Physical security failures account for a significant share of enterprise data breaches yet most ISO 27001 implementations treat physical controls as an afterthought behind firewalls and access policies. The 2022 revision of ISO/IEC 27001 restructured this entirely. Annex A.7 now consolidates all physical and environmental security requirements into a dedicated control domain, covering everything from perimeter fencing to clear desk policies to equipment disposal.
For US organizations pursuing ISO 27001 certification or aligning with NIST CSF 2.0, CMMC 2.0, or HIPAA physical safeguard requirements this control domain deserves far more attention than a checklist. This guide covers every Annex A.7 control in practical depth, including how they map to US regulatory frameworks and what auditors actually look for.
What Annex A.7 Actually Covers (And Why the 2022 Revision Changed Everything)
The original ISO 27001:2013 standard spread physical and environmental controls across two domains: A.11 (physical and environmental security) and scattered references throughout. The 2022 revision collapsed these into a single, coherent Annex A.7 domain titled “Physical Controls,” containing 14 distinct controls.
This restructuring reflects how physical and logical security have converged. A server room isn’t just a room anymore it’s an access-controlled, climate-monitored, CCTV-surveilled environment that generates its own audit logs. The 2022 controls acknowledge this by treating physical security as a system rather than a set of individual barriers.
Annex A.7 breaks down as follows:
A.7.1 – Physical security perimeters
A.7.2 – Physical entry controls
A.7.3 – Securing offices, rooms, and facilities
A.7.4 – Physical security monitoring
A.7.5 – Protecting against physical and environmental threats
A.7.6 – Working in secure areas
A.7.7 – Clear desk and clear screen
A.7.8 – Equipment siting and protection
A.7.9 – Security of assets off-premises
A.7.10 – Storage media
A.7.11 – Supporting utilities
A.7.12 – Cabling security
A.7.13 – Equipment maintenance
A.7.14 – Secure disposal or re-use of equipment
For US organizations, NIST CSF 2.0’s “Protect” function maps directly to the majority of these controls, particularly under the PR.AC (Identity Management and Access Control) and PR.IP (Information Protection Processes and Procedures) categories. CMMC 2.0 Level 2 includes Physical Protection (PE) practices that align one-to-one with A.7.1 through A.7.6.
Physical security is only effective when employees understand and follow security responsibilities, making ISO 27001 people controls a critical complement to Annex A.7 requirements
Designing Physical Security Perimeters That Pass Annex A.7.1 Scrutiny
A.7.1 requires organizations to define and implement security perimeters that protect areas containing sensitive information and information processing facilities. The control is deceptively simple in description — in practice, it demands documented rationale for every perimeter boundary and evidence that each zone provides appropriate protection for the assets within it.
The key concept is zoned perimeter design. Rather than treating a building as either “inside” or “outside,” a mature physical security architecture defines multiple concentric zones:
Outer perimeter – Property boundary, parking lot access, building entry points. Controls here include fencing, security lighting, vehicle barriers, and reception/guard presence. For high-security environments, mantrap vestibules replace single-door entry.
Inner perimeter – The building envelope itself. Badge readers, visitor management systems, and CCTV coverage are standard. ISO 27001 auditors will ask whether access logs are retained and reviewed.
Secure areas – Server rooms, network operations centers, document archives, executive areas. These require stronger access control (biometrics or two-factor physical access), environmental monitoring, and restricted visitor access with escort requirements.
For US federal contractors under CMMC 2.0, the Physical Protection domain (PE.L1-3.10.1) requires organizations to “limit physical access to organizational systems to authorized users.” The documentation requirements are nearly identical to A.7.1: access authorization lists, physical access logs, and review procedures.
One frequently missed element: perimeter definitions must be documented in your ISMS scope and risk assessment, not just implied by existing locks and cameras. Auditors look for a formal perimeter map that matches the physical reality of the site.
Physical Entry Controls: What A.7.2 Requires Beyond a Badge Reader
Badge readers alone do not satisfy A.7.2. The control requires organizations to control access at all physical entry and exit points, with methods appropriate to the security classification of the area being protected.
