ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 4. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 7.5 Protecting against physical and environmental threats

ISO 27001 Annex A 7.5 Protecting against physical and environmental threats

What is ISO 27001 Annex A 7.5 – Protecting Against Physical and Environmental Threats?

ISO 27001 Annex A 7.5 focuses on protecting information and other associated assets against physical and environmental threats.

These threats can come from:

  • Fire
  • Flood
  • Water leakage
  • Extreme temperatures
  • High humidity
  • Dust
  • Smoke
  • Power failure
  • Electrical problems
  • Natural disasters
  • Severe weather
  • Earthquakes
  • Physical damage
  • Civil disturbances
  • Other environmental or facility-related events

The objective is to reduce the likelihood that a physical or environmental event will:

  • Damage information assets
  • Interrupt business operations
  • Destroy equipment
  • Cause data loss
  • Affect availability of systems
  • Create safety or security incidents
  • Prevent recovery of critical services

Simple Explanation

A.7.5 is about protecting information, systems and equipment from things such as fire, water, heat, power problems and other physical or environmental threats.

A company can have excellent cybersecurity controls and still suffer a major security incident if a fire destroys its office equipment or a water leak damages critical infrastructure.


Why is A.7.5 Important?

Information security is not only about confidentiality.

Physical and environmental events can affect all three parts of the CIA Triad:

Confidentiality

Physical damage can result in:

  • Loss of confidential documents
  • Theft of damaged equipment
  • Unauthorized recovery of storage media

Integrity

Physical events can:

  • Damage systems
  • Corrupt data
  • Interrupt processing
  • Damage storage devices

Availability

Physical events can cause:

  • Server outages
  • Network outages
  • Power failures
  • Office shutdown
  • Loss of critical equipment

Example

A startup’s network equipment is located under a water pipe.

A pipe leak damages the equipment.

The organization may experience:

Water leak → Network equipment failure → Internet/network outage → Business disruption → Customer impact

This is a physical and environmental information-security risk.

Simple Principle

Protect critical information assets from the physical environment just as you protect them from cyber threats.


What Does A.7.5 Require?

Organizations should identify and protect against relevant physical and environmental threats.

The controls should be based on:

  • Risk assessment
  • Location
  • Building characteristics
  • Criticality of assets
  • Type of information processed
  • Business continuity requirements
  • Local environmental conditions
  • Supplier/facility arrangements
  • Legal and regulatory requirements

Not every organization faces the same threats.

For example:

A company in a flood-prone area may have significant water and flooding risks.

A company operating in an area with frequent power instability may need stronger power-continuity measures.

A small cloud-based startup with no server room may have limited equipment-related environmental risks.


Physical Threats vs Environmental Threats

These terms can overlap.

TypeExamples
Physical ThreatsTheft, vandalism, impact, unauthorized physical interference
Environmental ThreatsFire, flood, water, heat, humidity, smoke
Utility ThreatsPower failure, electrical surge, HVAC failure
Natural ThreatsEarthquake, storm, extreme weather
Facility ThreatsBuilding damage, plumbing failure, structural problems

The organization should consider threats relevant to its actual environment rather than creating a generic list.


A.7.3 vs A.7.4 vs A.7.5

These controls are related but have different purposes.

ControlMain Purpose
A.7.3Secure offices, rooms and facilities
A.7.4Monitor physical security
A.7.5Protect against physical and environmental threats

Example: Server Room

A.7.3

Secure the server room and its physical environment.

A.7.4

Monitor relevant physical security activity.

A.7.5

Protect the equipment against fire, water, heat, humidity, power and other relevant environmental threats.


Activities Required to Implement A.7.5

1. Identify Critical Information Assets

Start with the organization’s asset inventory.

Identify assets that could be affected by physical or environmental threats.

Examples:

  • Servers
  • Network equipment
  • Firewalls
  • Storage systems
  • Backup devices
  • Laptops
  • Physical records
  • Communication systems
  • Power infrastructure
  • Critical office equipment

This connects A.7.5 with A.5.9 – Inventory of Information and Other Associated Assets.


2. Identify Physical and Environmental Threats

Conduct a facility-level risk assessment.

