We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

ISO/IEC 27001:2022 · Annex A theme 3 of 4 · 14 controls

Annex A.7: Physical Controls

Fourteen controls from perimeters to clear desks. The 2022 addition — physical security monitoring — formalised what assessors already expected: premises watched, not just locked. For cloud-first organisations this theme shrinks but never disappears: offices, endpoints and the paper on desks stay in scope.

Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the Annex A series

The controls that decide your audit

A.7.1–7.2
Perimeters and entry

Defined security perimeters protecting areas with information assets; entry controlled and monitored appropriately.

A.7.3
Securing offices, rooms and facilities

Physical security designed and applied for offices and server/network rooms.

A.7.4
Physical security monitoring (new 2022)

Premises continuously monitored for unauthorised access — CCTV, intruder detection, guard processes — with retention and review defined.

A.7.6
Working in secure areas

Rules for working inside secure areas: supervision, no unauthorised recording, vacant-area lockdown.

A.7.7
Clear desk and clear screen

The rule interviews and walkthroughs test — papers, removable media and unlocked screens in shared spaces.

A.7.9
Off-premises assets

Devices and media used outside the premises protected — travel rules, home-office expectations.

A.7.10
Storage media

Media managed through its lifecycle: acquisition, use, transport and secure disposal.

A.7.14
Secure disposal or re-use of equipment

Storage verified wiped or destroyed before disposal/reuse — with records that prove it.

Control numbers reference ISO/IEC 27001:2022 Annex A (ISO/IEC 27002:2022 numbering). The 2013→2022 transition ended 31 October 2025 — audits now run against this control set.

Where audits actually fail

CCTV exists; nobody can produce retention or review evidence

A.7.4 is about monitoring as a process — retention period, who reviews, what triggers escalation — not camera count.

Server room key on a hook

Uncontrolled physical keys to secure areas defeat every badge-system control upstream (A.7.2/7.3).

Walkthrough finds passwords on monitors

Clear desk/screen (A.7.7) is the finding auditors photograph. One sticky note in a sampled bay becomes a nonconformity.

Disposed laptops with no wipe certificates

A.7.14 needs per-asset evidence — certificates or logged internal wipes reconciled against the asset register.

Evidence an auditor accepts

  • Physical access records and authorisation lists for secure areas
  • Monitoring configuration: coverage, retention, review responsibility (A.7.4)
  • Clear-desk/screen policy + internal walkthrough/audit records (A.7.7)
  • Asset-movement authorisations for off-premises equipment (A.7.9)
  • Media lifecycle records and disposal/wipe certificates (A.7.10/7.14)

Annex A.7 FAQ

We are fully cloud — does Annex A.7 still apply?

Yes, reduced: offices, endpoints, home working and paper remain physical scope, and your data centre controls are inherited via the cloud provider and verified through A.5.23/supplier evidence.

What changed in physical controls in the 2022 revision?

A.7.4 Physical security monitoring is the new control — continuous monitoring of premises with defined retention and review, formalising CCTV/intruder-detection expectations.

How is clear desk actually audited?

By walking the floor: sampled desks, meeting rooms, printers and screens. Policy plus periodic internal walkthrough records is the defensible combination (A.7.7).

People (A.6)Technological (A.8)

Annex A.7 in your ISMS

We take organisations from gap assessment to certificate — and keep the ISMS audit-ready on SigmaTrust afterwards.