The 2022 standard explicitly calls out several elements that many organizations implement inconsistently:
Visitor management: Visitors must be identified, their access must be authorized in advance or by an authorized escort, and their presence must be logged with entry and exit times. For US healthcare organizations under HIPAA, the Physical Safeguards rule (45 CFR §164.310) includes the same requirement under “Facility Access Controls.”
Tailgating controls: Physical access logs are meaningless if five people badge through a single card swipe. Anti-tailgating measures turnstiles, mantraps, staff awareness training must address this gap. During ISO 27001 audits, certification bodies routinely test this during site visits by attempting to follow authorized personnel through access-controlled doors.
Access revocation speed: A.7.2 requires timely revocation of physical access rights when employment ends or roles change. The standard does not define “timely,” but most certification bodies expect same-day revocation for terminations involving sensitive areas.
Key management: Physical keys, combinations, and access cards must be tracked. Lost key/card procedures must be documented and tested. This is an area where organizations frequently have informal practices that don’t survive audit scrutiny.
A practical benchmark: NIST SP 800-53 PE-3 (Physical Access Control) requires organizations to enforce physical access authorizations, maintain access logs, and review them at a defined frequency. Implementing PE-3 thoroughly puts an organization well ahead of A.7.2 minimum requirements.
To understand where physical controls fit within the wider information security framework, review the ISO 27001 Annex A controls list, which explains all 93 controls across organizational, people, physical, and technological domains
Securing Offices, Rooms and Facilities: A.7.3 and A.7.6 in Practice
A.7.3 and A.7.6 work together. A.7.3 addresses how physical spaces are secured against unauthorized access and environmental risk. A.7.6 addresses how people behave inside those secure areas once they’re in.
Space-level security design (A.7.3)
The placement of sensitive operations matters. Server rooms shouldn’t share walls with parking structures. Reception areas shouldn’t have line-of-sight into executive meeting rooms. Document processing areas shouldn’t be visible from public corridors. These seem obvious when stated plainly they’re routinely overlooked in office planning decisions.
ISO 27001 auditors assess whether the physical design of facilities aligns with the security classification of the work performed there. An organization handling US government contract data under CMMC requirements cannot have cleared personnel working in open-plan offices adjacent to visitor areas without additional controls.
Key design elements auditors examine:
- No visible signage indicating server room, NOC, or data center locations
- Walls, floors, and ceilings of secure areas extend to the structural boundary (not drop-ceiling tiles that anyone in the adjacent space can lift)
- Emergency exits in secure areas are alarmed and cannot be propped open
- Environmental monitoring (temperature, humidity, water detection) with alert notifications
Behavior inside secure areas (A.7.6)
The control requires rules for working in secure areas to be designed and applied. In practice this means: no photography, no personal devices unless specifically authorized, no unescorted visitors, clean desk enforcement before leaving, and clear supervision of contractors or maintenance workers.
For US defense contractors, CMMC 2.0’s PE.L2-3.10.3 (“Escort visitors and monitor visitor activity”) directly mirrors A.7.6’s escort requirements. Organizations that treat these as separate compliance exercises are doubling their documentation burden unnecessarily.
Physical Security Monitoring and Threat Protection: A.7.4 and A.7.5
Physical security monitoring (A.7.4) and protection against physical threats (A.7.5) address two distinct but related concerns: detecting unauthorized access or anomalous activity, and defending against environmental and deliberate physical threats.
Monitoring requirements (A.7.4)
CCTV coverage of entry/exit points, secure areas, and equipment rooms is the baseline expectation. But A.7.4 goes further it requires that monitoring actually be reviewed. A camera system that records without anyone watching is worth considerably less than one with defined review procedures, alert triggers, and incident response protocols.
ISO 27001 auditors will ask:
- What is the retention period for CCTV footage? (Most organizations target 30–90 days; some regulatory frameworks specify minimums)
- How quickly are alerts from intrusion detection systems escalated?
- Are monitoring procedures documented and tested?
- Who has access to monitoring footage, and is that access controlled?
