ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 4. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 7.1: Physical Security Perimeters

ISO 27001 Annex A 7.1: Physical Security Perimeters

What is ISO 27001 Annex A 7.1 – Physical Security Perimeters?

ISO 27001 Annex A 7.1 requires organizations to define and use security perimeters to protect areas where information and other associated assets are located.

A physical security perimeter is a boundary designed to control and restrict physical access to areas that contain information, systems, equipment, or other assets that need protection.

Examples include:

  • Company offices
  • Server rooms
  • Data centers
  • Network equipment rooms
  • Secure storage areas
  • Archive rooms
  • Restricted work areas
  • Security operations areas
  • Areas containing confidential records
  • Production facilities

Simple Explanation

Know which physical areas need protection, define their boundaries, and control who can physically enter them.

The purpose is not to turn every office into a high-security facility.

The objective is to ensure that areas containing sensitive information or important assets receive protection appropriate to their risks.


Why is Annex A 7.1 Important?

Physical security is sometimes overlooked because modern organizations increasingly use cloud services and remote working.

However, organizations may still have:

  • Employee laptops
  • Network equipment
  • Backup devices
  • Printed confidential information
  • Employee records
  • Customer documents
  • Physical security keys
  • Network infrastructure
  • Office equipment
  • Physical media

Unauthorized physical access can result in:

  • Theft
  • Unauthorized viewing of information
  • Device tampering
  • Network compromise
  • Data leakage
  • Damage to equipment
  • Loss of physical records
  • Installation of unauthorized devices
  • Business disruption

Simple Principle

If unauthorized people can physically reach an important asset, technical security controls may not be enough.


What Does Annex A 7.1 Require?

The organization should define and establish appropriate physical security perimeters around areas where sensitive information and associated assets require protection.

The perimeter should be appropriate to:

  • Information security risks
  • Asset sensitivity
  • Business requirements
  • Legal and regulatory requirements
  • Customer requirements
  • Physical location
  • Threat environment

A physical security perimeter may be:

  • A locked office
  • A restricted floor
  • A locked server room
  • A controlled data center
  • A secure archive
  • A fenced facility
  • A reception-controlled area
  • A combination of physical and electronic access controls

The organization should determine what level of perimeter protection is appropriate for each location.


What is a Physical Security Perimeter?

A physical security perimeter establishes a boundary between:

Protected Area

and

Uncontrolled or Less-Controlled Area

For example:

Public Area
     ↓
Reception
     ↓
Employee-Only Area
     ↓
Restricted IT Area
     ↓
Server / Network Room

Each boundary can have different security requirements.


Physical Security Zones

A startup can use a simple zoning model.

ZoneExampleTypical Access
PublicReception / waiting areaVisitors
GeneralEmployee workspaceEmployees
RestrictedFinance / HR areaAuthorized employees
Highly RestrictedServer/network roomIT/security personnel
CriticalSpecialized infrastructure areaSpecifically authorized personnel

Not every organization needs five physical security zones.

The number of zones should reflect actual risk.


Activities Required to Implement Annex A 7.1

Step 1: Identify Physical Locations

Create an inventory of locations where organizational information or associated assets are physically present.

Examples:

  • Head office
  • Branch office
  • Data center
  • Server room
  • Storage room
  • Records room
  • Network closet
  • Secure archive
  • Warehouse

For a cloud-first startup, this list may be surprisingly short.


Step 2: Identify What Needs Physical Protection

Determine what assets are located at each physical location.

For example:

LocationAssetsSensitivity
OfficeEmployee laptopsHigh
HR roomEmployee recordsHigh
Finance roomFinancial recordsHigh
Network roomNetwork equipmentHigh
Server roomServersCritical
ReceptionVisitor informationLow/Medium
Storage roomArchived recordsMedium/High

This helps determine where stronger physical boundaries are needed.


Step 3: Define Physical Security Perimeters

Determine where access restrictions should begin.

For example:

Perimeter 1 – Building

Controls access to the overall office.

Perimeter 2 – Employee Area

Restricts access to employees and authorized visitors.

Perimeter 3 – Restricted Area

Protects sensitive departments or assets.

Perimeter 4 – Server/Network Room

Provides stronger restrictions for critical infrastructure.

The organization’s actual structure may be simpler.


Step 4: Define Access Requirements

For each protected area, determine:

  • Who can enter?
  • Why do they need access?
  • How is access granted?
  • Who approves it?
  • How is access removed?
  • How are visitors handled?
  • How are contractors handled?
  • Is access logged?

