controls protect the same asset and should be designed together against the same threat. A GxP system whose logical controls are strong and whose physical access is unrestricted has a control boundary that stops at the door, and every data-integrity argument built on the logical controls stops there too.
Controlled substances: prescribed, not risk-based
For controlled substances, security is not a matter for the organisation’s judgement. 21 CFR Part 1301 sets registration and physical security requirements — construction of storage areas, alarm and monitoring provisions, and controls over who has access — and Part 1304 sets the recordkeeping and inventory obligations, including biennial inventory and specific record retention.
This is a distinct regime from GMP with a distinct inspectorate, and it is prescriptive where GMP is risk-based. A site accustomed to justifying controls through risk assessment can be surprised by requirements that are simply stated, and the surprise usually arrives during a DEA inspection rather than during an internal audit that applied the wrong mental model.
Visitors, contractors and the access nobody reviews
Employee access is reviewed periodically in most regulated sites. Contractor and visitor access frequently is not: a badge issued for a shutdown that still works two years later, a contractor whose engagement ended and whose card was not returned, an escort requirement that decayed into a signature at reception.
These populations are also the ones most likely to be in critical areas — construction, maintenance and vendor engineering are exactly the work that happens in classified space and near regulated systems. Including contractor and visitor access in the same periodic review as employee access is a one-line scope change and it is where the review usually finds something.
SPEQ interpretation — the perimeter that matters is around the record
Site security is designed outward-in: perimeter, building, area, room. For product and record protection the useful question is the reverse — for a given critical asset, a batch record, a server, a controlled-substance store, an isolator, who can physically reach it, and is that set the same as the set authorised to act on it.
Those two sets diverge constantly and nobody compares them, because physical access is administered by security and logical authorisation by IT or quality. Running the comparison for the handful of genuinely critical assets is a short exercise that reliably finds people who can reach something they are not authorised to touch — which is the gap physical security exists to close.
FREQUENTLY ASKED
How does physical access undermine logical controls?
Someone at the machine can bypass most of them — an unlocked workstation, an unrestricted server room, an instrument with no local authentication, a printed batch record left accessible. A GxP system with strong logical controls and unrestricted physical access has a control boundary that stops at the door, and so does the data-integrity argument built on it.
Is controlled-substance security risk-based?
No. 21 CFR Part 1301 prescribes registration and physical security — storage construction, alarms and monitoring, access controls — and Part 1304 prescribes recordkeeping and inventory including biennial inventory. It is a distinct regime with a distinct inspectorate, prescriptive where GMP is risk-based, and applying the GMP mental model to it produces surprises during a DEA inspection.
Whose access is usually not reviewed?
Contractors and visitors — a badge issued for a shutdown that still works two years later, a card never returned, an escort requirement that decayed into a signature at reception. They are also the populations most likely to be in critical areas, since construction, maintenance and vendor engineering happen in classified space.
What comparison finds real physical-security gaps?
For each genuinely critical asset — a batch record, a server, a controlled-substance store, an isolator — compare who can physically reach it against who is authorised to act on it. The two sets diverge constantly because physical access is administered by security and logical authorisation by IT or quality, and nobody compares them.