A.7 14 controls · 1 new in 2022

ISO 27001 Physical Controls (A.7)

Fourteen controls covering secure areas, equipment, clear desk, cabling, maintenance and secure disposal.

What the Physical Controls theme covers

A.7 is the theme most often scoped down and most often scoped down badly. If you run entirely in the cloud you still cannot exclude physical controls wholesale — you inherit them from your provider, and the Statement of Applicability needs to say so and point at the provider assurance that supports the claim. For controls you do own, expect verification by walkthrough as well as document review: what the auditor sees on site has to match what the procedure claims, with badge and visitor logs as the standard corroboration.

All 14 Physical Controls

A.7.1 Physical security perimeters
Define security perimeters and use them to protect areas that contain information and information processing facilities.
A.7.2 Physical entry
Secure areas shall be protected by appropriate entry controls to ensure only authorised personnel are allowed access.
A.7.3 Securing offices, rooms and facilities
Design and apply physical security for offices, rooms and facilities.
A.7.4 Physical security monitoring New
Continuously monitor premises for unauthorised physical access.
A.7.5 Protecting against physical and environmental threats
Design and implement protection against physical and environmental threats such as fire, flood, earthquake, and other natural or man-made disasters.
A.7.6 Working in secure areas
Design and apply security measures for working in secure areas.
A.7.7 Clear desk and clear screen
Define and enforce clear desk rules for papers and removable storage media and clear screen rules for information processing facilities.
A.7.8 Equipment siting and protection
Site and protect equipment to reduce risks from environmental threats, hazards and unauthorised access.
A.7.9 Security of assets off-premises
Apply security to assets taken off-site, taking into account the different risks of working outside the organisation's premises.
A.7.10 Storage media
Manage storage media through their lifecycle of acquisition, use, transportation and disposal, in line with the classification scheme.
A.7.11 Supporting utilities
Protect information processing facilities from power failures and disruptions caused by failures in supporting utilities.
A.7.12 Cabling security
Protect power and data transmission cables from interception, interference or damage.
A.7.13 Equipment maintenance
Maintain equipment to ensure continued availability and integrity of information.
A.7.14 Secure disposal or re-use of equipment
Verify that all sensitive information and licensed software has been removed or securely overwritten prior to disposal or re-use of equipment.

Other Annex A themes

A.5 Organisational Controls A.6 People Controls A.8 Technological Controls
Crosswalk to SOC 2 & NIST CSF →
Map these controls across frameworks in the Control Mapper.
Search all 93 controls →
Filter Annex A by keyword, theme or control ID.

Frequently asked questions

How many Physical Controls are there in ISO 27001:2022?

There are 14 controls in the A.7 Physical Controls theme, of which 1 is new in the 2022 revision. Annex A defines 93 controls in total across four themes: Organisational (37), People (8), Physical (14) and Technological (34).

Do I have to implement every Physical Controls control?

No. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify any exclusion in the Statement of Applicability — it does not require you to apply all 93. What auditors test is whether the justification is risk-based and documented, not whether the count is high.

What replaced the ISO 27001:2013 domains?

The 2013 edition organised 114 controls into 14 domains (A.5–A.18). The 2022 revision restructured them into 93 controls across four themes, merging 57 and introducing 11 new ones. Each control page below lists its 2013 predecessors so you can re-point existing evidence during transition.