For example:

AreaAuthorized People
General officeEmployees
HR areaHR personnel + authorized management
FinanceFinance personnel + authorized management
Network roomIT/security personnel
Server roomAuthorized infrastructure personnel
Records archiveAuthorized records personnel

Step 5: Implement Physical Access Controls

Possible controls include:

  • Locks
  • Electronic access control
  • Access cards
  • Biometrics
  • Security guards
  • Reception controls
  • Turnstiles
  • Fences
  • Doors
  • Security gates
  • Visitor management systems

The control should be proportional to the risk.

A small startup may not need biometric access control for a normal office.

A locked door and controlled access may be sufficient.


Step 6: Define Visitor Controls

Visitors should not automatically receive unrestricted physical access.

Depending on risk, the organization may:

  • Require visitor registration
  • Verify identity
  • Issue visitor badges
  • Restrict visitor areas
  • Escort visitors
  • Record visitor entry/exit
  • Restrict photography
  • Restrict access to sensitive areas

For example:

Visitor arrives

→ Reception registration

→ Identity verification

→ Visitor badge

→ Host confirmation

→ Escort where required

→ Restricted access

→ Visitor departure

→ Badge returned


Step 7: Protect Sensitive Areas

Certain areas may require stronger physical controls.

Examples:

Server Room

Possible controls:

  • Locked door
  • Restricted access list
  • Access logs
  • Environmental monitoring
  • CCTV where appropriate
  • Visitor restrictions

HR Records Room

Possible controls:

  • Restricted access
  • Locked cabinets
  • Authorized personnel only
  • Confidential document handling

Network Room

Possible controls:

  • Restricted access
  • Locked cabinets/racks
  • Visitor restrictions
  • Asset identification

Step 8: Consider Physical Security During Remote and Hybrid Work

Modern organizations may have fewer physical offices.

However, employees may still have organizational assets at:

  • Home
  • Hotels
  • Coworking spaces
  • Customer locations
  • Temporary offices

A.7.1 primarily concerns organizational physical premises and protected areas, but physical security expectations should work together with:

  • A.6.7 Remote Working
  • A.7.7 Clear Desk and Clear Screen
  • A.8.1 User Endpoint Devices

Startup Example

Consider a 30-person SaaS startup operating from a leased office.

The office contains:

  • Employee laptops
  • Network equipment
  • Backup devices
  • HR documents
  • Finance records

The startup defines:

Zone 1 – Reception

Visitors allowed.

Zone 2 – General Office

Employees allowed.

Zone 3 – HR/Finance

Authorized personnel only.

Zone 4 – Network Room

IT/security personnel only.

The network room is locked.

Visitors cannot enter the network room without authorization and appropriate supervision.

Physical Security Structure

Building
   ↓
Reception
   ↓
Employee Area
   ↓
Restricted HR / Finance
   ↓
Locked Network Room

The organization documents these boundaries and maintains appropriate access records.


Cloud-First Startup Example

Now consider a 20-person SaaS startup that is almost completely cloud-based.

The company uses:

  • AWS
  • GitHub
  • Microsoft 365
  • Slack
  • Remote work

There is no company-owned server room.

The organization may still have:

  • Laptops
  • Office equipment
  • Network equipment
  • Employee records
  • Printed documents

For this organization, A.7.1 does not mean creating a server room simply to satisfy ISO 27001.

Instead, it should:

  • Define the office boundary
  • Control office access
  • Protect sensitive areas
  • Secure physical devices
  • Use secure cloud providers
  • Address physical infrastructure through supplier/cloud security controls

This is a good example of risk-based implementation.


Startup-Focused Quick Summary

A small startup can begin with a simple model:

Identify

Where are important physical assets located?

Classify

Which locations need restricted access?

Define

Establish physical security boundaries.

Control

Use appropriate locks/access controls.

Manage Visitors

Control visitor access to protected areas.

Protect Critical Areas

Apply stronger controls to server/network/records areas.

Review

Review physical access when people join, leave, or change roles.

Evidence

Maintain enough records to demonstrate that the controls operate.


Example Physical Security Zone Register

A startup can maintain a simple register:

ZoneLocationAssetsAccess LevelControl
Z01ReceptionVisitor recordsPublic/ControlledReception
Z02General OfficeLaptopsEmployeeDoor access
Z03HR RoomEmployee PIIRestrictedLocked door
Z04Finance RoomFinancial recordsRestrictedLocked door
Z05Network RoomNetwork equipmentHighly RestrictedElectronic lock
Z06Records RoomArchived recordsRestrictedLocked room

The register should reflect the actual organization’s environment.