Environmental and physical threat protection (A.7.5)
This control addresses physical threats that aren’t human intruders: fire, flood, earthquake, extreme temperature, power failure, and deliberate physical damage. For US organizations, this intersects directly with NIST SP 800-53’s PE-13 (Fire Protection), PE-14 (Temperature and Humidity Controls), and PE-18 (Location of Information System Components).
Practical measures A.7.5 expects:
- Fire suppression systems appropriate for the environment (gas suppression in server rooms, not water sprinklers)
- UPS and generator backup for critical systems, with documented and tested failover procedures
- Flood/water damage prevention for basement or ground-floor data centers
- Regular testing of environmental monitoring alerts
- Business impact analysis documentation that identifies which physical facilities are critical
A frequently overlooked A.7.5 element: location selection. Organizations planning new facilities should document a risk assessment that considers natural disaster exposure, proximity to industrial hazards, and neighborhood crime rates. For US organizations in hurricane zones or flood plains, this risk assessment becomes part of the ISO 27001 evidence package.
Clear Desk and Clear Screen Policy: Why A.7.7 Is More Than a Housekeeping Rule
A.7.7 gets dismissed as administrative tidiness. It isn’t. The clear desk and clear screen control directly addresses one of the most persistent and underappreciated physical security risks in modern organizations: the accidental or opportunistic exposure of sensitive information.
The scope of A.7.7 is broader than most organizations realize:
Clear desk – Paper documents containing sensitive information should not be left unattended on desks. This applies to printed reports, sticky notes with credentials, contracts with client data, and anything else that someone walking by (a visitor, a cleaning crew member, a colleague from another department) could photograph or read.
Clear screen – Computers should lock automatically after a short period of inactivity. Screen privacy filters should be used in open-plan environments where screens face walkways. Sensitive information should not be visible on screens in video calls where the background isn’t controlled.
Printers and copiers – Sensitive documents left in printer output trays are a common source of data exposure. Secure print release requiring badge authentication at the device before printing addresses this. Organizations without this capability need compensating controls and documented procedures.
For US organizations subject to SOC 2 Type II audits, the CC6.4 control (Logical and Physical Access Controls) explicitly addresses clear desk/screen as a component of physical security. Examiners review evidence that the policy exists, training has been delivered, and periodic spot checks or audits are conducted.
The enforcement gap is where most organizations stumble. Having a clear desk policy in an employee handbook is insufficient evidence for ISO 27001 certification. Auditors look for training records, supervisor enforcement procedures, and at least some documented evidence of policy compliance checks.
Equipment Security: A.7.8 Through A.7.14 as an Integrated System
Seven of Annex A.7’s fourteen controls address equipment specifically its placement, off-site use, storage media, supporting utilities, cabling, maintenance, and disposal. Taken together, they define a complete equipment security lifecycle.
Equipment siting and protection (A.7.8)
Equipment must be positioned to minimize risks from environmental hazards and unauthorized access. In practice: servers shouldn’t sit under water pipes, UPS units need adequate ventilation, workstations in reception areas need screen positioning to prevent visual eavesdropping, and mobile devices shouldn’t be left visible in vehicles.
Off-premises asset security (A.7.9)
Laptops, phones, storage media, and other portable equipment carry the same risks off-premises as on often more. A.7.9 requires controls appropriate to the exposure: full-disk encryption, remote wipe capability, VPN enforcement for network access, and a documented authorization process for which assets can leave the premises.
For US government contractors, the CMMC 2.0 PE.L2-3.10.5 control (“Protect and monitor the physical facility and support infrastructure”) extends to mobile assets used in government work. NIST SP 800-171 3.10.5 includes the same requirement.
Storage media controls (A.7.10)
Removable storage media USB drives, external hard disks, optical media require formal management: an inventory of authorized media, controls preventing unauthorized media from being connected to systems, and documented procedures for media containing sensitive data.
Many US organizations have moved to blocking removable media at the endpoint level (DLP tools, USB port controls). This is a valid technical implementation of A.7.10, but it still requires documentation: the policy rationale, exception procedures, and audit evidence that the blocking controls are functioning.
