What is ISO 27001 Annex A 7.1 – Physical Security Perimeters?
ISO 27001 Annex A 7.1 requires organizations to define and use security perimeters to protect areas where information and other associated assets are located.
A physical security perimeter is a boundary designed to control and restrict physical access to areas that contain information, systems, equipment, or other assets that need protection.
Examples include:
- Company offices
- Server rooms
- Data centers
- Network equipment rooms
- Secure storage areas
- Archive rooms
- Restricted work areas
- Security operations areas
- Areas containing confidential records
- Production facilities
Simple Explanation
Know which physical areas need protection, define their boundaries, and control who can physically enter them.
The purpose is not to turn every office into a high-security facility.
The objective is to ensure that areas containing sensitive information or important assets receive protection appropriate to their risks.
Why is Annex A 7.1 Important?
Physical security is sometimes overlooked because modern organizations increasingly use cloud services and remote working.
However, organizations may still have:
- Employee laptops
- Network equipment
- Backup devices
- Printed confidential information
- Employee records
- Customer documents
- Physical security keys
- Network infrastructure
- Office equipment
- Physical media
Unauthorized physical access can result in:
- Theft
- Unauthorized viewing of information
- Device tampering
- Network compromise
- Data leakage
- Damage to equipment
- Loss of physical records
- Installation of unauthorized devices
- Business disruption
Simple Principle
If unauthorized people can physically reach an important asset, technical security controls may not be enough.
What Does Annex A 7.1 Require?
The organization should define and establish appropriate physical security perimeters around areas where sensitive information and associated assets require protection.
The perimeter should be appropriate to:
- Information security risks
- Asset sensitivity
- Business requirements
- Legal and regulatory requirements
- Customer requirements
- Physical location
- Threat environment
A physical security perimeter may be:
- A locked office
- A restricted floor
- A locked server room
- A controlled data center
- A secure archive
- A fenced facility
- A reception-controlled area
- A combination of physical and electronic access controls
The organization should determine what level of perimeter protection is appropriate for each location.
What is a Physical Security Perimeter?
A physical security perimeter establishes a boundary between:
Protected Area
and
Uncontrolled or Less-Controlled Area
For example:
Public Area
↓
Reception
↓
Employee-Only Area
↓
Restricted IT Area
↓
Server / Network Room
Each boundary can have different security requirements.
Physical Security Zones
A startup can use a simple zoning model.
| Zone | Example | Typical Access |
|---|---|---|
| Public | Reception / waiting area | Visitors |
| General | Employee workspace | Employees |
| Restricted | Finance / HR area | Authorized employees |
| Highly Restricted | Server/network room | IT/security personnel |
| Critical | Specialized infrastructure area | Specifically authorized personnel |
Not every organization needs five physical security zones.
The number of zones should reflect actual risk.
Activities Required to Implement Annex A 7.1
Step 1: Identify Physical Locations
Create an inventory of locations where organizational information or associated assets are physically present.
Examples:
- Head office
- Branch office
- Data center
- Server room
- Storage room
- Records room
- Network closet
- Secure archive
- Warehouse
For a cloud-first startup, this list may be surprisingly short.
Step 2: Identify What Needs Physical Protection
Determine what assets are located at each physical location.
For example:
| Location | Assets | Sensitivity |
|---|---|---|
| Office | Employee laptops | High |
| HR room | Employee records | High |
| Finance room | Financial records | High |
| Network room | Network equipment | High |
| Server room | Servers | Critical |
| Reception | Visitor information | Low/Medium |
| Storage room | Archived records | Medium/High |
This helps determine where stronger physical boundaries are needed.
Step 3: Define Physical Security Perimeters
Determine where access restrictions should begin.
For example:
Perimeter 1 – Building
Controls access to the overall office.
Perimeter 2 – Employee Area
Restricts access to employees and authorized visitors.
Perimeter 3 – Restricted Area
Protects sensitive departments or assets.
Perimeter 4 – Server/Network Room
Provides stronger restrictions for critical infrastructure.
The organization’s actual structure may be simpler.
Step 4: Define Access Requirements
For each protected area, determine:
- Who can enter?
- Why do they need access?
- How is access granted?
- Who approves it?
- How is access removed?
- How are visitors handled?
- How are contractors handled?
- Is access logged?
