A.7.4 A.7 · Physical Controls New in 2022

A.7.4 — Physical security monitoring

Continuously monitor premises for unauthorised physical access.

Also written as A7.4, Annex A 7.4, ISO 27001:2022 A.7.4, ISO27001 A.7.4.

What ISO 27001 A.7.4 requires

Physical security monitoring is one of 14 Physical Controls in ISO/IEC 27001:2022 Annex A. Continuously monitor premises for unauthorised physical access. Physical controls are usually verified by walkthrough as well as by document review, so what an auditor observes on site has to match what the procedure claims — badge logs and visitor records are the standard corroboration.

Audit evidence assessors look for

When preparing your Statement of Applicability (SoA) for A.7.4, gather artefacts such as:

  • CCTV or surveillance system installation and configuration records
  • Footage retention policy
  • Intrusion detection system (IDS) alert logs
  • Regular monitoring review or response-time records

How A.7.4 maps to SOC 2 and NIST CSF

If you run more than one framework, the same evidence usually satisfies all of them. A.7.4 aligns with:

SOC 2: CC6.4 Physical access restriction, CC7.2 Anomaly and security event monitoring

NIST CSF 2.0: PR.AA-06 Physical access management, DE.CM-02 Physical environment monitoring

ISO 27001:2013 mapping

A.7.4 is a new control introduced in the 2022 revision with no direct 2013 equivalent. Treat it as a fresh requirement when transitioning from ISO 27001:2013.

Map A.7.4 to NIST CSF & SOC 2 →
Crosswalk this control in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against A.7.4 in the Risk Register.

Related Annex A controls

A.7.1 Physical security perimeters A.7.2 Physical entry A.7.3 Securing offices, rooms and facilities A.7.6 Working in secure areas A.7.7 Clear desk and clear screen A.7.8 Equipment siting and protection

See all 14 Physical Controls →

Frequently asked questions

Is ISO 27001 A.7.4 mandatory?

Annex A controls are not mandatory in the abstract. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify, in the Statement of Applicability, any control you exclude. If your risk assessment surfaces a risk that A.7.4 addresses, excluding it needs a documented, risk-based rationale that an auditor will test.

How do auditors test ISO 27001 A.7.4?

In two passes. First design: does a documented control exist, is it owned, and does it address the risk? Then operating effectiveness: the auditor samples records from across the audit period to confirm the control actually ran. A Stage 2 audit will typically pull several samples, so evidence that only exists for the month before the audit is a common finding.

How often should A.7.4 be reviewed?

ISO 27001 sets no fixed interval — it requires review at "planned intervals" and after significant change. Annual review is the norm most certification bodies expect, with an out-of-cycle review triggered by incidents, major system changes, restructures, or new regulatory obligations. Record the review date and outcome either way; an undated control is treated as unreviewed.

What does ISO 27001 A.7.4 map to in SOC 2 and NIST CSF?

A.7.4 aligns with SOC 2 CC6.4, CC7.2 and NIST CSF PR.AA-06, DE.CM-02. Evidence gathered for one framework will usually satisfy the others, which is the basis for a test-once, satisfy-many control library.

Is A.7.4 a new control in ISO 27001:2022?

Yes. A.7.4 is one of the 11 controls introduced in the 2022 revision and has no direct ISO 27001:2013 equivalent, so a transitioning ISMS has no prior evidence to re-point and should treat it as a fresh implementation.