Physical Security Perimeter Assessment

For each location, ask:

QuestionExample
What assets are located here?Laptops / records / network equipment
Is sensitive information present?Yes
Who needs access?Employees / IT
Who should not have access?General visitors
How is access controlled?Key/card
Are visitors controlled?Yes
Are access rights reviewed?Periodically
Is the area monitored?Where appropriate
What happens if access is lost?Lock replacement / access revocation
Are physical risks documented?Risk assessment

Physical Security Perimeter vs. Physical Access Control

These concepts are related but not identical.

Physical Security Perimeter

Defines the boundary that needs protection.

Example:

“The network room is a restricted area.”

Physical Access Control

Controls who can cross that boundary.

Example:

“Only authorized infrastructure personnel can unlock the network room.”

Therefore:

Perimeter = Where protection begins

Access control = Who can enter


Audit Evidence for Annex A 7.1

An auditor may request:

Policies

  • Physical Security Policy
  • Physical Access Control Policy
  • Visitor Management Policy
  • Office Security Policy

Procedures

  • Physical Access Procedure
  • Visitor Management Procedure
  • Restricted Area Access Procedure
  • Key/Card Management Procedure
  • Physical Security Incident Procedure

Registers

  • Physical Security Zone Register
  • Authorized Access List
  • Visitor Register
  • Key Register
  • Access Card Register
  • Physical Asset Register

Technical/Operational Evidence

  • Door access logs
  • Access control configuration
  • Visitor records
  • CCTV arrangements where applicable
  • Photographs/layouts of restricted areas where appropriate
  • Security guard records
  • Physical access reviews
  • Access revocation records

Risk Evidence

  • Physical security risk assessment
  • Business impact assessment
  • Physical security review
  • Incident records

Audit Checklist for Annex A 7.1

Audit QuestionEvidence
Are physical security boundaries defined?Zone register / floor plan
Are sensitive areas identified?Risk assessment
Are physical assets identified?Asset inventory
Are restricted areas established?Physical security policy
Is physical access controlled?Access-control records
Are critical areas protected?Server/network room controls
Are visitors controlled?Visitor procedure/register
Are contractors controlled?Visitor/access records
Are physical access rights authorized?Access list
Are access rights removed when no longer required?Access revocation records
Are physical access logs maintained where appropriate?Access logs
Are physical security incidents handled?Incident records
Are physical security risks periodically reviewed?Risk review
Are controls appropriate to the organization’s risks?Risk assessment

Common Mistakes

1. Assuming the Office Door Is Enough

Simply having a locked office does not necessarily demonstrate appropriate protection of sensitive areas.

The organization should consider:

  • What is inside?
  • Who can enter?
  • Which areas are restricted?
  • How are visitors handled?

2. No Physical Security Zones

Some organizations treat the entire office as one security area.

This may be inappropriate if:

  • HR records are stored there
  • Network equipment is present
  • Sensitive documents are accessible
  • Server/network rooms exist

3. Visitors Can Walk Anywhere

A visitor should not automatically be able to walk into:

  • Server rooms
  • Network rooms
  • HR offices
  • Finance areas
  • Records rooms

4. No Access Revocation

When an employee leaves, physical access may remain active.

Examples:

  • Access card still works
  • Key not returned
  • Building access not revoked

Physical access should form part of the joiner-mover-leaver process.


5. Forgetting Contractors

Cleaning staff, maintenance personnel, IT contractors and other service providers may have physical access.

Their access should be managed according to risk.


6. Creating Excessive Controls

A small startup does not necessarily need:

  • Security guards
  • Biometrics
  • Multiple access-control layers
  • 24/7 CCTV

The organization should implement controls proportionate to its risks.


7. Ignoring Physical Assets Because “Everything Is in the Cloud”

Cloud computing reduces some physical infrastructure requirements but does not eliminate physical security responsibilities.

Organizations still have:

  • Laptops
  • Phones
  • Security keys
  • Printed documents
  • Office infrastructure

Cloud provider physical security is addressed through supplier/cloud security arrangements.


Practical Startup Implementation Model

A practical implementation model is:

Identify

Identify physical locations and assets.

Assess

Assess physical security risks.

Define

Define security boundaries and zones.

Authorize

Determine who should have physical access.

Control

Implement locks, cards, reception, visitor controls or other measures.

Monitor

Maintain appropriate access and visitor records.

Review

Review access rights and physical security periodically.

Revoke

Remove physical access when employment or authorization ends.

Respond

Handle physical security incidents.

Improve

Update controls when risks or locations change.

