3.4 Physical Controls (Theme 7)

Key Takeaways

  • Theme 7 encompasses 14 physical and environmental controls designed to protect facilities, equipment, utilities, and media against unauthorized physical access, theft, and natural disasters.
  • Control 7.4 (Physical Security Monitoring) introduces a mandatory requirement for continuous perimeter and interior physical surveillance via CCTV, intrusion detection systems, and alarm logging.
  • Control 7.7 (Clear Desk and Clear Screen) enforces strict physical and logical session protection to safeguard confidential paper media and unattended user workstations.
  • Control 7.14 (Secure Disposal or Re-use of Equipment) mandates certified sanitization and destruction of storage media in accordance with standards like NIST SP 800-88 before disposal.
Last updated: July 2026

ISO/IEC 27001:2022 Theme 7: Physical Controls

Auditor Focus: Theme 7 comprises 14 controls (Controls 7.1 through 7.14) that establish defense-in-depth physical security zones around organizational assets. Lead auditors must conduct on-site physical inspections, evaluate environmental redundancy, review access logs, and verify media sanitization processes.


1. Physical Security Defense-in-Depth Architecture

Physical security relies on concentric layers of security zones. An attacker must breach multiple independent physical controls to reach sensitive assets (such as core data centers or hardware security modules).

+-----------------------------------------------------------------------------------+
|                    PHYSICAL DEFENSE-IN-DEPTH CONCENTRIC ZONES                     |
+-----------------------------------------------------------------------------------+
|  ZONE 1: PERIMETER       ---> Fencing, Gates, Bollards, Exterior CCTV (7.1, 7.4)  |
|  ZONE 2: FACILITY ENTRY  ---> Reception, Visitor Badges, Turnstiles (7.2)        |
|  ZONE 3: SECURE OFFICE   ---> Keycard Doors, Clear Desk Policy (7.3, 7.7)        |
|  ZONE 4: SERVER ROOM / DC---> Biometric Access, Rack Locks, FM200, UPS (7.5, 7.6) |
+-----------------------------------------------------------------------------------+

2. In-Depth Analysis of Theme 7 Controls

Controls 7.1 – 7.3: Physical Perimeters, Entry Controls, and Room Security

  • 7.1 Physical security perimeter: Security perimeters must be defined and used to protect areas that contain information and other associated assets (e.g., perimeter walls, card-controlled entry gates, physical security barriers).
  • 7.2 Physical entry controls: Secure areas must be protected by appropriate entry controls to ensure that only authorized personnel are allowed access.
    • Audit Evidence: Electronic badge reader access logs, visitor sign-in ledgers, government ID checks, visitor badge color-coding, and mandatory escort enforcement.
  • 7.3 Securing offices, rooms and facilities: Physical security for offices, rooms, and facilities must be designed and implemented. Server rooms must have no exterior windows, fire-rated doors, and anti-passback badge readers.

Control 7.4: Physical Security Monitoring (NEW)

Control 7.4 requires continuous monitoring of premises against unauthorized physical access.

  • CCTV Systems: Cameras positioned at all entry/exit points, server room doors, and loading docks. Auditors check video retention settings (e.g., minimum 30 to 90 days retention) and camera field-of-view obstructions.
  • Intrusion Detection Systems (IDS): Motion sensors, glass-break detectors, and door contact sensors tied to a 24/7 central monitoring station or SOC.

Control 7.5: Protecting Against Physical and Environmental Threats

  • Protection against physical and environmental threats (fire, flood, earthquake, explosion, civil unrest) must be designed and implemented.
  • Environmental Safeguards:
    • Fire Suppression: Clean-agent gas suppression systems (e.g., FM-200, Novec 1230, Inergen) that do not leave liquid residue on electronic components.
    • HVAC & Climate Control: Redundant (N+1) air conditioning units keeping data center temperatures within ASHRAE guidelines.
    • Water Detection: Raised floor moisture sensors beneath server racks and HVAC units.

Control 7.6: Working in Secure Areas

  • Special rules for working in high-security zones (e.g., clean rooms, vault facilities, core data halls). Prohibits unapproved recording devices, cameras, or mobile phones; enforces two-person integrity rules where required.

Control 7.7: Clear Desk and Clear Screen

  • Clear Desk: Sensitive physical paper documents and storage media must be locked away in fireproof cabinets when not in use.
  • Clear Screen: Unattended workstations must automatically initiate password-protected screen savers or session locks after a short period of inactivity (e.g., 5 to 10 minutes).

Controls 7.8 – 7.13: Equipment, Utilities, and Cabling Security

  • 7.8 Equipment siting and protection: Positioning server racks to reduce physical hazard risks (e.g., avoiding placement under water pipes or beneath building roof drains).
  • 7.11 Supporting utilities: Dual utility feeds, Uninterruptible Power Supply (UPS) battery banks, and backup diesel generators with guaranteed fuel delivery contracts.
  • 7.12 Cabling security: Power and telecommunications cables carrying data or supporting information services must be protected from interception, interference, or damage (e.g., armored conduits, overhead cable trays).

Control 7.14: Secure Disposal or Re-Use of Equipment

  • Items of equipment containing storage media must be verified to ensure that any sensitive data and licensed software has been removed or securely overwritten prior to disposal or re-use.
  • Sanitization Standards: Compliance with NIST SP 800-88 Guidelines for Media Sanitization (Clear, Purge, Destroy).
  • Auditor Verification: Inspecting Certificates of Destruction issued by certified e-waste recycling vendors, verifying matching hard drive serial numbers.

3. Physical Security Zonal Defense & Audit Checklist

Inspection AreaApplicable ControlsMandatory Physical Inspection PointsCommon Nonconformities
Building Exterior7.1, 7.4CCTV coverage of perimeter, gate locks, perimeter lighting, barrier integrity.Blind spots in CCTV coverage; unmonitored rear delivery doors left propped open.
Reception / Lobby7.2Visitor logbook accuracy, visitor badge issuing, escort sign-in, turnstiles.Unescorted visitors walking past reception; blank visitor badges left unattended.
Server Room / Data Center7.3, 7.5, 7.6, 7.11Biometric access, FM-200 pressure gauges, UPS battery test logs, N+1 HVAC, cable conduits.Storage of combustible cardboard boxes in server rooms; expired fire suppression inspection tags.
Open Office Floor7.7Unlocked screens on unattended desks, sensitive documents left on printers, clear desk compliance.Unlocked laptops with active admin sessions while employees are at lunch; printed payroll on shared trays.
Media Storage & E-Waste7.10, 7.14Locked media safes, degaussers, media sanitization logs, Certificates of Destruction.Scrapped hard drives stored in unlocked bins awaiting disposal without serial number verification.

4. Lead Auditor Worked Scenario

Scenario Background

Lead Auditor Vikram is conducting an on-site Stage 2 audit at AeroSpace Components Corp, a manufacturer of defense components certified under ISO/IEC 27001. Vikram is inspecting the primary facility housing corporate servers, R&D labs, and executive offices.

Physical Inspection & Audit Evidence Gathering

  1. Data Center Physical Walkthrough (Controls 7.3, 7.4, 7.5, 7.11):

    • Vikram enters the primary server room using biometric access.
    • Observation A: Inside the server room, Vikram notes 15 large cardboard shipping boxes filled with spare parts stacked directly against server racks containing defense schematics.
    • Observation B: Inspecting the FM-200 gas fire suppression system, Vikram reviews the maintenance tag attached to the cylinder. The last certified inspection date was 18 months ago (annual inspection required).
    • Observation C: Vikram tests the CCTV monitoring system (7.4) and requests the past 30 days of video footage for the server room door. The security manager states that the DVR hard drive failed 2 weeks ago and video recording has been offline since.
  2. Clear Desk & Media Disposal Walkthrough (Controls 7.7 & 7.14):

    • During lunch hour, Vikram walks through the R&D engineering floor. He observes 4 unattended engineering workstations with active CAD models displayed on screens without screen locks.
    • In the disposal staging room, Vikram finds a box of 12 decommissioned magnetic hard drives marked for recycling. No serial number logging or Certificates of Destruction were recorded.

Nonconformities Issued by Vikram

  • Major Nonconformity against Control 7.4 & Clause 8.1 (Physical Security Monitoring): Physical security surveillance of the primary server room had been completely non-functional for 14 days due to unmonitored DVR failure, leaving high-security assets without physical intrusion detection.
  • Minor Nonconformity against Control 7.5 (Environmental Threats): Combustible cardboard materials stored inside the server room and an overdue annual fire suppression maintenance tag increase fire risks to information assets.
  • Minor Nonconformity against Control 7.7 (Clear Screen): Multiple unattended workstations in the R&D department failed to initiate automatic session locks, exposing confidential CAD files to unauthorized physical viewing.
  • Minor Nonconformity against Control 7.14 (Equipment Disposal): Decommissioned storage media were staged for disposal without serial number tracking or verification of media sanitization in accordance with NIST SP 800-88.
Test Your Knowledge

Control 7.4 (Physical security monitoring) requires continuous surveillance of sensitive areas. Which audit evidence best proves compliance for a high-security server room?

A
B
C
D
Test Your Knowledge

During a physical site inspection of a data center, an ISO 27001 lead auditor notices several stacks of empty cardboard boxes stored inside the main server room next to power distribution units. Which control is violated?

A
B
C
D
Test Your Knowledge

An organization disposes of 50 obsolete laptops containing historical customer data. To satisfy Control 7.14 (Secure disposal or re-use of equipment), what documentation must the lead auditor inspect?

A
B
C
D