For example:
| Area | Authorized People |
|---|---|
| General office | Employees |
| HR area | HR personnel + authorized management |
| Finance | Finance personnel + authorized management |
| Network room | IT/security personnel |
| Server room | Authorized infrastructure personnel |
| Records archive | Authorized records personnel |
Step 5: Implement Physical Access Controls
Possible controls include:
- Locks
- Electronic access control
- Access cards
- Biometrics
- Security guards
- Reception controls
- Turnstiles
- Fences
- Doors
- Security gates
- Visitor management systems
The control should be proportional to the risk.
A small startup may not need biometric access control for a normal office.
A locked door and controlled access may be sufficient.
Step 6: Define Visitor Controls
Visitors should not automatically receive unrestricted physical access.
Depending on risk, the organization may:
- Require visitor registration
- Verify identity
- Issue visitor badges
- Restrict visitor areas
- Escort visitors
- Record visitor entry/exit
- Restrict photography
- Restrict access to sensitive areas
For example:
Visitor arrives
→ Reception registration
→ Identity verification
→ Visitor badge
→ Host confirmation
→ Escort where required
→ Restricted access
→ Visitor departure
→ Badge returned
Step 7: Protect Sensitive Areas
Certain areas may require stronger physical controls.
Examples:
Server Room
Possible controls:
- Locked door
- Restricted access list
- Access logs
- Environmental monitoring
- CCTV where appropriate
- Visitor restrictions
HR Records Room
Possible controls:
- Restricted access
- Locked cabinets
- Authorized personnel only
- Confidential document handling
Network Room
Possible controls:
- Restricted access
- Locked cabinets/racks
- Visitor restrictions
- Asset identification
Step 8: Consider Physical Security During Remote and Hybrid Work
Modern organizations may have fewer physical offices.
However, employees may still have organizational assets at:
- Home
- Hotels
- Coworking spaces
- Customer locations
- Temporary offices
A.7.1 primarily concerns organizational physical premises and protected areas, but physical security expectations should work together with:
- A.6.7 Remote Working
- A.7.7 Clear Desk and Clear Screen
- A.8.1 User Endpoint Devices
Startup Example
Consider a 30-person SaaS startup operating from a leased office.
The office contains:
- Employee laptops
- Network equipment
- Backup devices
- HR documents
- Finance records
The startup defines:
Zone 1 – Reception
Visitors allowed.
Zone 2 – General Office
Employees allowed.
Zone 3 – HR/Finance
Authorized personnel only.
Zone 4 – Network Room
IT/security personnel only.
The network room is locked.
Visitors cannot enter the network room without authorization and appropriate supervision.
Physical Security Structure
Building
↓
Reception
↓
Employee Area
↓
Restricted HR / Finance
↓
Locked Network Room
The organization documents these boundaries and maintains appropriate access records.
Cloud-First Startup Example
Now consider a 20-person SaaS startup that is almost completely cloud-based.
The company uses:
- AWS
- GitHub
- Microsoft 365
- Slack
- Remote work
There is no company-owned server room.
The organization may still have:
- Laptops
- Office equipment
- Network equipment
- Employee records
- Printed documents
For this organization, A.7.1 does not mean creating a server room simply to satisfy ISO 27001.
Instead, it should:
- Define the office boundary
- Control office access
- Protect sensitive areas
- Secure physical devices
- Use secure cloud providers
- Address physical infrastructure through supplier/cloud security controls
This is a good example of risk-based implementation.
Startup-Focused Quick Summary
A small startup can begin with a simple model:
Identify
Where are important physical assets located?
Classify
Which locations need restricted access?
Define
Establish physical security boundaries.
Control
Use appropriate locks/access controls.
Manage Visitors
Control visitor access to protected areas.
Protect Critical Areas
Apply stronger controls to server/network/records areas.
Review
Review physical access when people join, leave, or change roles.
Evidence
Maintain enough records to demonstrate that the controls operate.
Example Physical Security Zone Register
A startup can maintain a simple register:
| Zone | Location | Assets | Access Level | Control |
|---|---|---|---|---|
| Z01 | Reception | Visitor records | Public/Controlled | Reception |
| Z02 | General Office | Laptops | Employee | Door access |
| Z03 | HR Room | Employee PII | Restricted | Locked door |
| Z04 | Finance Room | Financial records | Restricted | Locked door |
| Z05 | Network Room | Network equipment | Highly Restricted | Electronic lock |
| Z06 | Records Room | Archived records | Restricted | Locked room |
The register should reflect the actual organization’s environment.
