ISO 27001A.7 — Physical security perimeters
A.7.1
Physical security perimeters
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Define and use security perimeters to protect areas containing information and information processing facilities.
Points of focus
- Define scope and requirements for physical security perimeters
- Assign ownership and operating cadence
- Integrate with risk treatment and SoA status
- Retain dated records proving operation
Implementation notes
For offices, define perimeter and badge zones. For pure remote/cloud, document residual facilities and provider inheritance in the SoA. Tie the SoA implementation summary to the systems of record engineers already use, and keep dated samples ready for Stage 2 sampling.
Audit tip: Present the SoA line for A.7.1, the current procedure, and one recent dated operating sample with a named owner.
Evidence auditors typically request:
- Facility / office physical security procedure
- Access badge logs or visitor register samples
- Photos or diagrams of perimeter / entry controls (as appropriate)
- Vendor/cloud shared-responsibility note if facilities are outsourced
Common gaps
- SoA marks physical security perimeters applicable without dated operating samples
- Procedure exists but interviews describe a different tribal process
- Owner unclear or last review older than the stated cadence
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.7.1 | This control |
| SOC 2 | CC6.4 | Related Trust Services Criteria themes — map in your crosswalk; not identical requirements. |
| HIPAA | 164.310(a) | Related HIPAA Security Rule citations when PHI is in scope — SoA does not replace BAAs. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.7.1)
Frequently Asked Questions
Applicability depends on risk and scope. Many cloud-native SoAs still include organizational and technological controls; physical themes may be partially inherited from providers with documented shared responsibility.
Applicability decision, brief implementation summary, and justification if excluded. Vague 'N/A — cloud' without rationale is a common Stage 1 finding.
Name the owner, the system of record, and the cadence. Auditors sample reality — tickets, configs, and interviews — not synonym-rewritten ISO text.