Supporting utilities (A.7.11)
Power, HVAC, water, and other utilities supporting information processing must be protected from failure and interference. This means UPS for servers, generator backup for facilities, documented redundancy arrangements, and tested failover. The testing requirement is often where organizations fall short auditors want evidence of actual failover tests, not just assertions that the generator exists.
Cabling security (A.7.12)
Network and power cabling must be protected from interception or damage. Exposed cabling in drop ceilings, unlocked wiring closets, and network ports in public areas are common findings. Cabling should be marked and documented, with structured cabling diagrams maintained as part of the ISMS asset inventory.
Equipment maintenance (A.7.13)
Equipment must be correctly maintained to ensure availability and integrity. Maintenance contracts, scheduled servicing records, and authorization controls for who can service equipment are the minimum evidence requirements. External maintenance personnel represent a physical access risk A.7.13 intersects with A.7.6 on supervision requirements.
Secure disposal (A.7.14)
This is where many organizations’ physical security programs have their most significant gap. Hard drives and storage media in end-of-life equipment must be sanitized or destroyed before disposal or reuse. The standard accepts multiple approaches: overwriting (to NIST SP 800-88 standards), degaussing, or physical destruction.
For US healthcare organizations under HIPAA, the Security Rule requires covered entities to have policies and procedures addressing the final disposition of electronic PHI which directly maps to A.7.14. Third-party disposal vendors should provide certificates of destruction. Those certificates belong in the ISMS evidence package.
US Regulatory Alignment: How Annex A.7 Maps to NIST, HIPAA, CMMC and FedRAMP
One of the practical advantages of implementing Annex A.7 thoroughly is the cross-framework coverage it provides. US organizations typically face multiple regulatory requirements simultaneously and a well-documented physical security program can serve as evidence across all of them.
| Annex A.7 Control | NIST CSF 2.0 | NIST SP 800-53 | CMMC 2.0 | HIPAA Physical Safeguards |
|---|---|---|---|---|
| A.7.1 Perimeters | PR.AC-2 | PE-3, PE-18 | PE.L2-3.10.1 | Facility Access Controls |
| A.7.2 Entry Controls | PR.AC-2 | PE-3 | PE.L2-3.10.2 | Facility Access Controls |
| A.7.3 Offices/Rooms | PR.AC-2 | PE-18 | PE.L1-3.10.1 | – |
| A.7.4 Monitoring | PR.AC-2, DE.CM-2 | PE-6 | PE.L2-3.10.4 | – |
| A.7.5 Threat Protection | PR.IP-1 | PE-13, PE-14 | – | – |
| A.7.7 Clear Desk/Screen | PR.AC-4 | AC-11, MP-4 | – | – |
| A.7.9 Off-Premises | PR.AC-3 | PE-17 | PE.L2-3.10.5 | – |
| A.7.10 Storage Media | PR.DS-3 | MP-4, MP-5 | MP.L2-3.8.3 | Device and Media Controls |
| A.7.11 Utilities | PR.IP-1 | PE-9, PE-10, PE-11 | – | – |
| A.7.14 Secure Disposal | PR.DS-3 | MP-6 | MP.L1-3.8.2 | Device and Media Controls |
This mapping has practical implications for US organizations:
For FedRAMP authorization: The Physical and Environmental Protection (PE) control family in NIST SP 800-53 maps comprehensively to A.7. Organizations pursuing FedRAMP Moderate or High authorization that have already implemented A.7 controls can leverage their existing ISMS documentation directly.
For CMMC 2.0 Level 2: The Physical Protection domain includes six practices, all of which align to A.7 controls. Organizations that have completed ISO 27001 certification will find CMMC Level 2 assessment for physical protection largely redundant the evidence base is the same.
For HIPAA-covered entities: The Physical Safeguards standard (45 CFR §164.310) includes four required specifications and three addressable ones. A.7.1, A.7.2, A.7.9, and A.7.14 cover the required specifications; A.7.3, A.7.6, and A.7.10 address the addressable ones. Integrated implementation eliminates duplicate documentation overhead.
Implementation Roadmap: Building a Physical Controls Program That Passes Certification
Organizations approaching physical controls implementation for the first time should resist the temptation to treat it as a facilities management exercise. Physical security for ISO 27001 is an information security program it needs risk-based prioritization, documented controls, evidence collection, and ongoing review.
