Book an Appointment

Physical security in the penetration test

How access controls, building processes and on-site behaviour can be verified under realistic attack conditions – controlled, authorised and documented in a traceable way.

In many security programmes, physical security is considered a closed case: there is a perimeter, turnstiles, badge readers and a security service. Whether these measures actually hold up in combination with people and processes only becomes apparent under attack conditions – for instance when someone walks through with a plausible role, a cloned card or simply in the slipstream of a group. A physical penetration test examines exactly that: with a clearly limited scope, written authorisation and defined abort criteria. It thus provides evidence of effectiveness for measures that cannot be reliably assessed through document review alone.

The Essentials at a Glance

01

Objectives and test scope

The test examines whether the physical protective measures of a site can be circumvented under realistic conditions: perimeter, access and escort processes, protection of server rooms and technical areas as well as the behaviour of employees. NIST SP 800-115 describes physical security testing as a non-technical testing technique in which locks, badge readers and other physical controls are defeated in order to gain unauthorised access to specific systems. ISECOM's OSSTMM 3 assigns such tests to the Physical Security (PHYSSEC) class with its two channels Human and Physical, and requires results that are quantitatively measurable, consistent and repeatable and that contain only facts from the test itself – explicitly without subjective interpretation. The BSI practical guide for IS penetration tests likewise explicitly lists infrastructure facilities such as access control mechanisms and building management as a common test object.

02

Typical attack scenarios

At the centre are unauthorised entry and the question of how far an attacker gets inside the building: tailgating behind authorised persons, pretended roles such as service provider, supplier or auditor (onsite social engineering), unsecured secondary routes via goods delivery, underground car park or side entrances, as well as mechanical attacks on locking and latching hardware. With badge cloning, the choice of card technology is decisive: with the widely used MIFARE Classic, each memory sector is protected by its own 48-bit key of the CRYPTO1 stream cipher; as early as 2009, attacks were published that require nothing more than radio contact with the card – without access to a genuine reader – and reconstruct a key in less than a second on off-the-shelf hardware, so that the card can be copied immediately. USB drops test the last mile on the inside: in a field study with 297 USB drives dropped on a campus, the estimated success rate was between 45 and 98 percent, and the first drive was plugged in in less than six minutes – predominantly with the motive of finding the owner. The goal is never to collect individual defects, but to evidence the attack path from the outside area through to a defined protected asset.

03

Rules of engagement and authorisation letter

Without written authorisation, a physical test is not permissible: anyone who unlawfully enters business premises commits trespass (Hausfriedensbruch, § 123 StGB, imprisonment of up to one year or a fine, prosecuted only upon complaint); if a protective mechanism securing access to data is additionally defeated, § 202a StGB may be affected. The BSI states that testers should never test without a written engagement and that the test object, test period and test depth, as well as duties to cooperate, liability and confidentiality, must be governed contractually; where services are outsourced, the service provider must also be included in the contract. In Appendix B, NIST SP 800-115 provides a template for rules of engagement covering purpose and scope, assumptions and limitations, risks, logistics (people, time windows, test locations including badges, escorts and security personnel, test equipment), communication and escalation paths including abort criteria, as well as an explicit exclusion list. In practice this means: an authorisation letter carried on site – NIST provides a form with signatures and contact details that testers can show to security or law enforcement personnel –, an authorised contact person reachable at any time during the test window, and a defined means of verification: guards must be able to check the testers' legitimacy via a contact person or documents.

04

How a physical penetration test proceeds

After objectives have been clarified and the scope defined, reconnaissance and scenario planning follow (publicly available information, site walks, observation of shift changes and delivery traffic), then execution, a closing meeting and the report. For tests lasting several days, the BSI recommends a brief conversation each morning between the testers and the client's technical staff involved, as well as a short summary once the work has been completed; critical findings should be evaluated on site to the extent that those responsible can remediate them immediately. A moderate level of intrusiveness is important: evidence should be produced, but systems and locking hardware must not be damaged. If personal data is affected, the data protection officer and, where applicable, the employee representatives must be involved before the tests; according to the BSI, tests with a social engineering component should only take place under precisely defined conditions, with the involvement of the employee representatives and with specialists trained for this purpose. For such tests, NIST emphasises that the results serve the security of the organisation and not the purpose of singling out individuals. For repeat tests, the BSI names a cycle of two to three years, since new vulnerabilities and attack methods become known on a regular basis.

