2.2 Physical and Technological Controls (Annex A Themes 7 & 8)

Key Takeaways

  • Theme 7 encompasses 14 Physical controls designed to protect physical perimeters, offices, equipment, and facilities from unauthorized access or environmental threats.
  • Theme 8 consists of 34 Technological controls, addressing digital safeguards like cryptography, access management, network security, and secure development.
  • Data leakage prevention (8.12) and Web filtering (8.9) are prominent additions in the 2022 revision, reflecting modern technological threat landscapes.
  • Physical and technological controls must be layered (defense-in-depth) to effectively secure organizational assets, ensuring physical failures are mitigated by technological safeguards and vice versa.
Last updated: July 2026

2.2 Physical and Technological Controls (Annex A Themes 7 & 8)

Transitioning from Policy to Implementation

While Organizational and People controls establish the administrative intent and behavioral expectations of an ISMS, Physical (Theme 7) and Technological (Theme 8) controls represent the concrete mechanisms deployed to protect assets. In the ISO/IEC 27001:2022 framework, these two themes account for over half of the 93 Annex A controls, reflecting the complex reality of securing modern enterprise environments. Together, they form the tangible layers of a defense-in-depth strategy, ensuring that both the physical facilities housing data and the digital systems processing it are resilient against compromise. A policy stating data must be protected is organizational; the encryption algorithm protecting the data is technological; the locked door protecting the server is physical.

Theme 7: Physical Controls

Comprising 14 controls (Controls 7.1 through 7.14), the Physical theme focuses on preventing unauthorized physical access, damage, and interference to the organization's information and information processing facilities. Despite the rapid migration to cloud services and remote work, physical security remains a foundational requirement; even cloud data centers rely heavily on these exact controls, and employee laptops represent physical assets operating outside traditional perimeters.

Physical Security Perimeters and Entry Controls (Controls 7.1 - 7.2)

An organization must define and implement physical security perimeters (7.1) to protect areas that contain sensitive information or critical infrastructure. This involves walls, card-controlled doors, fences, and reception desks. Working in tandem, Physical entry controls (7.2) ensure that only authorized personnel can pass through these perimeters.

During an audit, an auditor will not only review the policies but will physically walk the premises. They will observe if visitors are required to sign in, wear badges, and be escorted. They will check if doors designed to be locked are propped open, if tailgating is a common occurrence, and if access logs are periodically reviewed to detect anomalies.

Securing Offices, Rooms, and Facilities (Control 7.3)

Physical security extends beyond the front door. Control 7.3 requires security for internal offices and facilities. This includes considering risks from natural disasters, malicious attacks, or accidents. The auditor will assess whether critical assets, such as server rooms or archives, are placed in areas not susceptible to flooding (e.g., not in basements in flood zones), fires, or easy public view from external windows.

Clear Desk and Clear Screen (Control 7.7)

A highly visible and commonly audited control is the clear desk and clear screen policy. This control mitigates the risk of unauthorized access to information left on desks (paper documents, removable media) or displayed on unattended computer screens. Auditors frequently conduct "walk-arounds" after business hours or during lunch breaks to verify that whiteboards are erased, sensitive documents are locked away in drawers, and workstations automatically lock after a defined period of inactivity.

Equipment Siting, Protection, and Maintenance (Controls 7.8 - 7.14)

Information processing equipment must be sited and protected to reduce the risks from environmental threats and unauthorized access (7.8). This includes preventing theft by securing equipment to desks if necessary. Furthermore, supporting utilities like power and telecommunications must be secure from failure (7.11), often requiring uninterruptible power supplies (UPS) and backup generators that are regularly tested. Cabling security (7.12) ensures network lines are not easily tapped or severed. Equipment maintenance (7.13) ensures hardware continues to function as specified. Finally, the secure disposal or reuse of equipment (7.14) is critical; auditors will demand evidence, such as destruction certificates, to prove that hard drives and other media are securely wiped or physically destroyed before leaving the organization's control or being reassigned to new users.

