01Objectives and test scope
The test examines whether the physical protective measures of a site can be circumvented under realistic conditions: perimeter, access and escort processes, protection of server rooms and technical areas as well as the behaviour of employees. NIST SP 800-115 describes physical security testing as a non-technical testing technique in which locks, badge readers and other physical controls are defeated in order to gain unauthorised access to specific systems. ISECOM's OSSTMM 3 assigns such tests to the Physical Security (PHYSSEC) class with its two channels Human and Physical, and requires results that are quantitatively measurable, consistent and repeatable and that contain only facts from the test itself – explicitly without subjective interpretation. The BSI practical guide for IS penetration tests likewise explicitly lists infrastructure facilities such as access control mechanisms and building management as a common test object.
02Typical attack scenarios
At the centre are unauthorised entry and the question of how far an attacker gets inside the building: tailgating behind authorised persons, pretended roles such as service provider, supplier or auditor (onsite social engineering), unsecured secondary routes via goods delivery, underground car park or side entrances, as well as mechanical attacks on locking and latching hardware. With badge cloning, the choice of card technology is decisive: with the widely used MIFARE Classic, each memory sector is protected by its own 48-bit key of the CRYPTO1 stream cipher; as early as 2009, attacks were published that require nothing more than radio contact with the card – without access to a genuine reader – and reconstruct a key in less than a second on off-the-shelf hardware, so that the card can be copied immediately. USB drops test the last mile on the inside: in a field study with 297 USB drives dropped on a campus, the estimated success rate was between 45 and 98 percent, and the first drive was plugged in in less than six minutes – predominantly with the motive of finding the owner. The goal is never to collect individual defects, but to evidence the attack path from the outside area through to a defined protected asset.
03Rules of engagement and authorisation letter
Without written authorisation, a physical test is not permissible: anyone who unlawfully enters business premises commits trespass (Hausfriedensbruch, § 123 StGB, imprisonment of up to one year or a fine, prosecuted only upon complaint); if a protective mechanism securing access to data is additionally defeated, § 202a StGB may be affected. The BSI states that testers should never test without a written engagement and that the test object, test period and test depth, as well as duties to cooperate, liability and confidentiality, must be governed contractually; where services are outsourced, the service provider must also be included in the contract. In Appendix B, NIST SP 800-115 provides a template for rules of engagement covering purpose and scope, assumptions and limitations, risks, logistics (people, time windows, test locations including badges, escorts and security personnel, test equipment), communication and escalation paths including abort criteria, as well as an explicit exclusion list. In practice this means: an authorisation letter carried on site – NIST provides a form with signatures and contact details that testers can show to security or law enforcement personnel –, an authorised contact person reachable at any time during the test window, and a defined means of verification: guards must be able to check the testers' legitimacy via a contact person or documents.
04How a physical penetration test proceeds
After objectives have been clarified and the scope defined, reconnaissance and scenario planning follow (publicly available information, site walks, observation of shift changes and delivery traffic), then execution, a closing meeting and the report. For tests lasting several days, the BSI recommends a brief conversation each morning between the testers and the client's technical staff involved, as well as a short summary once the work has been completed; critical findings should be evaluated on site to the extent that those responsible can remediate them immediately. A moderate level of intrusiveness is important: evidence should be produced, but systems and locking hardware must not be damaged. If personal data is affected, the data protection officer and, where applicable, the employee representatives must be involved before the tests; according to the BSI, tests with a social engineering component should only take place under precisely defined conditions, with the involvement of the employee representatives and with specialists trained for this purpose. For such tests, NIST emphasises that the results serve the security of the organisation and not the purpose of singling out individuals. For repeat tests, the BSI names a cycle of two to three years, since new vulnerabilities and attack methods become known on a regular basis.
05Positioning within ISO/IEC 27001 Annex A.7
Annex A of ISO/IEC 27001:2022 organises its 93 controls into four themes; 14 of them are physical controls (A.7.1 to A.7.14), from security perimeters (A.7.1) through physical entry (A.7.2) and securing offices, rooms and facilities (A.7.3) to working in secure areas (A.7.6) and clear desk and clear screen (A.7.7). New compared with the 2013 version is A.7.4 on physical security monitoring; implementation guidance is provided by ISO/IEC 27002:2022. A physical penetration test is not explicitly required by the standard – but it does require processes and measures to be monitored and measured and the effectiveness of the management system to be evaluated (clause 9.1), and information security to be independently reviewed at planned intervals (A.5.35). In the BSI's IT-Grundschutz, the modules of the INF layer correspond, among them INF.1 Allgemeines Gebäude and INF.2 Rechenzentrum sowie Serverraum.
06What a good report delivers
The report should begin with a description of the test object and the test conditions, followed by a management summary and technical chapters with comprehensible descriptions and recommendations; the BSI recommends refraining from product recommendations and naming product classes instead. For prioritisation, a classification that combines damage potential and the required response time is suitable – the BSI uses high (immediately), medium (short term), low (medium term) and for information (long term) and factors the protection requirements of the data as well as the capabilities and resources needed by the attacker into the assessment. For physical tests there is more: the chronological reconstruction of the attack paths with evidence, the mapping of findings to the affected controls (for example A.7.1 to A.7.4) and the explicit naming of what did work – that is, attempts that were detected and repelled, as a basis for assessing the security service and the reporting processes. Equally part of it are a limited distribution list, a confidentiality marking and the note that the results reflect the state at the time of testing.