Skip to content
compliancebase
ISO 27001A.7 — Physical security perimeters

A.7.1

Physical security perimeters

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Define and use security perimeters to protect areas containing information and information processing facilities.

Points of focus

  • Identify every physical location where information processing facilities exist — offices, colo cages, remote workers' homes
  • Document what perimeter you control directly versus what's inherited from a landlord, co-working provider, or cloud vendor
  • Obtain and review the cloud/colo provider's relevant assurance report annually
  • Address residual perimeter risk for remote work — device custody, shared living spaces, unattended screens

Implementation notes

Start by inventorying every physical location in scope: any leased office, any co-working membership, any colo cage if you self-host anything, and the home offices of remote employees. For cloud infrastructure, physical perimeter control is inherited — pull the provider's current SOC 2 Type II or ISO 27001 certification annually, confirm your services are in scope, and document who owns that review. For a controlled office, define the perimeter explicitly: which doors, which floors, whether it's shared with other tenants. For a co-working space, be honest that the perimeter is largely managed by the landlord, and document what you rely on them for versus what you control (laptop locking, clean-desk practice, visitor escort within your suite). For remote-first teams, the meaningful residual risk isn't a building perimeter at all — it's device custody, screen privacy in shared living spaces, and physical loss or theft — so the remote work policy should cover locking screens, secure storage of company devices, and reporting lost or stolen equipment promptly.

Audit tip: State plainly which perimeters you control and which you inherit. "We have no data center; AWS's ISO 27001 certificate covers physical and environmental controls for our infrastructure, reviewed annually by [owner]" is a stronger answer than vague language implying controls you don't actually operate.

Evidence auditors typically request:

  • Facility inventory listing every office, colo, and remote-work population in scope
  • Cloud provider SOC 2 Type II or ISO 27001 certificate covering physical/environmental controls, reviewed annually
  • Office lease or co-working agreement showing which entity controls the perimeter
  • Remote work security policy addressing device custody and physical workspace expectations

Common gaps

  • The SoA claims physical perimeter controls but no one has actually pulled or reviewed the cloud provider's current assurance report
  • A co-working membership is treated as a controlled perimeter when the landlord — not the company — actually manages badge access and visitor policy
  • Remote work policy never addresses physical security at all, despite the workforce being fully distributed

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.7.1This control
SOC 2CC6.4CC6.4 addresses restricting physical access to facilities and protected information assets; for cloud-hosted SaaS, both frameworks converge on the same answer — review the hosting provider's assurance report rather than re-testing physical controls you don't operate.
HIPAA164.310(a)164.310(a)(1) — Facility Access Controls — applies if any ePHI touches a facility you control; cloud-only environments typically inherit this through the provider's BAA and assurance reporting, not through your own office lease.

Primary sources

Frequently Asked Questions

You still need to document the control, but for infrastructure it's satisfied by reviewing your cloud provider's assurance reporting rather than building your own data center perimeter. What remains in scope is any office space and remote work environments.

Only partially. The landlord typically controls building access and visitor policy; document what they manage and what, if anything, you control within your own suite or dedicated area.

There's no traditional perimeter, so the control shifts to device custody and workspace practices — locked screens, secure device storage, and a defined process for reporting a lost or stolen laptop.

Annually at minimum, and whenever you change providers or add a new region/service that might fall outside the certificate's stated scope.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above