What changed in 2022
In ISO/IEC 27001:2013, physical security sat in A.11, "Physical and environmental security", with 15 controls. The 2022 revision regrouped all Annex A controls into four themes, and physical security became A.7, with 14 controls. Organizations certified to the 2013 version had until October 2025 to transition.
The 14 controls
| Control | In plain English | What we look at on site |
|---|---|---|
| A.7.1 Physical security perimeters | Define the boundaries that protect information and assets | Where the perimeter really is, and where it can be walked around |
| A.7.2 Physical entry | Control who gets through entry points | Credential technology, tailgating, visitor and contractor entry |
| A.7.3 Securing offices, rooms and facilities | Protect the rooms that matter | Server rooms, comms rooms, labs, records |
| A.7.4 Physical security monitoring | Watch the premises for unauthorized access | Camera coverage, alarm response, who reviews what |
| A.7.5 Protecting against physical and environmental threats | Fire, flood, power and similar hazards | Environmental risks to sensitive rooms |
| A.7.6 Working in secure areas | Rules for behavior inside secure areas | Escort, photography, lone working |
| A.7.7 Clear desk and clear screen | Don’t leave information exposed | Walk-through outside working hours |
| A.7.8 Equipment siting and protection | Put equipment where it is safe | Equipment in shared or public spaces |
| A.7.9 Security of assets off-premises | Protect assets that leave the building | Laptops, media, remote kit |
| A.7.10 Storage media | Manage media through its life | Handling, transport and storage of drives and tapes |
| A.7.11 Supporting utilities | Protect power and other utilities | Access to plant rooms and power feeds |
| A.7.12 Cabling security | Protect power and data cables | Exposed cabling, patch panels in shared areas |
| A.7.13 Equipment maintenance | Maintain equipment correctly | Who maintains what, and under whose escort |
| A.7.14 Secure disposal or re-use of equipment | Wipe or destroy before disposal | Chain of custody from rack to destruction |
Where certified organizations usually fall short
- A.7.2 is documented as "badge access" without anyone checking what the badges are. See can prox cards be cloned.
- Contractor entry is controlled on paper and informal at the loading dock.
- A.7.14 relies on a destruction certificate, with no record of what happened between the rack and the truck.
How an assessment helps
Our credential and access control assessment is mapped to Annex A.7, alongside SOC 2 CC6.4, ASIS guidance, NPSA and TIA-942. It tests the controls rather than the paperwork, and every finding is prioritized with a price range.
Last reviewed September 23, 2026.