What is ISO 27001 Annex A 7.5 – Protecting Against Physical and Environmental Threats?
ISO 27001 Annex A 7.5 focuses on protecting information and other associated assets against physical and environmental threats.
These threats can come from:
- Fire
- Flood
- Water leakage
- Extreme temperatures
- High humidity
- Dust
- Smoke
- Power failure
- Electrical problems
- Natural disasters
- Severe weather
- Earthquakes
- Physical damage
- Civil disturbances
- Other environmental or facility-related events
The objective is to reduce the likelihood that a physical or environmental event will:
- Damage information assets
- Interrupt business operations
- Destroy equipment
- Cause data loss
- Affect availability of systems
- Create safety or security incidents
- Prevent recovery of critical services
Simple Explanation
A.7.5 is about protecting information, systems and equipment from things such as fire, water, heat, power problems and other physical or environmental threats.
A company can have excellent cybersecurity controls and still suffer a major security incident if a fire destroys its office equipment or a water leak damages critical infrastructure.
Why is A.7.5 Important?
Information security is not only about confidentiality.
Physical and environmental events can affect all three parts of the CIA Triad:
Confidentiality
Physical damage can result in:
- Loss of confidential documents
- Theft of damaged equipment
- Unauthorized recovery of storage media
Integrity
Physical events can:
- Damage systems
- Corrupt data
- Interrupt processing
- Damage storage devices
Availability
Physical events can cause:
- Server outages
- Network outages
- Power failures
- Office shutdown
- Loss of critical equipment
Example
A startup’s network equipment is located under a water pipe.
A pipe leak damages the equipment.
The organization may experience:
Water leak → Network equipment failure → Internet/network outage → Business disruption → Customer impact
This is a physical and environmental information-security risk.
Simple Principle
Protect critical information assets from the physical environment just as you protect them from cyber threats.
What Does A.7.5 Require?
Organizations should identify and protect against relevant physical and environmental threats.
The controls should be based on:
- Risk assessment
- Location
- Building characteristics
- Criticality of assets
- Type of information processed
- Business continuity requirements
- Local environmental conditions
- Supplier/facility arrangements
- Legal and regulatory requirements
Not every organization faces the same threats.
For example:
A company in a flood-prone area may have significant water and flooding risks.
A company operating in an area with frequent power instability may need stronger power-continuity measures.
A small cloud-based startup with no server room may have limited equipment-related environmental risks.
Physical Threats vs Environmental Threats
These terms can overlap.
| Type | Examples |
|---|---|
| Physical Threats | Theft, vandalism, impact, unauthorized physical interference |
| Environmental Threats | Fire, flood, water, heat, humidity, smoke |
| Utility Threats | Power failure, electrical surge, HVAC failure |
| Natural Threats | Earthquake, storm, extreme weather |
| Facility Threats | Building damage, plumbing failure, structural problems |
The organization should consider threats relevant to its actual environment rather than creating a generic list.
A.7.3 vs A.7.4 vs A.7.5
These controls are related but have different purposes.
| Control | Main Purpose |
|---|---|
| A.7.3 | Secure offices, rooms and facilities |
| A.7.4 | Monitor physical security |
| A.7.5 | Protect against physical and environmental threats |
Example: Server Room
A.7.3
Secure the server room and its physical environment.
A.7.4
Monitor relevant physical security activity.
A.7.5
Protect the equipment against fire, water, heat, humidity, power and other relevant environmental threats.
Activities Required to Implement A.7.5
1. Identify Critical Information Assets
Start with the organization’s asset inventory.
Identify assets that could be affected by physical or environmental threats.
Examples:
- Servers
- Network equipment
- Firewalls
- Storage systems
- Backup devices
- Laptops
- Physical records
- Communication systems
- Power infrastructure
- Critical office equipment
This connects A.7.5 with A.5.9 – Inventory of Information and Other Associated Assets.
2. Identify Physical and Environmental Threats
Conduct a facility-level risk assessment.
Consider:
Fire
- Is there fire detection?
- Is fire suppression available?
- Are emergency procedures defined?