Physical Security Perimeter Assessment
For each location, ask:
| Question | Example |
|---|---|
| What assets are located here? | Laptops / records / network equipment |
| Is sensitive information present? | Yes |
| Who needs access? | Employees / IT |
| Who should not have access? | General visitors |
| How is access controlled? | Key/card |
| Are visitors controlled? | Yes |
| Are access rights reviewed? | Periodically |
| Is the area monitored? | Where appropriate |
| What happens if access is lost? | Lock replacement / access revocation |
| Are physical risks documented? | Risk assessment |
Physical Security Perimeter vs. Physical Access Control
These concepts are related but not identical.
Physical Security Perimeter
Defines the boundary that needs protection.
Example:
“The network room is a restricted area.”
Physical Access Control
Controls who can cross that boundary.
Example:
“Only authorized infrastructure personnel can unlock the network room.”
Therefore:
Perimeter = Where protection begins
Access control = Who can enter
Audit Evidence for Annex A 7.1
An auditor may request:
Policies
- Physical Security Policy
- Physical Access Control Policy
- Visitor Management Policy
- Office Security Policy
Procedures
- Physical Access Procedure
- Visitor Management Procedure
- Restricted Area Access Procedure
- Key/Card Management Procedure
- Physical Security Incident Procedure
Registers
- Physical Security Zone Register
- Authorized Access List
- Visitor Register
- Key Register
- Access Card Register
- Physical Asset Register
Technical/Operational Evidence
- Door access logs
- Access control configuration
- Visitor records
- CCTV arrangements where applicable
- Photographs/layouts of restricted areas where appropriate
- Security guard records
- Physical access reviews
- Access revocation records
Risk Evidence
- Physical security risk assessment
- Business impact assessment
- Physical security review
- Incident records
Audit Checklist for Annex A 7.1
| Audit Question | Evidence |
|---|---|
| Are physical security boundaries defined? | Zone register / floor plan |
| Are sensitive areas identified? | Risk assessment |
| Are physical assets identified? | Asset inventory |
| Are restricted areas established? | Physical security policy |
| Is physical access controlled? | Access-control records |
| Are critical areas protected? | Server/network room controls |
| Are visitors controlled? | Visitor procedure/register |
| Are contractors controlled? | Visitor/access records |
| Are physical access rights authorized? | Access list |
| Are access rights removed when no longer required? | Access revocation records |
| Are physical access logs maintained where appropriate? | Access logs |
| Are physical security incidents handled? | Incident records |
| Are physical security risks periodically reviewed? | Risk review |
| Are controls appropriate to the organization’s risks? | Risk assessment |
Common Mistakes
1. Assuming the Office Door Is Enough
Simply having a locked office does not necessarily demonstrate appropriate protection of sensitive areas.
The organization should consider:
- What is inside?
- Who can enter?
- Which areas are restricted?
- How are visitors handled?
2. No Physical Security Zones
Some organizations treat the entire office as one security area.
This may be inappropriate if:
- HR records are stored there
- Network equipment is present
- Sensitive documents are accessible
- Server/network rooms exist
3. Visitors Can Walk Anywhere
A visitor should not automatically be able to walk into:
- Server rooms
- Network rooms
- HR offices
- Finance areas
- Records rooms
4. No Access Revocation
When an employee leaves, physical access may remain active.
Examples:
- Access card still works
- Key not returned
- Building access not revoked
Physical access should form part of the joiner-mover-leaver process.
5. Forgetting Contractors
Cleaning staff, maintenance personnel, IT contractors and other service providers may have physical access.
Their access should be managed according to risk.
6. Creating Excessive Controls
A small startup does not necessarily need:
- Security guards
- Biometrics
- Multiple access-control layers
- 24/7 CCTV
The organization should implement controls proportionate to its risks.
7. Ignoring Physical Assets Because “Everything Is in the Cloud”
Cloud computing reduces some physical infrastructure requirements but does not eliminate physical security responsibilities.
Organizations still have:
- Laptops
- Phones
- Security keys
- Printed documents
- Office infrastructure
Cloud provider physical security is addressed through supplier/cloud security arrangements.
Practical Startup Implementation Model
A practical implementation model is:
Identify
Identify physical locations and assets.
Assess
Assess physical security risks.
Define
Define security boundaries and zones.
Authorize
Determine who should have physical access.
Control
Implement locks, cards, reception, visitor controls or other measures.
Monitor
Maintain appropriate access and visitor records.
Review
Review access rights and physical security periodically.
Revoke
Remove physical access when employment or authorization ends.
Respond
Handle physical security incidents.
Improve
Update controls when risks or locations change.
