The organisation should own those responsibilities directly when the data center is co located or on premises. That includes provisioning physical access controls, assigning staff privileges, reviewing access logs, and ensuring disaster procedures are clear. If any third party is involved, the policy should spell out duties before contracts are signed so recovery actions do not become a dispute.
Ownership When the Facility Is Not Fully Yours
When infrastructure is co located or on premises, access control is not a shared gray area. The organisation that relies on the environment should retain direct ownership of who can enter, who can approve entry, and who can act during an incident, even if a facilities provider or hosting partner operates the building. That ownership needs to cover both routine physical security and the emergency path when something goes wrong.
Direct ownership matters because access control is only effective when the accountable party can enforce, review, and change it without waiting for a third party to interpret priorities. Physical badges, escort rules, visitor handling, and break-glass response all need a clear owner, and the owner should be the organisation whose systems and recovery objectives are at risk.
For teams formalising that boundary, the control objective is straightforward: CIS Controls v8 and NIST SP 800-207 Zero Trust Architecture both reinforce that access should be explicitly governed, limited, and continuously checked rather than assumed through location or tenancy.
What Must Be Decided Before the Contract Is Signed
The practical failure mode in co located and on premises environments is not usually a lack of policy, it is ambiguity. If the contract, service schedule, or runbook does not state who approves physical entry, who can escort responders, who can isolate systems, and who can invoke disaster procedures, recovery becomes a negotiation at the worst possible moment.
That is why the responsibility split should be documented before signature, not after an outage or facility event. The organisation should know in advance whether it owns badge issuance, log review, emergency access approval, and escalation to incident leadership, while the third party should know exactly where its responsibilities end.
- Define who can grant and revoke physical access.
- State who reviews access logs and how often.
- Document who may enter during an emergency without waiting for normal approval.
- Assign who coordinates facility actions with incident, IT, and business continuity teams.
Where the site operator controls some of these functions, the agreement should still make the organisation’s authority and evidence expectations explicit. A useful reference point for control design and accountability is the ISO/IEC 27001:2022 Information Security Management model, which treats access and operational responsibility as governed controls rather than informal practice.
Risk and Threat Considerations
Ambiguous ownership creates both security exposure and operational delay. If no one is clearly responsible for access approvals, emergency entry, or recovery actions, attackers, insiders, and even routine operational failures can exploit the confusion, and the organisation may lose time when it most needs coordinated action.
Failure mechanism: A facility partner can control the door while the organisation controls the system, but neither side can complete the full response path. That split can leave access reviews stale, emergency approvals slow, and disaster procedures unenforced.
Impact: The result can be delayed recovery, unauthorised physical access, weak auditability, and disputes over who was allowed to act during an incident. In regulated or high-availability environments, that uncertainty can also increase compliance and resilience risk.
Practical evidence suggests the broader identity and access problem is usually compounded by overpermission and weak visibility, which is why NHI Mgmt Group’s Ultimate Guide to NHIs is useful here: the same governance failure pattern that affects digital access often shows up in physical and emergency access processes.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS Control 6 — Access Control Management | Physical access ownership and review are access-control governance decisions. |
| CIS Control 17 — Incident Response Management | Emergency responsibilities and recovery roles must be preassigned and rehearsed. | |
| Recommendation — Define and enforce site access approval, review, and revocation responsibilities. Assign and test emergency access and recovery actions in the incident plan. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | The question is about who governs access rights and emergency authority. |
| RS.RP — Response Planning | Disaster procedures need prewritten ownership so recovery is not delayed. | |
| Recommendation — Establish accountable access governance for facility entry and emergency actions. Document and exercise recovery responsibilities before an incident occurs. | ||
| NIST Zero Trust (SP 800-207) | 5.2 — Access to Resources is Determined by Policy | Access decisions should be policy-driven, not implied by location or tenancy. |
| 4.1 — Zero Trust Planning | Zero Trust requires clearly defined control ownership across boundary conditions. | |
| Recommendation — Set explicit policy for physical access and emergency entry decisions. Assign clear control ownership across co-located and third-party environments. | ||
Practitioner Guidance
What to verify: Confirm that the contract, site runbook, and incident plan all say who owns access approvals, log review, escorting, emergency entry, and post-incident evidence retention. If any of those are split across teams, the handoff needs to be explicit enough that another operator can execute it without interpretation.
Decision rule: If a third party is involved in the facility, treat emergency authority as a pre-negotiated control, not an improvised response. If the organisation cannot directly direct or audit the response path, assume the control is weaker than it appears and close the gap before the site is relied on for production recovery.
Practitioner takeaway: Physical hosting does not transfer accountability, it only changes who executes parts of the control. The organisation should own the decision rights, the evidence trail, and the recovery authority even when a partner owns the building.
Related resources from NHI Mgmt Group
- When should organizations review access controls?
- What is the difference between securing data center infrastructure on-premises and in a cloud-hosted environment?
- Who should own cloud logging coverage when the provider controls the platform but customers own their data and access decisions?
- How should organisations implement segregation of duties across access, change, and data management workflows?