Information Security Management

ISO 27001 Physical Controls Explored

They complement the Organisational, People, and Technological controls by securing the physical layer of your information assets.

Jump to the full list of Annex A controls →
Looking for the broader Annex A context? Start here →

Annex A Physical Control List (7.1 – 7.14)

Below is a complete list of the physical controls, each linking to its own detailed explanation and examples.

I’ve grouped them into themes to help organise them, but these are not ISO 27001 formal groupings.

Physical Access Controls (7.1-7.14)


Defines and protects secure areas to prevent unauthorised entry or tampering.

7.1 Physical security perimeters – Defined and protected boundaries around areas that contain information or information processing facilities, with appropriate access controls at each boundary.

7.2 Physical entry – Controls that ensure only authorised people can enter secure areas, typically through a combination of locks, badges, sign-in procedures, and supervision.

7.3 Securing offices, rooms and facilities – Practical measures to protect the spaces where work happens, from server rooms to general office areas, against unauthorised access and environmental threats.

7.4 Physical security monitoring – Active monitoring of premises through CCTV, alarms, intruder detection, or other systems that identify unauthorised physical access in real time.

7.5 Protecting against physical and environmental threats – Protections against natural and man-made threats such as fire, flood, power loss, and theft, proportionate to the value of what’s being protected.

7.6 Working in secure areas – Rules and protections covering how staff and visitors should behave when working in areas that hold sensitive information or critical systems.

7.7 Clear desk and clear screen – Practices that prevent sensitive information being left visible on desks, screens, whiteboards, or printers when unattended.

7.8 Equipment siting and protection – Positioning equipment so that it’s protected from environmental hazards and from being overlooked, tampered with, or damaged.

7.9 Security of assets off-premises – Protections for organisational equipment and information when used outside the office, including laptops in transit, equipment at home, and devices on client sites.

7.10 Storage media – Controls covering the lifecycle of removable media (USB drives, backup tapes, disposable hard drives) from acquisition through use to secure disposal.

7.11 Supporting utilities – Protections for the utilities that information processing depends on, particularly power, cooling, and telecommunications.

7.12 Cabling security – Protecting the network and power cabling that supports information systems against interception, interference, and accidental damage.

7.13 Equipment maintenance – Maintaining equipment correctly so that it remains reliable and so that maintenance activities don’t introduce security risks.

7.14 Secure disposal or re-use of equipment – Ensuring that equipment containing information is wiped or destroyed properly before disposal or reuse, so data isn’t recoverable from old kit.

ISO 27001 Annex A Physical Controls Explained in 3 minutes

What Are Physical Controls in ISO 27001?

Physical controls are the safeguards that prevent physical threats — such as theft, fire, unauthorised entry, or equipment damage — from compromising your information.

They ensure that information stored on paper, devices, or local servers remains protected from accidental or deliberate harm.

How ISO 27001 Physical Controls Fit into Annex A

How the ISO 27001 physical controls relate to the other control families in Annex A
How the ISO 27001 physical controls relate to the other control families in Annex A

ISO 27001 Full Document Toolkit

Every document your auditor
expects to see.

130 Word & Excel templates, ready to edit. Policies, risk register, Statement of Applicability, audit pack, staff communications — all updated for ISO 27001:2022.

130 templates

Instant download

Written by practising consultant

ISO 27001:2022


So, why have this group of controls? Well, the benefits include;

  • They protect your information where it physically exists.
  • They demonstrate diligence to auditors and customers.
  • They support compliance with data protection and business continuity requirements.
  • They prevent small incidents (like unattended laptops) from becoming data breaches.

The physical controls ask people to consider how they deal with ‘real-world’ security; Offices, desks, and computers. How we protect these from environmental and malicious intentions.

Increasingly, however, organisations are often 100% remote and work as a virtual team, so many of the controls may not be directly applicable in such circumstances.


Physical Controls for Virtual Teams and Cloud-First Businesses

I want to focus on a particular area here for a while, because a growing number of the SMEs I work with don’t have offices. Their teams are distributed, they meet in coffee shops and co-working spaces when they need to, and their infrastructure lives entirely in the cloud. When these businesses come to ISO 27001, the Physical family is the one that causes the most confusion – because most of the controls are written assuming you have premises, equipment racks, and physical perimeters to defend.