05

Positioning within ISO/IEC 27001 Annex A.7

Annex A of ISO/IEC 27001:2022 organises its 93 controls into four themes; 14 of them are physical controls (A.7.1 to A.7.14), from security perimeters (A.7.1) through physical entry (A.7.2) and securing offices, rooms and facilities (A.7.3) to working in secure areas (A.7.6) and clear desk and clear screen (A.7.7). New compared with the 2013 version is A.7.4 on physical security monitoring; implementation guidance is provided by ISO/IEC 27002:2022. A physical penetration test is not explicitly required by the standard – but it does require processes and measures to be monitored and measured and the effectiveness of the management system to be evaluated (clause 9.1), and information security to be independently reviewed at planned intervals (A.5.35). In the BSI's IT-Grundschutz, the modules of the INF layer correspond, among them INF.1 Allgemeines Gebäude and INF.2 Rechenzentrum sowie Serverraum.

06

What a good report delivers

The report should begin with a description of the test object and the test conditions, followed by a management summary and technical chapters with comprehensible descriptions and recommendations; the BSI recommends refraining from product recommendations and naming product classes instead. For prioritisation, a classification that combines damage potential and the required response time is suitable – the BSI uses high (immediately), medium (short term), low (medium term) and for information (long term) and factors the protection requirements of the data as well as the capabilities and resources needed by the attacker into the assessment. For physical tests there is more: the chronological reconstruction of the attack paths with evidence, the mapping of findings to the affected controls (for example A.7.1 to A.7.4) and the explicit naming of what did work – that is, attempts that were detected and repelled, as a basis for assessing the security service and the reporting processes. Equally part of it are a limited distribution list, a confidentiality marking and the note that the results reflect the state at the time of testing.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

National Institute of Standards and Technology (NIST) · 2008

Technical Guide to Information Security Testing and Assessment (SP 800-115)

Describes physical security testing as a non-technical testing technique and contains, in Appendix B, a template for rules of engagement including an exclusion list and abort criteria.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2016

Ein Praxis-Leitfaden für IS-Penetrationstests, Version 1.2

Names access control mechanisms and building management as a common test object and sets out requirements on the written engagement, the involvement of data protection and employee representatives, test depth, report structure, criticality levels and the repeat cycle.

ISO/IEC · 2022

ISO/IEC 27002:2022 – Information security, cybersecurity and privacy protection – Information security controls

Provides the implementation guidance for the 14 physical controls (7.1 to 7.14) that Annex A of ISO/IEC 27001:2022 lists as A.7.

ISECOM (Institute for Security and Open Methodologies) · 2010

OSSTMM 3 – The Open Source Security Testing Methodology Manual

Lists Human and Physical as separate testing channels of the Physical Security (PHYSSEC) class and requires quantitatively measurable, consistent and repeatable test results without subjective interpretation.

IEEE Symposium on Security and Privacy (Tischer et al.) · 2016

Users Really Do Plug in USB Drives They Find

Field study with 297 dropped USB drives: estimated success rate 45 to 98 percent, first drive plugged in after less than six minutes.

IEEE Symposium on Security and Privacy (S&P '09) – Garcia et al., Radboud University Nijmegen · 2009

Wirelessly Pickpocketing a Mifare Classic Card

Shows four attacks that require only radio contact with the card; the most serious one reconstructs a 48-bit CRYPTO1 sector key in under a second on off-the-shelf hardware and allows the card to be copied immediately.

Physical protective measures put to the test?

We assess sites, scenarios and framework conditions together with you and clarify in an initial conversation which test scope and which rules of engagement make sense for you.