Water
- Are critical systems located near plumbing?
- Is there a risk of flooding?
- Are water-leak detection mechanisms appropriate?
Temperature
- Could excessive heat damage equipment?
- Is cooling available?
Humidity
- Could humidity affect equipment or storage?
Power
- What happens during a power outage?
- Are critical systems protected?
Natural Events
Consider relevant local risks such as:
- Earthquakes
- Floods
- Cyclones
- Storms
- Extreme heat
- Lightning
Other Threats
Depending on the environment:
- Dust
- Smoke
- Chemical exposure
- Construction activity
- Vibration
- Pest infestation
3. Conduct a Physical and Environmental Risk Assessment
A simple risk assessment may look like this:
| Threat | Asset | Likelihood | Impact | Risk | Existing Control | Action |
|---|---|---|---|---|---|---|
| Fire | Network equipment | Medium | High | High | Fire system | Verify inspection |
| Water leak | Network room | Low | High | Medium | Room location | Relocate equipment |
| Power failure | Network equipment | High | High | High | UPS | Test UPS |
| Heat | Network equipment | Medium | High | High | HVAC | Temperature monitoring |
| Flood | Office | Low | High | Medium | Building controls | Review continuity plan |
The exact risk methodology can vary according to the organization’s ISMS.
4. Protect Against Fire
Fire protection can include:
- Smoke detection
- Fire alarms
- Fire extinguishers
- Fire suppression systems
- Appropriate fire-rated infrastructure
- Emergency procedures
- Evacuation plans
- Regular inspections
The appropriate controls depend on:
- Building type
- Equipment
- Fire risk
- Local requirements
- Facility arrangements
Organizations should not improvise specialized fire-suppression systems without appropriate professional guidance.
5. Protect Against Water and Flooding
Water can cause significant damage to:
- Servers
- Network switches
- Storage devices
- Electrical systems
- Physical records
- Backup equipment
Consider:
- Location of equipment
- Plumbing routes
- Roof leakage
- Drainage
- Flood risk
- Water detection
- Equipment elevation
- Appropriate physical barriers
Simple Example
Instead of placing critical network equipment directly below a water pipe:
Identify the risk → relocate equipment → protect the room → monitor where appropriate.
6. Protect Against Temperature and Humidity
Information-processing equipment may require appropriate environmental conditions.
Consider:
- Air conditioning
- HVAC maintenance
- Temperature monitoring
- Humidity monitoring
- Alerts for abnormal conditions
For critical environments, organizations may configure alerts for conditions that could damage equipment.
7. Protect Against Power Failure
Power interruptions can cause:
- System shutdown
- Data corruption
- Network outages
- Equipment damage
- Business disruption
Possible controls include:
- UPS
- Surge protection
- Backup power
- Generators
- Dual power supplies
- Power monitoring
Not every organization needs all of these.
A small startup may use:
UPS + cloud services + provider redundancy + documented recovery procedures.
A data center may require much stronger power resilience.
8. Protect Critical Equipment From Physical Damage
Equipment should be appropriately located and protected.
Consider:
- Secure equipment rooms
- Equipment racks
- Cable protection
- Protection from accidental impact
- Protection from water
- Protection from excessive heat
- Protection from unauthorized movement
This also connects with A.7.8 – Equipment Siting and Protection.
9. Consider Natural Disasters
Organizations should consider natural threats relevant to their location.
Examples:
- Flooding
- Earthquake
- Cyclone
- Severe storm
- Lightning
- Extreme heat
- Wildfire where relevant
The risk assessment should be location-specific.
A company should not simply copy a generic disaster list into its ISMS.
10. Protect Physical Records and Media
Physical environmental threats can affect:
- Contracts
- Customer records
- HR records
- Financial documents
- Backup media
- Paper-based operational records
Controls may include:
- Secure cabinets
- Fire-resistant storage where justified
- Off-site storage
- Digital backups
- Environmental protection
- Controlled access
11. Consider Third-Party Facilities
Many organizations use third parties for:
- Cloud hosting
- Data centers
- Colocation
- Office space
- Backup storage
- Managed infrastructure
In such cases, the organization may not directly control the physical environment.
