ISO 27001 Physical controls
The 14 physical controls protect facilities, equipment, and media. They apply even to cloud-first companies (offices, laptops, disposal).
Physical security perimeters
Stop unauthorised people from physically reaching, damaging or interfering with the organisation's information and supporting assets.
Guidance and how to meet it →Physical entry
Make sure only authorised people can physically enter areas holding the organisation information and assets.
Guidance and how to meet it →Securing offices, rooms and facilities
Design and apply physical security for offices, rooms and facilities to prevent unauthorised access, damage or interference.
Guidance and how to meet it →Physical security monitoring
Continuously watch premises to detect and deter unauthorised physical access.
Guidance and how to meet it →Protecting against physical and environmental threats
Prevent or lessen harm from physical and environmental threats such as natural disasters and physical attacks.
Guidance and how to meet it →Working in secure areas
Protect information and assets in secure areas from damage and interference by the people working in them.
Guidance and how to meet it →Clear desk and clear screen
Cut the risk of unauthorised access to, or loss or damage of, information left visible on desks and screens.
Guidance and how to meet it →Equipment siting and protection
Site and protect equipment to reduce risks from physical and environmental threats and unauthorised access.
Guidance and how to meet it →Security of assets off-premises
Protect assets used away from the premises to prevent loss, damage, theft, compromise or disruption.
Guidance and how to meet it →Storage media
Manage storage media across its life cycle so information is only disclosed, changed, removed or destroyed by authorised parties.
Guidance and how to meet it →Supporting utilities
Protect information processing facilities from power failures and other disruptions in supporting utilities.
Guidance and how to meet it →Cabling security
Protect power, data and supporting service cabling from interception, interference or damage.
Guidance and how to meet it →Equipment maintenance
Maintain equipment correctly to keep information available, accurate and confidential and avoid disruption from breakdowns.
Guidance and how to meet it →Secure disposal or re-use of equipment
Verify equipment has had sensitive data and licensed software removed or securely overwritten before disposal or reuse.
Guidance and how to meet it →