The mistake I see often is teams looking at this family and thinking, “none of this applies to us, let’s mark them all not applicable”. That’s not right. The intent of these controls still applies – you still have information that needs protecting from physical and environmental threats – but the implementation is fundamentally different.

The right mental model is to ask, for each control: where does this information actually live, and what physical and environmental risks does it face? Once you ask the question that way, the answers fall out fairly cleanly.

What “physical” means when there’s no office

For a virtual team, your physical estate is essentially the laptops, phones, and home working environments of your staff. That’s where information is accessed, processed, and (when people print things) stored. So the Physical Controls don’t disappear – they shift from being about your building to being about your distributed kit and the homes it’s used in.

The controls split roughly into three groups for a virtual team.

Controls that still apply, but implemented differently

A.7.7 Clear desk and clear screen apply in someone’s kitchen as much as they apply in an office. If anything, it’s harder to enforce, because you can’t walk around. The implementation moves from “tour the office” to “set the expectation in your remote working policy and reinforce it in training”. Auditors will sometimes ask staff how they handle sensitive information at home, so the cultural side of this control matters more in a virtual team than in an office.

A.7.9 Security of off-premises assets is arguably the most important physical control for a virtual team, because all of your assets are off-premises by default. This is where laptop encryption, device management, screen privacy filters, and clear rules about home working environments earn their keep. If you only get one physical control really right, make it this one.

A.7.10 Storage media and A.7.14 Secure disposal apply because your staff still have laptops with hard drives, even if those drives are encrypted SSDs. When the kit is replaced, retired, or returned by leavers, it needs to be wiped properly. A simple disposal log covering what was decommissioned, when, and how is enough evidence for an audit.

A.7.13 Equipment maintenance applies in a lighter form – you’re not maintaining server hardware, but you do still need to keep laptops patched, replaced before they fail, and serviced when issues arise. This usually rolls up into your IT support arrangements and your A.8 technological controls.

Controls that are met by your suppliers, not by you

If you operate from co-working spaces, serviced offices, or your team meets occasionally at hired venues, several physical controls are largely delivered by the operator of those spaces. A.7.1 (perimeters), A.7.2 (entry), A.7.3 (securing rooms), and A.7.4 (monitoring) are typically met by the building’s existing measures.

Your work is to document the arrangement: what the venue provides, what you have assured yourself of, and what your contracts with these providers say about security. This usually appears as a short note in your SoA for each control, referencing the supplier review you’ve done under A.5.19. Auditors are very used to this pattern and won’t penalise you for it as long as you’ve actually thought about it rather than assumed it’s covered.

If your team is fully remote and meets only online, even this lighter framing doesn’t apply – the controls become genuinely not applicable, with “the organisation operates without dedicated premises” as the justification.

Controls that may be genuinely not applicable

A.7.11 Supporting utilities and A.7.12 Cabling security cover utilities and physical network infrastructure. If you don’t operate either, both can be marked not applicable in your SoA. The justification is straightforward: the organisation does not operate a physical IT infrastructure, and all information processing is delivered through cloud services managed under A.5.23.

A.7.4 Physical security monitoring may also not be applicable if you have no premises to monitor, though some auditors prefer to see this control marked as “covered by suppliers” rather than excluded entirely if you ever use shared workspaces.

How to write this up in your SoA

For a virtual team, your Physical Controls SoA entries should make the operating model explicit. Something like this works for each control:
The organisation operates as a fully distributed team without dedicated premises. Information is accessed and processed exclusively through encrypted laptops in employee home environments and occasionally at hired meeting venues. The intent of this control is achieved through [specific implementation], supported by [specific policies]. Where premises are used temporarily, physical security is delivered by the venue operator under arrangements documented in [supplier review reference].

This is much stronger than marking controls as not applicable without explanation. It tells the auditor you’ve understood the control, considered how it applies to your business, and made deliberate decisions. That’s exactly what they want to see.

A note on what auditors care about

In my experience, auditors don’t penalise virtual teams for being virtual. What they penalise is virtual teams that haven’t considered the physical aspects of security at all. The two failure patterns I see at audit are:

The “we don’t have an office” excuse. Marking every physical control as not applicable, with justifications that amount to “we work from home”. Auditors will push back because some of these controls clearly still apply to the laptops and home-working environments your business actually uses.