Phase 1: Asset and facility mapping (Weeks 1–3)
Start with a complete inventory of physical locations, facilities, and the assets within them. This means identifying every location where information is processed, stored, or transmitted — including home offices if remote work is in scope. Map each location against the sensitivity of the information handled there. This becomes your perimeter definition for A.7.1.
Phase 2: Risk assessment for physical controls (Weeks 3–6)
Conduct a physical security risk assessment for each location type. Common risks to assess:
- Unauthorized physical access (insider and external)
- Natural disasters (location-specific: flood, earthquake, hurricane, tornado)
- Power and utility failure
- Equipment theft
- Shoulder surfing and visual eavesdropping
- Tailgating and social engineering at entry points
- Media theft or improper disposal
The outputs of this risk assessment drive control selection and implementation priority.
Phase 3: Gap analysis against A.7 controls (Weeks 4–7)
Compare current physical controls against each of the 14 A.7 requirements. Document what exists, what’s partially implemented, and what’s absent. Many organizations find that controls exist in practice but lack the documentation that ISO 27001 certification requires.
Phase 4: Control implementation (Weeks 7–16)
Prioritize gaps by risk level. High-risk gaps (inadequate access controls for server rooms, no secure disposal procedure, unmonitored entry points) get addressed first. Lower-risk gaps (clear desk policy documentation, cabling diagrams) can follow.
Document everything as you implement. ISO 27001 certification requires evidence of controls operating effectively, not just policies describing intended controls.
Phase 5: Testing and internal audit (Weeks 16–20)
Test controls before the certification audit finds gaps. Physical penetration testing attempting to enter secure areas using social engineering, tailgating, or stolen credentials reveals weaknesses that paper-based reviews miss. Internal audits of clear desk compliance, access log reviews, and equipment disposal records provide pre-audit evidence.
Ongoing: Continuous monitoring
Physical security isn’t static. Personnel changes, facility modifications, new equipment, and evolving threats require periodic review. Build physical security reviews into your ISMS management review cycle (required annually under clause 9.3) and incident management process.
What Certification Body Auditors Actually Find: Common A.7 Nonconformities
Based on consistent patterns in ISO 27001 audit reports, physical security generates a predictable set of findings. Knowing what auditors look for allows organizations to address gaps before the certification audit.
Most frequently cited A.7 nonconformities:
1. Undocumented perimeter boundaries: Physical perimeters exist but aren’t formally defined in ISMS documentation. Auditors need to see a perimeter map or formal description, not just physical barriers they can observe.
2. Access logs that aren’t reviewed: Badge reader logs are collected but no one reviews them. A.7.2 requires periodic review of access records “periodic” should be defined, and review evidence should be retained.
3. Visitor management gaps: Visitor logs are informal, incomplete, or paper-based with no retention procedure. Some organizations log entry but not exit times. Escort procedures exist in policy but aren’t consistently followed in practice.
4. No secure disposal records: Equipment is disposed of or repurposed without documented sanitization. Certificates of destruction from vendors aren’t retained. This is one of the most common A.7.14 findings and carries significant risk.
5. Clear desk policy without enforcement evidence: The policy exists in the employee handbook, but there’s no training record, no compliance check record, and no enforcement mechanism.
6. Environmental monitoring gaps: Temperature and humidity sensors are installed but alerts aren’t configured, or alert notifications go to an unmanned inbox.
7. Cabling and wiring closet security: Network switches and patch panels in unlocked closets, network ports in public areas, or unapproved devices plugged into network infrastructure.
8. Off-premises equipment without risk assessment: Laptops leave the premises without documented authorization, encryption verification, or remote wipe capability.
Building ISO 27001 Expertise: The GAICC Certification Path
Understanding Annex A.7 at the implementation level not just as a checkbox list requires trained professionals who can assess risks, design controls, and build evidence that satisfies certification auditors. That’s the practical skill gap most organizations discover when they begin their ISO 27001 journey.
