A.7.1
Physical security perimeters
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Define and use security perimeters to protect areas containing information and information processing facilities.
Points of focus
- Identify every physical location where information processing facilities exist — offices, colo cages, remote workers' homes
- Document what perimeter you control directly versus what's inherited from a landlord, co-working provider, or cloud vendor
- Obtain and review the cloud/colo provider's relevant assurance report annually
- Address residual perimeter risk for remote work — device custody, shared living spaces, unattended screens
Implementation notes
Start by inventorying every physical location in scope: any leased office, any co-working membership, any colo cage if you self-host anything, and the home offices of remote employees. For cloud infrastructure, physical perimeter control is inherited — pull the provider's current SOC 2 Type II or ISO 27001 certification annually, confirm your services are in scope, and document who owns that review. For a controlled office, define the perimeter explicitly: which doors, which floors, whether it's shared with other tenants. For a co-working space, be honest that the perimeter is largely managed by the landlord, and document what you rely on them for versus what you control (laptop locking, clean-desk practice, visitor escort within your suite). For remote-first teams, the meaningful residual risk isn't a building perimeter at all — it's device custody, screen privacy in shared living spaces, and physical loss or theft — so the remote work policy should cover locking screens, secure storage of company devices, and reporting lost or stolen equipment promptly.
Audit tip: State plainly which perimeters you control and which you inherit. "We have no data center; AWS's ISO 27001 certificate covers physical and environmental controls for our infrastructure, reviewed annually by [owner]" is a stronger answer than vague language implying controls you don't actually operate.
Evidence auditors typically request:
- Facility inventory listing every office, colo, and remote-work population in scope
- Cloud provider SOC 2 Type II or ISO 27001 certificate covering physical/environmental controls, reviewed annually
- Office lease or co-working agreement showing which entity controls the perimeter
- Remote work security policy addressing device custody and physical workspace expectations
Common gaps
- The SoA claims physical perimeter controls but no one has actually pulled or reviewed the cloud provider's current assurance report
- A co-working membership is treated as a controlled perimeter when the landlord — not the company — actually manages badge access and visitor policy
- Remote work policy never addresses physical security at all, despite the workforce being fully distributed
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.7.1 | This control |
| SOC 2 | CC6.4 | CC6.4 addresses restricting physical access to facilities and protected information assets; for cloud-hosted SaaS, both frameworks converge on the same answer — review the hosting provider's assurance report rather than re-testing physical controls you don't operate. |
| HIPAA | 164.310(a) | 164.310(a)(1) — Facility Access Controls — applies if any ePHI touches a facility you control; cloud-only environments typically inherit this through the provider's BAA and assurance reporting, not through your own office lease. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.7.1)