The “physical doesn’t matter to us” assumption. Treating the family as a paperwork exercise to get through, without ever genuinely considering the physical risks to the distributed kit. The most common consequence is no laptop encryption, no documented disposal process, and no remote working expectations – all of which an auditor will spot quickly.

The virtual teams that do best in audits are the ones that have explicitly considered how physical security applies to their model and documented their thinking. The thinking is usually quite quick once you frame it the right way; what matters is that it’s been done.

Check out some of the other control families here;

Or, by group


FAQ: Physical Controls

Are Physical Controls relevant if my business is cloud-first and remote?

Yes, but the implementation looks very different. If you don’t have an office or physical infrastructure, controls like A.7.1 (perimeters), A.7.4 (monitoring), and A.7.11 (utilities) may be marked as not applicable in your SoA, with appropriate justification. But controls like A.7.7 (clear desk and screen), A.7.9 (off-premises assets), and A.7.14 (secure disposal) still very much apply, because your staff are working with laptops at home and at client sites. The principle is to assess each control against your actual operating model, not to assume the family doesn’t apply just because you don’t own a building.

Where do I start with the Physical Controls?

If you have an office, start with A.7.1 to A.7.4 (perimeters, entry, securing rooms, monitoring) because they cover the basics any auditor will want to see. If you’re remote-first, start with A.7.7 (clear desk and screen) and A.7.9 (off-premises assets), because these are the controls that actually apply to how your staff work. A.7.14 (secure disposal) is a quick win for almost everyone, because most SMEs already have some kind of disposal practice and just need to document it.

What if I don’t own my office – is that a problem?

Not at all. Most companies I engage with work entirely remotely. Many SMEs operate from co-working spaces, serviced offices, or shared buildings where the landlord controls physical security. The standard doesn’t require you to own the building; it requires you to manage the risks. Document the arrangement (what the landlord provides, what you’ve checked, what your contract specifies) and add any compensating measures you’ve put in place inside your own area. Auditors are very used to this pattern.

Which Physical Controls are most commonly excluded in SME SoAs?

A.7.11 (supporting utilities) and A.7.12 (cabling security) are the two most commonly marked as not applicable in cloud-first SMEs, because if you don’t operate physical infrastructure, neither control applies in any meaningful way. A.7.4 (physical security monitoring) is also commonly excluded for businesses without dedicated premises. The justification needs to be specific – “we don’t have premises” is fine, “we don’t think it applies” isn’t.

How do auditors typically check Physical Controls?

By walking around. If you have an office, expect the auditor to do at least a brief tour. They’ll look for desks with sensitive information left out (A.7.7), check whether server rooms are locked (A.7.3), see if visitor sign-in is being used (A.7.2), and notice things like screens facing windows or printers in public areas (A.7.8). For remote-first organisations, they’ll ask staff how they secure their home working environment and what happens to old equipment. Physical Controls are the family auditors most often verify by direct observation rather than document review.

Do I need CCTV to meet A.7.4?

Not necessarily. A.7.4 requires monitoring of physical access proportionate to the risk. CCTV is the most common way to achieve it but not the only way – intruder alarms, access logs from electronic entry systems, visitor sign-in records, and even regular physical inspections can all contribute. For small offices in low-risk environments, the existing landlord measures combined with locked doors and a sign-in book may be sufficient. The key is to document your decision and ensure it’s proportionate to what you’re protecting.

What’s the difference between A.7.7 (clear desk) and remote working in A.6.7?

A.7.7 covers the principle that sensitive information shouldn’t be left visible when unattended, regardless of where work happens. A.6.7 (in the People family) covers the broader rules and protections for working remotely. They overlap when staff are working from home – the clear desk principle applies in their kitchen as much as in the office – but the controls come from different angles. A.7.7 is about the physical state of any workspace; A.6.7 is about the rules governing remote work as a whole.

Do home offices count as “off-premises” under A.7.9?

Yes, but the practical implementation differs from how you’d handle equipment at client sites or in transit. Home working is a permanent arrangement for most SME staff now, so the protections need to be sustainable – that usually means a remote working policy (linking to A.6.7), encrypted laptops, secure remote access, and clear rules about what can and can’t be done at home. Auditors don’t expect you to inspect employees’ kitchens, but they do expect documented expectations and evidence that staff understand them.

Includes all the mandatory document templates — free, no commitment