GAICC’s ISO 27001 certification programs are designed for exactly this stage. The Lead Implementer certification covers the full ISMS implementation lifecycle, including physical controls program design, risk assessment methodology, evidence documentation, and internal audit preparation. For organizations at earlier stages, the Foundation certification provides the framework literacy that makes A.7 controls meaningful rather than mechanical.
For professionals already working in GRC, compliance, or information security roles, GAICC’s ISO 27001 credentials provide the implementation depth that differentiates practitioners who can lead certification projects from those who can only describe them.
Frequently Asked Questions: ISO 27001 Physical Controls
What is the difference between A.7 in ISO 27001:2013 and ISO 27001:2022?
The 2013 standard covered physical security across two Annex A domains (A.11 and parts of A.9). The 2022 revision consolidated all physical controls into Annex A.7 with 14 specific controls. The 2022 structure also adds explicit requirements for physical security monitoring (A.7.4) and clearer guidance on off-premises equipment security (A.7.9) both areas that were underspecified in the earlier version.
Do ISO 27001 physical controls apply to remote workers and home offices?
Yes, if remote work locations are within the ISMS scope. Organizations must assess physical security risks in home office environments, including clean desk practices, screen privacy, equipment storage, and printer security. The controls implemented can be lighter than those for corporate facilities but they must be risk-based and documented. Many organizations address this through a Remote Working Policy that incorporates A.7 requirements.
How often should physical access logs be reviewed under ISO 27001?
The standard doesn’t specify a frequency, but certification bodies typically expect at least monthly review for sensitive areas like server rooms, with more frequent review for anomalous access patterns. Review frequency should be documented in your physical security procedures and justified by your risk assessment. The key evidence requirement is that reviews actually happen and that findings are acted on.
What does ‘secure disposal’ require under A.7.14 for hard drives and storage media?
A.7.14 accepts several approaches: overwriting to NIST SP 800-88 standards (Purge or Clear, depending on media type and sensitivity), degaussing, or physical destruction. For cloud storage, documented contractual obligations from the cloud provider regarding data deletion satisfy the intent. For high-sensitivity data, physical destruction with a certificate from an accredited vendor is the most defensible approach.
Can ISO 27001 physical control documentation also satisfy CMMC 2.0 Physical Protection requirements?
In most cases, yes. The six CMMC 2.0 Level 2 Physical Protection practices align closely with A.7.1 through A.7.6. Organizations that have documented their physical security controls for ISO 27001 certification including access authorization lists, visitor logs, escort procedures, and monitoring records will find those same documents serve as evidence for CMMC 2.0 Physical Protection practices.
What’s the biggest physical security gap certification auditors find in US organizations?
Secure disposal of equipment (A.7.14) is consistently among the top findings. Organizations frequently lack documented procedures for sanitizing hard drives before disposal or reuse, don’t retain certificates of destruction from third-party vendors, and haven’t extended their disposal procedures to cover cloud-provisioned instances and virtual machines that have been decommissioned.
How does HIPAA’s Physical Safeguard requirement relate to ISO 27001 A.7?
HIPAA’s Physical Safeguards standard (45 CFR §164.310) and ISO 27001 Annex A.7 cover overlapping ground. Facility Access Controls (HIPAA) align with A.7.1 and A.7.2. Workstation Use and Security map to A.7.7 and A.7.8. Device and Media Controls map to A.7.10 and A.7.14. Healthcare organizations that implement A.7 thoroughly can use the same documented evidence for both HIPAA compliance and ISO 27001 certification.
The Physical Foundation of Information Security
Physical controls are the foundation that every other layer of information security depends on. A perfectly configured firewall means nothing if an unauthorized person can walk into the server room. A strong access management policy fails if terminated employees retain physical building access.
Organizations that treat Annex A.7 as genuine security architecture rather than a compliance checklist emerge with facilities that are materially harder to compromise and documentation that satisfies auditors across ISO 27001, CMMC, HIPAA, and NIST frameworks simultaneously. The implementation investment pays dividends across every framework an organization operates under.
If your organization is building toward ISO 27001 certification and needs structured guidance on physical controls implementation, GAICC’s ISO 27001 Lead Implementer program covers the full A.7 control domain in depth.

