Annex A category 7

ISO 27001 Physical controls

Protection of locations, equipment, media and physical working environments. Use this category page to understand the control family and move into detailed implementation guides.

How this category supports the ISMS

Physical controls provide a structured reference for risk treatment. Applicability follows the organization’s risks, obligations, scope and chosen treatment. Record decisions in the Statement of Applicability and test selected controls in operation.

Use these guides to move from category-level planning into control-specific implementation, evidence and audit testing. The interactive lookup remains available for quick cross-control reference.

Published physical control guides

Control 7.1

Physical security perimeters

Define and protect physical boundaries around information, people and supporting assets according to risk.

Read the full guide →

Control 7.2

Physical entry

Authorize, record and review entry to controlled areas while managing visitors and access credentials.

Read the full guide →

Control 7.3

Securing offices, rooms and facilities

Apply proportionate protection to workplaces and facilities, including shared and outsourced locations.

Read the full guide →

Control 7.4

Physical security monitoring

Detect and review unauthorized or suspicious physical activity using proportionate monitoring and response.

Read the full guide →

Control 7.5

Protecting against physical and environmental threats

Reduce harm from fire, water, temperature, power, civil disruption and other relevant environmental hazards.

Read the full guide →

Control 7.6

Working in secure areas

Set behaviour and supervision expectations for people working within sensitive physical areas.

Read the full guide →

Control 7.7

Clear desk and clear screen

Reduce accidental exposure of sensitive information in offices, shared spaces and remote-work environments.

Read the full guide →

Control 7.8

Equipment siting and protection

Position and protect equipment against unauthorized access, observation, damage and environmental exposure.

Read the full guide →

Control 7.9

Security of assets off-premises

Protect devices, media and information when used, transported or stored outside organizational premises.

Read the full guide →

Control 7.10

Storage media

Control removable and other storage media through authorization, handling, transport, reuse and disposal.

Read the full guide →

Control 7.11

Supporting utilities

Protect information-processing facilities from loss or instability of power, cooling, communications and other utilities.

Read the full guide →

Control 7.12

Cabling security

Protect power and communications cabling from interception, interference and damage.

Read the full guide →

Control 7.13

Equipment maintenance

Maintain equipment safely and reliably while controlling access, information exposure and service records.

Read the full guide →

Control 7.14

Secure disposal or re-use of equipment

Remove or protect information before equipment is disposed of, returned, reassigned or reused.

Read the full guide →

All physical controls

Browse the complete category. Each control opens a dedicated implementation guide and remains available in the free interactive lookup.