4.1 Physical Controls: Secure Areas & Equipment Protection (A.7.1-A.7.14)
Key Takeaways
- ISO/IEC 27001:2022 Annex A Theme 7 consolidates physical security into 14 controls focused on protecting facilities, equipment, utilities, and storage media from physical threats.
- Defense-in-depth physical security requires layered physical perimeters, anti-passback biometric access control, visitor escorts, and 24/7 CCTV surveillance with tamper protection.
- Clear desk and clear screen policies (A.7.7) enforce automated screen locks, physical document vaulting, and clean room rules to prevent unauthorized visual observation.
- Equipment disposal and re-use (A.7.14) mandates cryptographic erasure or physical destruction adhering to NIST SP 800-88 standards prior to asset decommissioning.
4.1 Physical Controls: Secure Areas & Equipment Protection (A.7.1–A.7.14)
In ISO/IEC 27001:2022, physical security is structured under Theme 7 (Physical controls), containing 14 controls (reduced and consolidated from 15 controls in the 2013 edition). Physical security forms the foundational barrier of any Information Security Management System (ISMS). Without robust physical perimeters and equipment protection, technical controls such as encryption and firewalls can be bypassed through physical intrusion, theft, wiretapping, or environmental destruction.
For a Lead Implementer, designing physical security requires evaluating physical threat vectors (unauthorized entry, natural disasters, utility failure, espionage) and integrating physical safeguards into the overall risk treatment plan.
Overview of ISO/IEC 27001:2022 Physical Controls (A.7.1–A.7.14)
Physical controls apply to all physical sites where information assets reside, including corporate headquarters, satellite offices, server rooms, data centers, manufacturing plants, and home/remote work environments.
1. Physical Security Perimeters & Entry Controls (A.7.1, A.7.2, A.7.3)
- A.7.1 Physical security perimeter: Defines physical boundaries (walls, card-gated turnstiles, fences, security guards) around areas holding confidential information or processing facilities. Outer perimeters must be physically distinct with no unmonitored entry gaps.
- A.7.2 Physical entry controls: Ensures only authorized personnel access secure areas. Implementation requires multi-factor physical authentication (e.g., RFID badge plus biometric scan), anti-passback controls, visitor registration logs, identity verification, escorted visitor protocols, and badge revocation processes.
- A.7.3 Securing offices, rooms, and facilities: Requires physical security design for internal rooms. Server rooms and key infrastructure rooms must lack external windows, feature floor-to-ceiling slab construction (to prevent intrusion via ceiling voids), and utilize reinforced locking mechanisms.
2. Physical Security Monitoring & Environmental Threats (A.7.4, A.7.5, A.7.11)
- A.7.4 Physical security monitoring: Mandates continuous surveillance of secure areas using closed-circuit television (CCTV), motion sensors, glass-break detectors, and intrusion alarm systems. Video feeds must be recorded, timestamped, stored securely, and monitored by security personnel or an automated Security Operations Center (SOC).
- A.7.5 Protecting against physical and environmental threats: Establishes protection against fire, flood, earthquake, explosion, civil unrest, and environmental hazards. Implementation includes fire detection systems, clean-agent gas suppression (e.g., FM-200, Novec 1230), water leak detection under raised floors, and seismic rack anchoring.
- A.7.11 Supporting utilities: Protects power, water, HVAC (heating, ventilation, air conditioning), and telecommunications. Requires dual redundant power feeds, Uninterruptible Power Supply (UPS) battery banks, diesel generators with automatic transfer switches (ATS), and environmental monitoring of temperature and relative humidity.
3. Working in Secure Areas & Clear Desk/Screen Policies (A.7.6, A.7.7)
- A.7.6 Working in secure areas: Controls internal activities within high-security environments (e.g., data centers, SOCs). Prohibits unauthorized cameras, recording devices, or personal mobile phones; requires dual-custody access for sensitive operations; and enforces clean room operating rules.
- A.7.7 Clear desk and clear screen policy: Requires that sensitive documents and media are locked away when desks are unattended (clear desk) and screen locks trigger automatically after a short period of inactivity (e.g., 3–5 minutes) with mandatory re-authentication (clear screen). Cross-cut shredders (DIN 66399 Level P-4 or higher) must be accessible for physical document disposal.