It should therefore understand:
- Which controls the provider operates
- Which risks remain with the organization
- What contractual protections exist
- What assurance information is available
Examples of assurance may include:
- SOC reports
- ISO certifications
- Facility assessments
- Supplier security assessments
- Contractual commitments
12. Connect A.7.5 With Business Continuity
Physical and environmental threats can cause business disruption.
Therefore, A.7.5 should connect with:
- Business continuity
- Disaster recovery
- Backup
- ICT recovery
- Incident management
For example:
Fire → Office unavailable → Employees relocate → Critical systems continue through cloud services → Business operations continue
This connects A.7.5 with:
- A.5.29 – Information Security During Disruption
- A.5.30 – ICT Readiness for Business Continuity
- Backup and recovery processes
Startup Example
Consider a 30-person SaaS startup.
The company uses:
- AWS for production
- Google Workspace
- Company laptops
- Office networking equipment
- A small network room
- Physical HR/finance records
The startup identifies:
Risk 1: Power Failure
The network room has a UPS.
Risk 2: Heat
The network room has appropriate cooling.
Risk 3: Water
The company identifies plumbing risks and avoids placing equipment directly below water pipes.
Risk 4: Fire
The office building provides fire detection and firefighting arrangements.
Risk 5: Laptop Damage
Employees are instructed to protect company devices from environmental damage during remote work and travel.
Risk 6: Cloud Infrastructure
AWS provides the underlying data-center infrastructure, while the startup evaluates the provider through its supplier/cloud security process.
This provides a risk-based A.7.5 implementation without requiring the startup to operate its own data center.
Physical and Environmental Threat Register
A startup can maintain a simple register:
| Threat | Location | Asset | Risk | Control | Owner | Review |
|---|---|---|---|---|---|---|
| Fire | Office | All equipment | High | Building fire system | Facilities | Annual |
| Power failure | Network room | Network equipment | High | UPS | IT | Quarterly |
| Water leak | Network room | Network equipment | Medium | Location assessment | Facilities | Annual |
| Heat | Network room | Network equipment | High | HVAC | IT | Quarterly |
| Flood | Office | Physical records | Medium | Off-site backup | Operations | Annual |
| Theft | Office | Laptops | Medium | Controlled access | IT | Quarterly |
Environmental Monitoring Register
Where monitoring is appropriate:
| Area | Parameter | Threshold | Monitoring Method | Alert | Responsible Team |
|---|---|---|---|---|---|
| Network Room | Temperature | Defined limit | Sensor | Email/Alert | IT |
| Network Room | Humidity | Defined limit | Sensor | Alert | IT |
| Equipment Room | Water | Detection | Sensor | Alert | Facilities |
| Network Room | Power | Failure | UPS | Alert | IT |
Thresholds should be determined according to the equipment and facility requirements rather than arbitrary values.
Business Continuity Connection
A.7.5 should not be considered only a facilities issue.
Consider:
What happens if our office, equipment room or physical infrastructure becomes unavailable?
For example:
Scenario
Office fire
↓
Office unavailable
↓
Employees cannot work from the office
↓
Cloud production remains operational
↓
Employees move to remote work/alternate location
↓
Business operations continue
This is where physical protection and business continuity work together.
What About Fully Cloud-Based Startups?
A cloud-based startup may have very limited physical infrastructure.
However, it can still have:
- Employee laptops
- Networking equipment
- Office facilities
- Physical records
- Backup devices
- Home-working environments
The startup should identify what it actually owns or controls.
For infrastructure operated by cloud providers, the startup should assess relevant provider controls rather than pretending it operates the physical data center.
