Access Control
Physical and logical access policies, badge systems, and visitor management
Access control fails at the edges: the contractor badge that still works, the leaver whose account was disabled but whose door card was not, the visitor book that nobody fills in after the receptionist changed.
This library covers both halves, the digital and the physical, because most organisations audit one and forget the other.
What this library checks
- Badge and door access holder list, reviewed by name against current staff
- Contractor and vendor access, including expiry dates
- Visitor management process, sign-in records and escort requirements
- Joiner, mover and leaver process and the evidence that each step happened
- Periodic user access reviews with a named reviewer and a signed outcome
- Key management for anything not on the badge system
- CCTV coverage, retention period and who can retrieve footage
Evidence you will be asked for
Every check in Spectra Core carries its own evidence. These are the artefacts an auditor, insurer or board most often wants to see for this area.
- Access holder list with review date and reviewer name
- Leaver records showing both account disable and badge revocation
- Visitor log sample for the review period
Where this usually goes wrong
The leaver process is the control most likely to be documented and least likely to be complete. Accounts get disabled because IT owns that step. Door cards, alarm codes and vendor portals usually belong to somebody else.
Run this library against your environment
Every check comes with a risk level, a review frequency, an assignee and a plain-language rationale, so the output reads for leadership as well as for engineers.
Other libraries
Remote Monitoring & Management
Alerting, patching, agent health, and endpoint visibility standards
Network Environment
Switching, routing, Wi-Fi, DNS, and network segmentation checks
Active Directory Configuration
GPOs, OU structure, password policies, and domain hygiene
Network Security
Identity, access management, and endpoint protection / EDR standards
Microsoft 365 Security
Identity threat detection and response, conditional access, and tenant hardening
Backup & Disaster Recovery
On-premise DR systems and Microsoft 365 backup configuration checks