Simple Model

Identify → Define → Restrict → Monitor → Review → Improve


Policy vs. Process vs. Evidence

LayerExample
PolicySensitive areas must be physically protected
ProcedureAccess to restricted areas requires authorization
Zone DefinitionNetwork room = highly restricted
Technical ControlElectronic door lock
ProcessEmployee access approval
EvidenceDoor access log
EvidenceVisitor register
EvidenceAccess review
EvidenceAccess revocation
ImprovementPhysical security risk review

An auditor should be able to see a connection between the organization’s documented requirements and the physical controls that actually exist.


Relationship With Other ISO 27001 Controls

A.5.9 – Inventory of Information and Other Associated Assets

Helps identify the physical assets that require protection.

A.5.11 – Return of Assets

Ensures physical assets are returned when they are no longer required.

A.5.15 – Access Control

Provides the broader access-control principles that also apply to physical access.

A.5.18 – Access Rights

Supports the review and removal of access rights.

A.6.5 – Responsibilities After Termination or Change of Employment

Supports physical access removal when employees leave or change roles.

A.6.7 – Remote Working

Addresses security when work is performed outside organizational premises.

A.7.2 – Physical Entry

Builds on the perimeter by controlling entry into protected areas.

A.7.3 – Securing Offices, Rooms and Facilities

Addresses protection of specific offices, rooms and facilities.

A.7.4 – Physical Security Monitoring

Addresses monitoring of physical premises where appropriate.

A.7.7 – Clear Desk and Clear Screen

Protects information exposed in physical work environments.

A.8.1 – User Endpoint Devices

Protects laptops, mobile devices and other endpoints.


A.7.1 vs. A.7.2

These two controls are closely connected.

ControlMain Question
A.7.1 Physical Security PerimetersWhere does the protected physical area begin and end?
A.7.2 Physical EntryHow do we control who enters that protected area?

Example

A.7.1

The network room is designated as a restricted physical security area.

A.7.2

Only authorized IT personnel can enter the network room using controlled access.

So:

A.7.1 defines the boundary. A.7.2 controls entry through that boundary.


Questions an Auditor May Ask

“What are your physical security perimeters?”

Show the organization’s physical security zones or documented boundaries.

“Which areas are restricted?”

Identify areas such as:

  • HR
  • Finance
  • Server/network rooms
  • Records storage
  • Other sensitive areas

“How do you determine which areas need protection?”

Show the physical security risk assessment.

“Who can access the server/network room?”

Show the authorized access list.

“How are visitors managed?”

Show the visitor process and sample records.

“What happens when an employee leaves?”

Demonstrate physical access-card/key revocation and asset return.

“How do you protect physical records?”

Show restricted areas, locked storage, access controls and records-management requirements.

“You are a cloud-first company. What physical infrastructure do you have?”

Explain the actual physical assets and premises under the organization’s control and how cloud-provider physical security is addressed through supplier/cloud arrangements.


Useful Documents and Resources

A startup implementing A.7.1 may maintain:

  1. Physical Security Policy
    [Insert Draft Document Link]
  2. Physical Security Perimeter Procedure
    [Insert Draft Document Link]
  3. Physical Security Zone Register
    [Insert Draft Document Link]
  4. Physical Security Risk Assessment
    [Insert Draft Document Link]
  5. Physical Access Control Policy
    [Insert Draft Document Link]
  6. Physical Access Authorization Form
    [Insert Draft Document Link]
  7. Restricted Area Access List
    [Insert Draft Document Link]
  8. Visitor Management Procedure
    [Insert Draft Document Link]
  9. Visitor Register
    [Insert Draft Document Link]
  10. Physical Access Review Checklist
    [Insert Draft Document Link]
  11. Key and Access Card Register
    [Insert Draft Document Link]
  12. Physical Security Inspection Checklist
    [Insert Draft Document Link]
  13. Physical Security Incident Report
    [Insert Draft Document Link]
  14. Physical Security Audit Checklist
    [Insert Draft Document Link]

Startup-Focused Final Takeaway

Annex A 7.1 is about establishing clear physical boundaries around areas that need protection.

A practical startup approach is:

Identify physical locations
↓
Identify assets and information
↓
Assess physical risks
↓
Define security zones/perimeters
↓
Determine authorized access
↓
Implement appropriate physical controls
↓
Control visitors and contractors
↓
Review physical access
↓
Revoke access when no longer required
↓
Maintain evidence

The key audit question is:

Have we identified the physical areas that require protection and established appropriate security boundaries around them?

For a startup, the objective is not to create unnecessary physical-security complexity.

A 20-person cloud-native SaaS company may need only a few practical controls, while a company operating its own data center or handling highly sensitive physical records may require significantly stronger protection.

Protect the physical boundary according to the value and risk of what lies behind it.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *