Physical security is the control layer that all other security controls depend on. An attacker with physical access to a network device can reset credentials, capture traffic, or destroy equipment in minutes. CTDISR-2025 Section 15 requires documented physical security controls at data centre and network facility locations, and auditors assess this section with the same rigour applied to logical controls.
For Pakistani ISPs, physical security at primary facilities (the main NOC, server room, or data centre co-location space) is typically more complete than at remote PoP locations, where equipment may be in a small cabinet in a building used for other purposes. Both categories are in scope for Section 15.
Access Control Requirements
Physical access to facilities that house network equipment, servers, or subscriber data must be controlled and logged. The control mechanisms must prevent unauthorised access and the logging must create a record of who entered, when, and for what purpose.
For primary facilities with permanent equipment: electronic access control (keycard, PIN pad, or biometric) is the standard that satisfies CTDISR requirements. Mechanical key-only access, while common in many Pakistani ISP facilities, does not create an access log and does not satisfy the logging requirement. If migrating from key-only to electronic access control is not immediately feasible, maintaining a manual sign-in log (dated, name, purpose, authorisation) for all access to the facility is the compensating control.
Access to the facility should be limited to employees and contractors who have a documented operational need. Maintaining a current access list, reviewed and updated quarterly and immediately when staff leave, is the procedural control that accompanies the physical control.
For remote PoP locations, the access control standard is proportionate to the equipment housed there and its criticality. A small cabinet in a co-located building may only need a physical lock with key management procedures. An unmanned PoP that houses a core router or OLT warrants the same electronic access control as a primary facility.
Visitor Management
All non-employee access to network facilities must be managed: the visitor must be registered in advance or at the time of visit, must be escorted by an authorised employee throughout the visit, and must be logged with name, organisation, purpose, entry time, and exit time.
Vendor engineers performing maintenance at ISP facilities fall under visitor management. Create a process for managing vendor access that includes: advance notification and approval, verification of identity at the facility, continuous escort during the visit, and a log entry.
The visitor log is audit evidence: an auditor who asks to see physical access records for your primary facility should be able to see a log of everyone who has entered in the past 12 months, both employees and visitors. Electronic access control systems produce this log automatically. Manual logs must be maintained consistently to be credible as evidence.
CCTV Requirements
CTDISR-2025 requires CCTV monitoring at network facilities. The practical implementation covers the entry points and the equipment areas: cameras covering the entrance, the main equipment room, and ideally the cabinet rows within the equipment room. Cameras must record continuously, not just on motion, and footage must be retained for a sufficient period to support incident investigation (30 days is a common minimum for ISP facilities).
Position cameras to capture clear images of faces at entry points and hands at equipment. A camera that captures a person entering the equipment room but cannot be used to identify the individual or see what they did to the equipment is not providing the investigative value CCTV is intended for.
Environmental Controls
Data centre and server room environmental controls (temperature, humidity, fire suppression, power conditioning) are both an operational necessity and a Section 15 requirement. The documentation requirement is the specific element that makes this a compliance item rather than just good practice: environmental controls must be documented in terms of what is installed, what the monitoring thresholds are, and what the response procedure is when a threshold is breached.
For Pakistani ISPs in the local climate, temperature control (air conditioning with redundancy or at least a backup plan for cooling failure) is the most operationally critical environmental control. UPS and generator backup for power conditioning is the second priority. Fire suppression at primary facilities is required: a clean-agent suppression system (FM-200 or similar) is appropriate for equipment rooms where water suppression would cause more damage than the fire.
For managing Section 15 evidence alongside all other CTDISR controls, ComplianceIQ maintains the physical security documentation and audit trail. For operators who want physical security reviewed as part of a broader security posture assessment, Cybersecurity for ISPs covers physical controls alongside logical controls in the same engagement.