What changed in 2022

In ISO/IEC 27001:2013, physical security sat in A.11, "Physical and environmental security", with 15 controls. The 2022 revision regrouped all Annex A controls into four themes, and physical security became A.7, with 14 controls. Organizations certified to the 2013 version had until October 2025 to transition.

The 14 controls

ControlIn plain EnglishWhat we look at on site
A.7.1 Physical security perimetersDefine the boundaries that protect information and assetsWhere the perimeter really is, and where it can be walked around
A.7.2 Physical entryControl who gets through entry pointsCredential technology, tailgating, visitor and contractor entry
A.7.3 Securing offices, rooms and facilitiesProtect the rooms that matterServer rooms, comms rooms, labs, records
A.7.4 Physical security monitoringWatch the premises for unauthorized accessCamera coverage, alarm response, who reviews what
A.7.5 Protecting against physical and environmental threatsFire, flood, power and similar hazardsEnvironmental risks to sensitive rooms
A.7.6 Working in secure areasRules for behavior inside secure areasEscort, photography, lone working
A.7.7 Clear desk and clear screenDon’t leave information exposedWalk-through outside working hours
A.7.8 Equipment siting and protectionPut equipment where it is safeEquipment in shared or public spaces
A.7.9 Security of assets off-premisesProtect assets that leave the buildingLaptops, media, remote kit
A.7.10 Storage mediaManage media through its lifeHandling, transport and storage of drives and tapes
A.7.11 Supporting utilitiesProtect power and other utilitiesAccess to plant rooms and power feeds
A.7.12 Cabling securityProtect power and data cablesExposed cabling, patch panels in shared areas
A.7.13 Equipment maintenanceMaintain equipment correctlyWho maintains what, and under whose escort
A.7.14 Secure disposal or re-use of equipmentWipe or destroy before disposalChain of custody from rack to destruction

Where certified organizations usually fall short

  • A.7.2 is documented as "badge access" without anyone checking what the badges are. See can prox cards be cloned.
  • Contractor entry is controlled on paper and informal at the loading dock.
  • A.7.14 relies on a destruction certificate, with no record of what happened between the rack and the truck.

How an assessment helps

Our credential and access control assessment is mapped to Annex A.7, alongside SOC 2 CC6.4, ASIS guidance, NPSA and TIA-942. It tests the controls rather than the paperwork, and every finding is prioritized with a price range.

Last reviewed September 23, 2026.

Contact

Want to know how your sites would hold up?

Twenty minutes is enough to know whether an assessment is worth it. We’ll be honest either way.