A.7 Physical Controls Overview
Physical controls ensure the protection of organizational assets, information, equipment, and processing facilities against unauthorized physical access, environmental threats, damage, and interference.
Draft Descriptions for A.7.1 – A.7.14
A.7.1 Physical Security Perimeter
- Purpose: To prevent unauthorized physical access, damage, and interference to the organization’s information and processing facilities.
- Description: Security perimeters (e.g., walls, card-controlled entry gates, security guards, fenced boundaries) must be clearly defined and implemented to protect areas containing information assets and processing equipment.
A.7.2 Physical Entry
- Purpose: To ensure secure areas are protected by suitable entry controls to permit access only to authorized personnel.
- Description: Entry to facility areas storing sensitive information must be controlled via authentication mechanisms (e.g., keycards, biometrics, badges). Visitors should be escorted, logged, and required to wear visible identification.
A.7.3 Securing Offices, Rooms, and Facilities
- Purpose: To prevent unauthorized physical access to offices, rooms, and facilities housing sensitive information or assets.
- Description: Physical security for interior offices, rooms, and server areas must be designed and implemented with appropriate lock systems, intruder detection, and structural physical barriers.
A.7.4 Physical Security Monitoring
- Purpose: To detect and deter unauthorized physical entry and access.
- Description: Continuous monitoring tools (e.g., CCTV cameras, motion sensors, intruder alarm systems) must monitor physical access points, perimeters, and internal sensitive locations.
A.7.5 Protecting Against Physical and Environmental Threats
- Purpose: To prevent or reduce loss, damage, theft, or compromise of information assets caused by physical and environmental events.
- Description: Procedures and physical safeguards must be designed to protect facilities against hazards such as fire, flooding, natural disasters, utility failure, or civil unrest.
A.7.6 Working in Secure Areas
- Purpose: To protect information and assets located within secure areas from unauthorized activity or exposure.
- Description: Policies and guidelines must govern activities inside secure areas (e.g., prohibition of recording devices, supervised visitor protocols, clear-desk requirements inside server rooms).
A.7.7 Clear Desk and Clear Screen
- Purpose: To prevent unauthorized access to, viewing of, or loss of physical and visual information.
- Description: Employees must keep paper documents containing sensitive data locked away when not in use, and automatically or manually lock display screens when leaving workstations unattended.
A.7.8 Equipment Siting and Protection
- Purpose: To protect equipment against physical and environmental operational threats and unauthorized access.
- Description: Equipment should be located strategically to minimize physical exposure, hazards (e.g., away from water pipes), or unauthorized visual observation, and secured against environmental factors.
A.7.9 Assets Off-Premises
- Purpose: To prevent loss, damage, theft, or compromise of off-site organizational assets.
- Description: Equipment or assets used outside company premises (e.g., laptops, mobile devices, remote site hardware) must be authorized, encrypted, physically protected, and tracked.
A.7.10 Storage Media
- Purpose: To protect storage media containing organizational information during acquisition, transport, storage, and disposal.
- Description: Removable media (e.g., hard drives, USBs, backup tapes) must be stored securely, encrypted, cataloged, handled per classification levels, and disposed of securely when no longer needed.
A.7.11 Supporting Utilities
- Purpose: To prevent loss, damage, or interruption of operations resulting from utility failures.
- Description: Equipment must be protected against power disruptions or infrastructure failures using redundant systems, Uninterruptible Power Supplies (UPS), generators, and regular maintenance of utility support lines (e.g., HVAC, power, telecommunications).
A.7.12 Cabling Security
- Purpose: To protect power and telecommunications cabling carrying data or supporting services from interception, interference, or damage.
- Description: Network and power cables must be protected using conduits, armor, or physically hidden channels to prevent tampering, eavesdropping, or physical damage.
A.7.13 Equipment Maintenance
- Purpose: To ensure equipment is maintained correctly to preserve its availability, integrity, and operational capability.
- Description: Equipment must be regularly inspected and maintained according to manufacturer guidelines by authorized personnel, with records kept to ensure operational reliability.
A.7.14 Secure Disposal or Re-use of Equipment
- Purpose: To prevent information disclosure from retired or re-allocated hardware and storage media.
- Description: Prior to disposal, recycling, or re-assignment, storage media and equipment containing confidential data must be sanitized, degaussed, or physically destroyed to ensure data cannot be recovered.
Articles
- ISO 27001 Annex A 7.1: Physical Security Perimeters
- ISO 27001 Annex A 7.10 Storage media
- ISO 27001 Annex A 7.11 Supporting utilities
- ISO 27001 Annex A 7.12 Cabling security
- ISO 27001 Annex A 7.13 Equipment maintenance
- ISO 27001 Annex A 7.14 Secure disposal or re-use of equipment
- ISO 27001 Annex A 7.2 Physical entry controls
- ISO 27001 Annex A 7.3 Securing offices, rooms and facilities
- ISO 27001 Annex A 7.4 Physical security monitoring
- ISO 27001 Annex A 7.5 Protecting against physical and environmental threats
- ISO 27001 Annex A 7.6 Working in secure areas
- ISO 27001 Annex A 7.7 Clear desk and clear screen
- ISO 27001 Annex A 7.8 Equipment siting and protection
- ISO 27001 Annex A 7.9 Security of assets off-premises