Consider:

Fire

  • Is there fire detection?
  • Is fire suppression available?
  • Are emergency procedures defined?

Water

  • Are critical systems located near plumbing?
  • Is there a risk of flooding?
  • Are water-leak detection mechanisms appropriate?

Temperature

  • Could excessive heat damage equipment?
  • Is cooling available?

Humidity

  • Could humidity affect equipment or storage?

Power

  • What happens during a power outage?
  • Are critical systems protected?

Natural Events

Consider relevant local risks such as:

  • Earthquakes
  • Floods
  • Cyclones
  • Storms
  • Extreme heat
  • Lightning

Other Threats

Depending on the environment:

  • Dust
  • Smoke
  • Chemical exposure
  • Construction activity
  • Vibration
  • Pest infestation

3. Conduct a Physical and Environmental Risk Assessment

A simple risk assessment may look like this:

ThreatAssetLikelihoodImpactRiskExisting ControlAction
FireNetwork equipmentMediumHighHighFire systemVerify inspection
Water leakNetwork roomLowHighMediumRoom locationRelocate equipment
Power failureNetwork equipmentHighHighHighUPSTest UPS
HeatNetwork equipmentMediumHighHighHVACTemperature monitoring
FloodOfficeLowHighMediumBuilding controlsReview continuity plan

The exact risk methodology can vary according to the organization’s ISMS.


4. Protect Against Fire

Fire protection can include:

  • Smoke detection
  • Fire alarms
  • Fire extinguishers
  • Fire suppression systems
  • Appropriate fire-rated infrastructure
  • Emergency procedures
  • Evacuation plans
  • Regular inspections

The appropriate controls depend on:

  • Building type
  • Equipment
  • Fire risk
  • Local requirements
  • Facility arrangements

Organizations should not improvise specialized fire-suppression systems without appropriate professional guidance.


5. Protect Against Water and Flooding

Water can cause significant damage to:

  • Servers
  • Network switches
  • Storage devices
  • Electrical systems
  • Physical records
  • Backup equipment

Consider:

  • Location of equipment
  • Plumbing routes
  • Roof leakage
  • Drainage
  • Flood risk
  • Water detection
  • Equipment elevation
  • Appropriate physical barriers

Simple Example

Instead of placing critical network equipment directly below a water pipe:

Identify the risk → relocate equipment → protect the room → monitor where appropriate.


6. Protect Against Temperature and Humidity

Information-processing equipment may require appropriate environmental conditions.

Consider:

  • Air conditioning
  • HVAC maintenance
  • Temperature monitoring
  • Humidity monitoring
  • Alerts for abnormal conditions

For critical environments, organizations may configure alerts for conditions that could damage equipment.


7. Protect Against Power Failure

Power interruptions can cause:

  • System shutdown
  • Data corruption
  • Network outages
  • Equipment damage
  • Business disruption

Possible controls include:

  • UPS
  • Surge protection
  • Backup power
  • Generators
  • Dual power supplies
  • Power monitoring

Not every organization needs all of these.

A small startup may use:

UPS + cloud services + provider redundancy + documented recovery procedures.

A data center may require much stronger power resilience.


8. Protect Critical Equipment From Physical Damage

Equipment should be appropriately located and protected.

Consider:

  • Secure equipment rooms
  • Equipment racks
  • Cable protection
  • Protection from accidental impact
  • Protection from water
  • Protection from excessive heat
  • Protection from unauthorized movement

This also connects with A.7.8 – Equipment Siting and Protection.


9. Consider Natural Disasters

Organizations should consider natural threats relevant to their location.

Examples:

  • Flooding
  • Earthquake
  • Cyclone
  • Severe storm
  • Lightning
  • Extreme heat
  • Wildfire where relevant

The risk assessment should be location-specific.

A company should not simply copy a generic disaster list into its ISMS.


10. Protect Physical Records and Media

Physical environmental threats can affect:

  • Contracts
  • Customer records
  • HR records
  • Financial documents
  • Backup media
  • Paper-based operational records

Controls may include:

  • Secure cabinets
  • Fire-resistant storage where justified
  • Off-site storage
  • Digital backups
  • Environmental protection
  • Controlled access

11. Consider Third-Party Facilities

Many organizations use third parties for:

  • Cloud hosting
  • Data centers
  • Colocation
  • Office space
  • Backup storage
  • Managed infrastructure

In such cases, the organization may not directly control the physical environment.