Theme 8: Technological Controls

Theme 8 is the second largest category, containing 34 controls (Controls 8.1 through 8.34). These controls address the digital, logical, and software-driven safeguards that protect data at rest, in transit, and in use. The 2022 update introduced several new technological controls to align the standard with contemporary cybersecurity practices and emerging threats.

Information Access Management (Controls 8.2 - 8.5)

Access control is a cornerstone of technological security. The standard requires the stringent management of privileged access rights (8.2), restricting access to information and application system functions based on business requirements (8.3), and securing access to source code (8.4). Secure authentication information (8.5), such as passwords and cryptographic keys, must be strictly managed to ensure they are not compromised.

An auditor will deeply evaluate how access is granted, modified, and revoked. They will look for the implementation of the principle of least privilege and the widespread use of Multi-Factor Authentication (MFA). A critical and common audit test involves sampling a list of recently terminated employees and verifying that their logical access to various systems, VPNs, and email accounts was revoked within the timeframe specified by the organization's policy.

Cryptography (Control 8.24)

Control 8.24 dictates that rules for the effective use of cryptography, including cryptographic key management, must be defined and implemented. This covers data encryption both at rest (e.g., full disk encryption, database encryption) and in transit (e.g., TLS for web traffic, IPsec for VPNs). Auditors will verify that weak, deprecated algorithms (like MD5 or obsolete versions of TLS) are not in use, and that encryption keys are stored securely, rotated according to policy, and protected against loss.

Modern Additions: DLP, Web Filtering, and Secure Coding (Controls 8.9, 8.12, 8.28)

The 2022 revision introduced specific controls to address modern attack vectors that were previously only implied:

  • Data Leakage Prevention (8.12): Organizations must apply DLP measures to sensitive systems and networks to detect and prevent unauthorized disclosure of information. Auditors will seek evidence of active DLP configurations, such as rules preventing the email exfiltration of documents marked 'Confidential' or blocking USB mass storage devices.
  • Web Filtering (8.9): Access to external websites must be managed to reduce exposure to malicious content. This is typically achieved through proxy servers, DNS filtering, and firewall rules blocking known malicious domains.
  • Secure Coding (8.28): Secure coding principles must be applied to software development. If the organization develops software, auditors will look for evidence of static and dynamic application security testing (SAST/DAST), peer code reviews, and adherence to frameworks like the OWASP Top 10.

Protection Against Malware, Logging, and Backups (Controls 8.7, 8.13 - 8.17)

Protection against malware (8.7) requires deploying endpoint detection and response (EDR) or traditional antivirus solutions, coupled with user awareness. Information Backup (8.13) mandates regular backups that are tested for restorability. Redundancy of information processing facilities (8.14) ensures high availability. Furthermore, robust logging (8.15) is mandatory. Event logs recording user activities, exceptions, faults, and information security events must be produced, kept, and regularly reviewed. Monitoring activities (8.16) and clock synchronization (8.17) via NTP servers ensure that when an incident occurs, the chronological sequence of events can be accurately reconstructed for forensic analysis.

The Intersection of Physical and Technological Controls

Effective security requires the seamless integration of physical and technological controls. For instance, a highly secure data center utilizes technological controls (biometric scanners, electronic access logs, CCTV tied to network storage) to enforce a physical boundary. Similarly, a technological control like full disk encryption (8.24) acts as a critical fail-safe if the physical control of equipment siting (7.8) fails and a laptop is stolen from a vehicle. When auditing an ISMS, a Lead Auditor must evaluate these controls not as isolated silos, but as a cohesive, interdependent defense architecture where weaknesses in one layer are compensated by strengths in another.

Test Your Knowledge

During an on-site audit, an auditor observes several unattended workstations displaying sensitive customer data, and finds printed payroll documents left on a printer in a common area. Which physical control is the organization failing to enforce?

A
B
C
D
Test Your Knowledge

Which newly introduced technological control in the ISO/IEC 27001:2022 revision specifically addresses the need to manage access to external websites to prevent exposure to malicious content?

A
B
C
D
Test Your Knowledge

When an auditor reviews the implementation of Control 8.17 (Clock synchronization), what is the primary security objective they are validating?

A
B
C
D