ACCESS CONTROL — PHYSICAL AND DIGITAL
Access control for critical-infrastructure operators
Who entered, which room or system, who approved it, when it was reviewed and when it was revoked. One record that serves the CIP officer, the cybersecurity delegate and the DPO. What fails is rarely the door: it is producing the evidence.
- Colbún
- GTD
- Enel
- Caja Los Héroes
One record, three regulators.
| Obligation | Control in Octoberus | Evidence produced | Frequency |
|---|---|---|---|
| CIP-006 R1.8 — log each individual’s entry with identity, date and time1 | Every opening (card, QR, fingerprint, plate, Google Wallet) creates an event with a photo or video of the access point. | Exportable log (CSV) per facility, zone, door and user. | Continuous |
| CIP-006 R1.9 — retain physical access logs at least 90 days1 | Retention configurable per client; 90-day minimum, with a documented deletion policy for Law 21,719. | Retention policy + deletion log. | Permanent |
| CIP-006 R1.5 / R1.7 — alert unauthorised access within 15 minutes1 | Door, tamper and REX sensors raise a security alert with state and owner. | Alert history with detection and closure times. | Per event |
| CIP-004 R5 — revoke unescorted physical access within 24 hours1 | Permits with end date and time; immediate revocation from the platform, pushed to the door. | Change audit: who revoked, when, which doors. | ≤24 h |
| Law 21,663 — ISMS and cybersecurity delegate for OIV2 | Physical and logical access events feed the same ISMS evidence file. | Periodic access report per critical asset, signable by the delegate. | Per ISMS |
| ISO/IEC 27001:2022 A.5.15 — physical and logical access rules3 | Roles per facility and zone, permits per work type and time window. | Role matrix and dated access review. | Planned review |
| Law 21,719 — biometrics as sensitive data4 | Non-biometric alternative at every point; documented consent and purpose. | Record of processing activities for the access system. | Permanent |
From permit to evidence in five steps.
Facility and zones
We model your plant, substation or data center: facilities, zones, doors and assets, with floor plan.
Identities
People, contractors and services with one or more credentials: card, QR, fingerprint, plate or phone.
Permit
Who, where, when and for which job. With safety approval if your process requires it.
The door decides
The controller enforces the list locally: it opens without network and queues events.
Evidence
Event with photo, alert if needed, export and report for the auditor.
Physical, digital and what comes next.
Physical access
Doors, electrical rooms, control rooms, telecom vaults and hatches. Controllers that decide without network.
Digital access
Roles, MFA for admins, change audit and permissions over assets and cloud services.
AI agents and services
Module in development: non-human identities with bounded permissions and an auditable log. Waitlist open.
Frequently asked questions
Does this replace my guard company? +
No. Guards keep operating; we keep each access as verifiable evidence and alert within minutes when something is off. Many clients integrate both.
Does it work if the site loses connectivity? +
Yes. The door controller stores the credential list and events locally and syncs when the network returns.
Do you hold certification under ISO 27001 or IEC 62443? +
We do not sell our own certifications. We map our controls to NERC-CIP (the Coordinator’s standard), ISO/IEC 27001:2022 Annex A and Law 21,719, and hand you the evidence for your audit.
Where is the data stored? +
In cloud infrastructure operated by Octo, with documented retention and deletion under Law 21,719. Access logs are personal data and we treat them as such.