It should therefore understand:

  • Which controls the provider operates
  • Which risks remain with the organization
  • What contractual protections exist
  • What assurance information is available

Examples of assurance may include:

  • SOC reports
  • ISO certifications
  • Facility assessments
  • Supplier security assessments
  • Contractual commitments

12. Connect A.7.5 With Business Continuity

Physical and environmental threats can cause business disruption.

Therefore, A.7.5 should connect with:

  • Business continuity
  • Disaster recovery
  • Backup
  • ICT recovery
  • Incident management

For example:

Fire → Office unavailable → Employees relocate → Critical systems continue through cloud services → Business operations continue

This connects A.7.5 with:

  • A.5.29 – Information Security During Disruption
  • A.5.30 – ICT Readiness for Business Continuity
  • Backup and recovery processes

Startup Example

Consider a 30-person SaaS startup.

The company uses:

  • AWS for production
  • Google Workspace
  • Company laptops
  • Office networking equipment
  • A small network room
  • Physical HR/finance records

The startup identifies:

Risk 1: Power Failure

The network room has a UPS.

Risk 2: Heat

The network room has appropriate cooling.

Risk 3: Water

The company identifies plumbing risks and avoids placing equipment directly below water pipes.

Risk 4: Fire

The office building provides fire detection and firefighting arrangements.

Risk 5: Laptop Damage

Employees are instructed to protect company devices from environmental damage during remote work and travel.

Risk 6: Cloud Infrastructure

AWS provides the underlying data-center infrastructure, while the startup evaluates the provider through its supplier/cloud security process.

This provides a risk-based A.7.5 implementation without requiring the startup to operate its own data center.


Physical and Environmental Threat Register

A startup can maintain a simple register:

ThreatLocationAssetRiskControlOwnerReview
FireOfficeAll equipmentHighBuilding fire systemFacilitiesAnnual
Power failureNetwork roomNetwork equipmentHighUPSITQuarterly
Water leakNetwork roomNetwork equipmentMediumLocation assessmentFacilitiesAnnual
HeatNetwork roomNetwork equipmentHighHVACITQuarterly
FloodOfficePhysical recordsMediumOff-site backupOperationsAnnual
TheftOfficeLaptopsMediumControlled accessITQuarterly

Environmental Monitoring Register

Where monitoring is appropriate:

AreaParameterThresholdMonitoring MethodAlertResponsible Team
Network RoomTemperatureDefined limitSensorEmail/AlertIT
Network RoomHumidityDefined limitSensorAlertIT
Equipment RoomWaterDetectionSensorAlertFacilities
Network RoomPowerFailureUPSAlertIT

Thresholds should be determined according to the equipment and facility requirements rather than arbitrary values.


Business Continuity Connection

A.7.5 should not be considered only a facilities issue.

Consider:

What happens if our office, equipment room or physical infrastructure becomes unavailable?

For example:

Scenario

Office fire

↓

Office unavailable

↓

Employees cannot work from the office

↓

Cloud production remains operational

↓

Employees move to remote work/alternate location

↓

Business operations continue

This is where physical protection and business continuity work together.


What About Fully Cloud-Based Startups?

A cloud-based startup may have very limited physical infrastructure.

However, it can still have:

  • Employee laptops
  • Networking equipment
  • Office facilities
  • Physical records
  • Backup devices
  • Home-working environments

The startup should identify what it actually owns or controls.

For infrastructure operated by cloud providers, the startup should assess relevant provider controls rather than pretending it operates the physical data center.