Practical Approach
Own facilities → Assess directly
Shared facilities → Understand shared responsibilities
Cloud provider facilities → Evaluate provider assurance
Audit Evidence for A.7.5
An auditor may request:
Policies
- Physical Security Policy
- Environmental Security Procedure
- Business Continuity Policy
- Disaster Recovery Procedure
Risk Assessments
- Physical Security Risk Assessment
- Environmental Threat Assessment
- Business Continuity Risk Assessment
- Facility Risk Assessment
Registers
- Physical and Environmental Threat Register
- Critical Equipment Register
- Environmental Monitoring Register
Operational Evidence
- Fire inspection records
- Fire alarm testing
- HVAC maintenance
- UPS testing
- Generator maintenance
- Water-leak monitoring
- Environmental monitoring
- Facility inspection records
Supplier Evidence
Where applicable:
- Cloud provider assurance reports
- Data-center certifications
- Supplier assessments
- Colocation agreements
- Facility security documentation
Audit Checklist for A.7.5
An auditor may ask:
Risk Identification
- What physical and environmental threats have you identified?
- How did you identify them?
- Which threats are relevant to your location?
Fire
- How is fire risk managed?
- Are fire detection and firefighting arrangements available?
- Are inspections performed?
Water
- What is your risk of water leakage or flooding?
- How are critical systems protected?
Power
- What happens during a power outage?
- Do you use UPS or backup power?
- How are these controls maintained?
Temperature
- How do you protect critical equipment from overheating?
- Is temperature monitored where necessary?
Natural Disasters
- Which natural disasters are relevant to your location?
- How do they affect business continuity?
Third Parties
- Which physical facilities are outsourced?
- How do you assess their physical and environmental controls?
Evidence
- Can you show your physical/environmental risk assessment?
- Can you show recent facility inspection or maintenance records?
- Can you demonstrate testing of relevant controls?
Common Mistakes
1. Creating a Generic Threat List
Listing:
Fire, flood, earthquake, cyclone…
is not the same as conducting a risk assessment.
The organization should identify threats relevant to its actual environment.
2. Ignoring Power Failure
Power interruptions can affect:
- Availability
- Data integrity
- Network infrastructure
- Security systems
Power should be considered where relevant.
3. Ignoring Water
Water damage is often overlooked when organizations focus heavily on cybersecurity.
4. No Evidence of Maintenance
Having an UPS or HVAC system is not enough.
The organization should consider whether appropriate maintenance and testing evidence exists.
5. Treating the Cloud as a Complete Solution
Cloud providers protect their infrastructure, but the organization still has responsibilities for its own devices, offices, information and cloud configuration.
6. Ignoring Remote Workers
Company laptops used from homes, hotels and other locations remain physical assets.
The organization should consider environmental and physical risks associated with remote work.
7. No Connection to Business Continuity
Physical threats should be considered in the organization’s continuity and recovery planning where relevant.
8. Overengineering
A small SaaS startup does not necessarily need:
- A generator
- A dedicated data center
- Multiple environmental sensors
- Specialized fire suppression
- Redundant electrical systems
Controls should be proportional to risk.
Practical Startup Implementation Model
A startup can implement A.7.5 using this lifecycle:
Identify → Assess → Protect → Monitor → Maintain → Prepare → Respond → Recover → Improve
Identify
Identify assets and facilities that could be affected.
Assess
Identify relevant physical and environmental threats.
Protect
Implement appropriate preventive controls.
Monitor
Monitor important environmental conditions where necessary.
Maintain
Maintain fire, power, cooling and other protective systems.
Prepare
Include significant threats in continuity and recovery planning.
Respond
Define what happens when a physical/environmental event occurs.
Recover
Restore affected systems, equipment and operations.
Improve
Learn from incidents, tests and assessments.
Policy vs. Process vs. Evidence
| Element | Example |
|---|---|
| Policy | Physical and Environmental Security Policy |
| Process | Environmental Risk Management Process |
| Procedure | Fire / Power Failure Response Procedure |
| Risk Assessment | Physical and Environmental Threat Assessment |
| Control | UPS, fire detection, HVAC |
| Monitoring | Temperature sensor |
| Record | UPS test report |
| Evidence | Fire inspection certificate |
| Review | Annual facility risk review |
Important Principle
Buying a security or environmental control is not the same as demonstrating that it works.
For example:
UPS installed = control exists.
UPS tested and maintained = evidence that the control is being managed.
