Annex A.7: Physical Controls
Fourteen controls from perimeters to clear desks. The 2022 addition — physical security monitoring — formalised what assessors already expected: premises watched, not just locked. For cloud-first organisations this theme shrinks but never disappears: offices, endpoints and the paper on desks stay in scope.
Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the Annex A series
The controls that decide your audit
Control numbers reference ISO/IEC 27001:2022 Annex A (ISO/IEC 27002:2022 numbering). The 2013→2022 transition ended 31 October 2025 — audits now run against this control set.
Where audits actually fail
A.7.4 is about monitoring as a process — retention period, who reviews, what triggers escalation — not camera count.
Uncontrolled physical keys to secure areas defeat every badge-system control upstream (A.7.2/7.3).
Clear desk/screen (A.7.7) is the finding auditors photograph. One sticky note in a sampled bay becomes a nonconformity.
A.7.14 needs per-asset evidence — certificates or logged internal wipes reconciled against the asset register.
Evidence an auditor accepts
- Physical access records and authorisation lists for secure areas
- Monitoring configuration: coverage, retention, review responsibility (A.7.4)
- Clear-desk/screen policy + internal walkthrough/audit records (A.7.7)
- Asset-movement authorisations for off-premises equipment (A.7.9)
- Media lifecycle records and disposal/wipe certificates (A.7.10/7.14)
Annex A.7 FAQ
We are fully cloud — does Annex A.7 still apply?
Yes, reduced: offices, endpoints, home working and paper remain physical scope, and your data centre controls are inherited via the cloud provider and verified through A.5.23/supplier evidence.
What changed in physical controls in the 2022 revision?
A.7.4 Physical security monitoring is the new control — continuous monitoring of premises with defined retention and review, formalising CCTV/intruder-detection expectations.
How is clear desk actually audited?
By walking the floor: sampled desks, meeting rooms, printers and screens. Policy plus periodic internal walkthrough records is the defensible combination (A.7.7).
Annex A.7 in your ISMS
We take organisations from gap assessment to certificate — and keep the ISMS audit-ready on SigmaTrust afterwards.