4. Equipment Protection, Cabling & Maintenance (A.7.8, A.7.9, A.7.10, A.7.12, A.7.13, A.7.14)
- A.7.8 Equipment placement and protection: Equipment must be sited to minimize environmental risks (e.g., avoiding placement under water pipes or near exterior windows) and unauthorized access.
- A.7.9 Security of assets off-premises: Extends security requirements to corporate assets used outside organization premises (laptops, mobile devices, field equipment). Requires full-disk encryption (FDE), physical cable locks, and remote wipe software.
- A.7.10 Storage media: Controls the handling, transit, storage, and disposal of removable storage media (USBs, external hard drives, backup tapes). Requires media classification, encryption in transit, and tamper-evident transport bags.
- A.7.12 Cabling security: Power and telecommunication cables carrying data must be protected from interception, interference, or physical damage. Mandates separation of data and power cables, deployment of armored conduits, and locking patch panels inside telecommunication closets.
- A.7.13 Equipment maintenance: Equipment must be properly maintained by authorized vendor engineers under formal SLAs to ensure continuous availability and integrity.
- A.7.14 Secure disposal or re-use of equipment: Prior to disposal, equipment containing storage media must undergo secure sanitization or physical destruction in compliance with NIST SP 800-88 Guidelines for Media Sanitization (Clear, Purge, or Destroy). Certificates of Destruction (CoD) must be retained for audit trails.
Implementation & Audit Evidence Matrix
| Control ID & Title | Technical & Operational Implementation | Primary Audit Evidence |
|---|---|---|
| A.7.2 Physical Entry Controls | Electronic badge access, biometric readers, visitor badge system, anti-passback rule | Electronic access logs, visitor logbooks, badge request/revocation tickets |
| A.7.4 Physical Security Monitoring | IP CCTV cameras at all ingress points, motion sensors, central alarm logging | CCTV retention logs (min. 30–90 days), alarm test records, monitoring SLAs |
| A.7.7 Clear Desk & Clear Screen | GPO/MDM screen-lock timeout policies, lockable pedestals, secure shredding bins | Group Policy configuration export, physical audit walk-through inspection reports |
| A.7.11 Supporting Utilities | Dual-path power, UPS systems, diesel backup generator, precision HVAC | Generator maintenance contracts, monthly load test logs, HVAC telemetry records |
| A.7.14 Secure Equipment Disposal | On-site degaussing, drive shredding, cryptographic erasure per NIST SP 800-88 | Serialized Certificates of Destruction, asset disposal register, vendor chain-of-custody |
Real-World Lead Implementer Scenario
Scenario: A financial services firm is migrating its primary data center to a co-location facility while retaining an on-premises staging server room. During a pre-certification internal audit, the Lead Implementer discovers that contractors servicing the HVAC system were escorted into the server room without signing visitor logs. Additionally, obsolete server hard drives awaiting decommissioning were stored in an unlocked cabinet in the hallway.
Lead Implementer Action Plan:
- Immediate Remediation: Secure all hard drives in a key-card locked media safe immediately and initiate physical media inventory reconciliation.
- Policy Enforcement: Re-issue the Physical Access Control Procedure, establishing mandatory visitor log-in, identity verification, and 100% continuous escort requirements for third-party maintenance contractors (A.7.2, A.7.13).
- Sanitization Protocol: Engage a certified disposal vendor to perform on-site physical shredding of obsolete drives, generating serialized Certificates of Destruction mapped to asset inventory IDs (A.7.14).
- Corrective Action Review: Implement an automated badge-access audit review conducted monthly by the Facility Security Officer.
An organization is preparing to decommission 50 legacy rack servers containing customer financial records. Which sequence of actions fully satisfies ISO/IEC 27001:2022 Control A.7.14 (Secure disposal or re-use of equipment)?
During a physical walk-through audit of a secure financial operation center, an auditor observes that telecommunication cables run loosely across accessible office ceilings and patch panels in server closets are unlocked. Which control is primarily deficient?
An enterprise enforces a workstation security configuration where user screens lock automatically after 3 minutes of inactivity, requiring multi-factor re-authentication to unlock. Employees are also provided with locking file cabinets for physical papers. Which Annex A control is directly implemented by these measures?