Relationship With Other ISO 27001 Controls
A.7.5 connects closely with:
- A.5.9 – Inventory of information and other associated assets
- A.5.24 – Information security incident management planning and preparation
- A.5.26 – Response to information security incidents
- A.5.29 – Information security during disruption
- A.5.30 – ICT readiness for business continuity
- A.6.7 – Remote working
- A.7.1 – Physical security perimeters
- A.7.2 – Physical entry controls
- A.7.3 – Securing offices, rooms and facilities
- A.7.4 – Physical security monitoring
- A.7.6 – Working in secure areas
- A.7.8 – Equipment siting and protection
- A.7.9 – Security of assets off-premises
- A.8.13 – Information backup
Simple Relationship
A.7.3
Secures the facility.
↓
A.7.4
Monitors physical security.
↓
A.7.5
Protects against physical and environmental threats.
↓
A.5.29 / A.5.30
Maintains security and ICT readiness during disruption.
Useful Resources and Draft Documents
Organizations implementing A.7.5 may consider creating:
- Physical and Environmental Security Policy
[Insert Draft Document Link] - Physical and Environmental Threat Assessment
[Insert Draft Document Link] - Physical and Environmental Risk Assessment
[Insert Draft Document Link] - Physical and Environmental Threat Register
[Insert Draft Document Link] - Facility Security Checklist
[Insert Draft Document Link] - Environmental Monitoring Register
[Insert Draft Document Link] - Server Room Environmental Checklist
[Insert Draft Document Link] - UPS Testing Checklist
[Insert Draft Document Link] - Fire Safety Inspection Checklist
[Insert Draft Document Link] - Water Leakage / Flood Risk Checklist
[Insert Draft Document Link] - Environmental Incident Report
[Insert Draft Document Link] - Business Continuity Scenario Assessment
[Insert Draft Document Link] - Physical Security Inspection Checklist
[Insert Draft Document Link]
Questions an Auditor May Ask Management
“What physical and environmental threats have you identified?”
The organization should be able to demonstrate a risk-based assessment rather than simply provide a generic list.
“How do you protect critical equipment from fire?”
The answer should reflect the actual facility and available controls.
“What happens if your office loses power?”
The organization should explain the impact and relevant continuity measures.
“What happens if water enters your network room?”
The organization should demonstrate that the risk has been considered and appropriate controls are in place.
“How do you know your UPS/HVAC/fire systems are functioning?”
The organization should provide relevant maintenance, inspection or testing evidence.
“Your production environment is hosted by a cloud provider. How do you assess physical security?”
The organization should explain how relevant supplier/cloud assurance is evaluated.
“What physical risks have you considered for your location?”
The answer should be specific to the organization’s actual location and operating environment.
Startup-Focused Quick Summary
A startup can approach A.7.5 practically.
Step 1 — Identify
What physical assets and facilities are important?
Step 2 — Assess
What could damage or disrupt them?
Think about:
- Fire
- Water
- Heat
- Humidity
- Power
- Flood
- Severe weather
- Physical damage
Step 3 — Protect
Implement appropriate controls.
Step 4 — Monitor
Monitor important environmental conditions where necessary.
Step 5 — Maintain
Test and maintain critical protective systems.
Step 6 — Prepare
Include significant physical threats in business continuity planning.
Step 7 — Recover
Know how critical operations will continue or be restored.
Simple Startup Principle
Don’t create a list of every possible disaster. Identify the physical and environmental threats that could realistically affect your business and protect against the ones that matter.
Startup-Focused Final Takeaway
A.7.5 reminds organizations that information security can be affected by events that have nothing to do with hacking.
A fire, flood, power outage, overheating server room, water leak or severe weather event can cause:
Physical event → Equipment damage → System outage → Information-security impact → Business disruption
A practical implementation is:
Identify assets → Identify threats → Assess risk → Apply controls → Monitor → Maintain → Prepare → Respond → Recover → Improve
For a startup, the objective is not to build a data center-level disaster protection system.
The objective is to ensure that:
The physical and environmental risks that could affect your information, systems, equipment and business operations are identified, assessed and appropriately controlled.