Simple Model
Identify → Define → Restrict → Monitor → Review → Improve
Policy vs. Process vs. Evidence
| Layer | Example |
|---|---|
| Policy | Sensitive areas must be physically protected |
| Procedure | Access to restricted areas requires authorization |
| Zone Definition | Network room = highly restricted |
| Technical Control | Electronic door lock |
| Process | Employee access approval |
| Evidence | Door access log |
| Evidence | Visitor register |
| Evidence | Access review |
| Evidence | Access revocation |
| Improvement | Physical security risk review |
An auditor should be able to see a connection between the organization’s documented requirements and the physical controls that actually exist.
Relationship With Other ISO 27001 Controls
A.5.9 – Inventory of Information and Other Associated Assets
Helps identify the physical assets that require protection.
A.5.11 – Return of Assets
Ensures physical assets are returned when they are no longer required.
A.5.15 – Access Control
Provides the broader access-control principles that also apply to physical access.
A.5.18 – Access Rights
Supports the review and removal of access rights.
A.6.5 – Responsibilities After Termination or Change of Employment
Supports physical access removal when employees leave or change roles.
A.6.7 – Remote Working
Addresses security when work is performed outside organizational premises.
A.7.2 – Physical Entry
Builds on the perimeter by controlling entry into protected areas.
A.7.3 – Securing Offices, Rooms and Facilities
Addresses protection of specific offices, rooms and facilities.
A.7.4 – Physical Security Monitoring
Addresses monitoring of physical premises where appropriate.
A.7.7 – Clear Desk and Clear Screen
Protects information exposed in physical work environments.
A.8.1 – User Endpoint Devices
Protects laptops, mobile devices and other endpoints.
A.7.1 vs. A.7.2
These two controls are closely connected.
| Control | Main Question |
|---|---|
| A.7.1 Physical Security Perimeters | Where does the protected physical area begin and end? |
| A.7.2 Physical Entry | How do we control who enters that protected area? |
Example
A.7.1
The network room is designated as a restricted physical security area.
A.7.2
Only authorized IT personnel can enter the network room using controlled access.
So:
A.7.1 defines the boundary. A.7.2 controls entry through that boundary.
Questions an Auditor May Ask
“What are your physical security perimeters?”
Show the organization’s physical security zones or documented boundaries.
“Which areas are restricted?”
Identify areas such as:
- HR
- Finance
- Server/network rooms
- Records storage
- Other sensitive areas
“How do you determine which areas need protection?”
Show the physical security risk assessment.
“Who can access the server/network room?”
Show the authorized access list.
“How are visitors managed?”
Show the visitor process and sample records.
“What happens when an employee leaves?”
Demonstrate physical access-card/key revocation and asset return.
“How do you protect physical records?”
Show restricted areas, locked storage, access controls and records-management requirements.
“You are a cloud-first company. What physical infrastructure do you have?”
Explain the actual physical assets and premises under the organization’s control and how cloud-provider physical security is addressed through supplier/cloud arrangements.
Useful Documents and Resources
A startup implementing A.7.1 may maintain:
- Physical Security Policy
[Insert Draft Document Link] - Physical Security Perimeter Procedure
[Insert Draft Document Link] - Physical Security Zone Register
[Insert Draft Document Link] - Physical Security Risk Assessment
[Insert Draft Document Link] - Physical Access Control Policy
[Insert Draft Document Link] - Physical Access Authorization Form
[Insert Draft Document Link] - Restricted Area Access List
[Insert Draft Document Link] - Visitor Management Procedure
[Insert Draft Document Link] - Visitor Register
[Insert Draft Document Link] - Physical Access Review Checklist
[Insert Draft Document Link] - Key and Access Card Register
[Insert Draft Document Link] - Physical Security Inspection Checklist
[Insert Draft Document Link] - Physical Security Incident Report
[Insert Draft Document Link] - Physical Security Audit Checklist
[Insert Draft Document Link]
Startup-Focused Final Takeaway
Annex A 7.1 is about establishing clear physical boundaries around areas that need protection.
A practical startup approach is:
Identify physical locations
↓
Identify assets and information
↓
Assess physical risks
↓
Define security zones/perimeters
↓
Determine authorized access
↓
Implement appropriate physical controls
↓
Control visitors and contractors
↓
Review physical access
↓
Revoke access when no longer required
↓
Maintain evidence
The key audit question is:
Have we identified the physical areas that require protection and established appropriate security boundaries around them?
For a startup, the objective is not to create unnecessary physical-security complexity.
A 20-person cloud-native SaaS company may need only a few practical controls, while a company operating its own data center or handling highly sensitive physical records may require significantly stronger protection.
Protect the physical boundary according to the value and risk of what lies behind it.