Practical Approach

Own facilities → Assess directly

Shared facilities → Understand shared responsibilities

Cloud provider facilities → Evaluate provider assurance


Audit Evidence for A.7.5

An auditor may request:

Policies

  • Physical Security Policy
  • Environmental Security Procedure
  • Business Continuity Policy
  • Disaster Recovery Procedure

Risk Assessments

  • Physical Security Risk Assessment
  • Environmental Threat Assessment
  • Business Continuity Risk Assessment
  • Facility Risk Assessment

Registers

  • Physical and Environmental Threat Register
  • Critical Equipment Register
  • Environmental Monitoring Register

Operational Evidence

  • Fire inspection records
  • Fire alarm testing
  • HVAC maintenance
  • UPS testing
  • Generator maintenance
  • Water-leak monitoring
  • Environmental monitoring
  • Facility inspection records

Supplier Evidence

Where applicable:

  • Cloud provider assurance reports
  • Data-center certifications
  • Supplier assessments
  • Colocation agreements
  • Facility security documentation

Audit Checklist for A.7.5

An auditor may ask:

Risk Identification

  • What physical and environmental threats have you identified?
  • How did you identify them?
  • Which threats are relevant to your location?

Fire

  • How is fire risk managed?
  • Are fire detection and firefighting arrangements available?
  • Are inspections performed?

Water

  • What is your risk of water leakage or flooding?
  • How are critical systems protected?

Power

  • What happens during a power outage?
  • Do you use UPS or backup power?
  • How are these controls maintained?

Temperature

  • How do you protect critical equipment from overheating?
  • Is temperature monitored where necessary?

Natural Disasters

  • Which natural disasters are relevant to your location?
  • How do they affect business continuity?

Third Parties

  • Which physical facilities are outsourced?
  • How do you assess their physical and environmental controls?

Evidence

  • Can you show your physical/environmental risk assessment?
  • Can you show recent facility inspection or maintenance records?
  • Can you demonstrate testing of relevant controls?

Common Mistakes

1. Creating a Generic Threat List

Listing:

Fire, flood, earthquake, cyclone…

is not the same as conducting a risk assessment.

The organization should identify threats relevant to its actual environment.


2. Ignoring Power Failure

Power interruptions can affect:

  • Availability
  • Data integrity
  • Network infrastructure
  • Security systems

Power should be considered where relevant.


3. Ignoring Water

Water damage is often overlooked when organizations focus heavily on cybersecurity.


4. No Evidence of Maintenance

Having an UPS or HVAC system is not enough.

The organization should consider whether appropriate maintenance and testing evidence exists.


5. Treating the Cloud as a Complete Solution

Cloud providers protect their infrastructure, but the organization still has responsibilities for its own devices, offices, information and cloud configuration.


6. Ignoring Remote Workers

Company laptops used from homes, hotels and other locations remain physical assets.

The organization should consider environmental and physical risks associated with remote work.


7. No Connection to Business Continuity

Physical threats should be considered in the organization’s continuity and recovery planning where relevant.


8. Overengineering

A small SaaS startup does not necessarily need:

  • A generator
  • A dedicated data center
  • Multiple environmental sensors
  • Specialized fire suppression
  • Redundant electrical systems

Controls should be proportional to risk.


Practical Startup Implementation Model

A startup can implement A.7.5 using this lifecycle:

Identify → Assess → Protect → Monitor → Maintain → Prepare → Respond → Recover → Improve

Identify

Identify assets and facilities that could be affected.

Assess

Identify relevant physical and environmental threats.

Protect

Implement appropriate preventive controls.

Monitor

Monitor important environmental conditions where necessary.

Maintain

Maintain fire, power, cooling and other protective systems.

Prepare

Include significant threats in continuity and recovery planning.

Respond

Define what happens when a physical/environmental event occurs.

Recover

Restore affected systems, equipment and operations.

Improve

Learn from incidents, tests and assessments.


Policy vs. Process vs. Evidence

ElementExample
PolicyPhysical and Environmental Security Policy
ProcessEnvironmental Risk Management Process
ProcedureFire / Power Failure Response Procedure
Risk AssessmentPhysical and Environmental Threat Assessment
ControlUPS, fire detection, HVAC
MonitoringTemperature sensor
RecordUPS test report
EvidenceFire inspection certificate
ReviewAnnual facility risk review

Important Principle

Buying a security or environmental control is not the same as demonstrating that it works.

For example:

UPS installed = control exists.

UPS tested and maintained = evidence that the control is being managed.


Relationship With Other ISO 27001 Controls

A.7.5 connects closely with:

  • A.5.9 – Inventory of information and other associated assets
  • A.5.24 – Information security incident management planning and preparation
  • A.5.26 – Response to information security incidents
  • A.5.29 – Information security during disruption
  • A.5.30 – ICT readiness for business continuity
  • A.6.7 – Remote working
  • A.7.1 – Physical security perimeters
  • A.7.2 – Physical entry controls
  • A.7.3 – Securing offices, rooms and facilities
  • A.7.4 – Physical security monitoring
  • A.7.6 – Working in secure areas
  • A.7.8 – Equipment siting and protection
  • A.7.9 – Security of assets off-premises
  • A.8.13 – Information backup

Simple Relationship

A.7.3

Secures the facility.

↓

A.7.4

Monitors physical security.

↓

A.7.5

Protects against physical and environmental threats.

↓

A.5.29 / A.5.30

Maintains security and ICT readiness during disruption.


Useful Resources and Draft Documents

Organizations implementing A.7.5 may consider creating:

  1. Physical and Environmental Security Policy
    [Insert Draft Document Link]
  2. Physical and Environmental Threat Assessment
    [Insert Draft Document Link]
  3. Physical and Environmental Risk Assessment
    [Insert Draft Document Link]
  4. Physical and Environmental Threat Register
    [Insert Draft Document Link]
  5. Facility Security Checklist
    [Insert Draft Document Link]
  6. Environmental Monitoring Register
    [Insert Draft Document Link]
  7. Server Room Environmental Checklist
    [Insert Draft Document Link]
  8. UPS Testing Checklist
    [Insert Draft Document Link]
  9. Fire Safety Inspection Checklist
    [Insert Draft Document Link]
  10. Water Leakage / Flood Risk Checklist
    [Insert Draft Document Link]
  11. Environmental Incident Report
    [Insert Draft Document Link]
  12. Business Continuity Scenario Assessment
    [Insert Draft Document Link]
  13. Physical Security Inspection Checklist
    [Insert Draft Document Link]

Questions an Auditor May Ask Management

“What physical and environmental threats have you identified?”

The organization should be able to demonstrate a risk-based assessment rather than simply provide a generic list.

“How do you protect critical equipment from fire?”

The answer should reflect the actual facility and available controls.

“What happens if your office loses power?”

The organization should explain the impact and relevant continuity measures.

“What happens if water enters your network room?”

The organization should demonstrate that the risk has been considered and appropriate controls are in place.

“How do you know your UPS/HVAC/fire systems are functioning?”

The organization should provide relevant maintenance, inspection or testing evidence.

“Your production environment is hosted by a cloud provider. How do you assess physical security?”

The organization should explain how relevant supplier/cloud assurance is evaluated.

“What physical risks have you considered for your location?”

The answer should be specific to the organization’s actual location and operating environment.


Startup-Focused Quick Summary

A startup can approach A.7.5 practically.

Step 1 — Identify

What physical assets and facilities are important?

Step 2 — Assess

What could damage or disrupt them?

Think about:

  • Fire
  • Water
  • Heat
  • Humidity
  • Power
  • Flood
  • Severe weather
  • Physical damage

Step 3 — Protect

Implement appropriate controls.

Step 4 — Monitor

Monitor important environmental conditions where necessary.

Step 5 — Maintain

Test and maintain critical protective systems.

Step 6 — Prepare

Include significant physical threats in business continuity planning.

Step 7 — Recover

Know how critical operations will continue or be restored.

Simple Startup Principle

Don’t create a list of every possible disaster. Identify the physical and environmental threats that could realistically affect your business and protect against the ones that matter.


Startup-Focused Final Takeaway

A.7.5 reminds organizations that information security can be affected by events that have nothing to do with hacking.

A fire, flood, power outage, overheating server room, water leak or severe weather event can cause:

Physical event → Equipment damage → System outage → Information-security impact → Business disruption

A practical implementation is:

Identify assets → Identify threats → Assess risk → Apply controls → Monitor → Maintain → Prepare → Respond → Recover → Improve

For a startup, the objective is not to build a data center-level disaster protection system.

The objective is to ensure that:

The physical and environmental risks that could affect your information, systems, equipment and business operations are identified, assessed and appropriately controlled.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *