A.7 · 14 controls

ISO 27001 Physical controls

The 14 physical controls protect facilities, equipment, and media. They apply even to cloud-first companies (offices, laptops, disposal).

A.7.1

Physical security perimeters

Stop unauthorised people from physically reaching, damaging or interfering with the organisation's information and supporting assets.

Guidance and how to meet it →
A.7.2

Physical entry

Make sure only authorised people can physically enter areas holding the organisation information and assets.

Guidance and how to meet it →
A.7.3

Securing offices, rooms and facilities

Design and apply physical security for offices, rooms and facilities to prevent unauthorised access, damage or interference.

Guidance and how to meet it →
A.7.4New

Physical security monitoring

Continuously watch premises to detect and deter unauthorised physical access.

Guidance and how to meet it →
A.7.5

Protecting against physical and environmental threats

Prevent or lessen harm from physical and environmental threats such as natural disasters and physical attacks.

Guidance and how to meet it →
A.7.6

Working in secure areas

Protect information and assets in secure areas from damage and interference by the people working in them.

Guidance and how to meet it →
A.7.7

Clear desk and clear screen

Cut the risk of unauthorised access to, or loss or damage of, information left visible on desks and screens.

Guidance and how to meet it →
A.7.8

Equipment siting and protection

Site and protect equipment to reduce risks from physical and environmental threats and unauthorised access.

Guidance and how to meet it →
A.7.9

Security of assets off-premises

Protect assets used away from the premises to prevent loss, damage, theft, compromise or disruption.

Guidance and how to meet it →
A.7.10

Storage media

Manage storage media across its life cycle so information is only disclosed, changed, removed or destroyed by authorised parties.

Guidance and how to meet it →
A.7.11

Supporting utilities

Protect information processing facilities from power failures and other disruptions in supporting utilities.

Guidance and how to meet it →
A.7.12

Cabling security

Protect power, data and supporting service cabling from interception, interference or damage.

Guidance and how to meet it →
A.7.13

Equipment maintenance

Maintain equipment correctly to keep information available, accurate and confidential and avoid disruption from breakdowns.

Guidance and how to meet it →
A.7.14

Secure disposal or re-use of equipment

Verify equipment has had sensitive data and licensed software removed or securely overwritten before disposal or reuse.

Guidance and how to meet it →