Skip to content
compliancebase
ISO 27001A.7 — Protecting against physical and environmental threats

A.7.5

Protecting against physical and environmental threats

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Protect against physical and environmental threats such as fire, flood, earthquake, and civil unrest consistent with risk assessment.

Points of focus

  • Identify facilities in scope
  • Assess environmental threats
  • Inherit CSP physical controls where applicable
  • Document residual office/colo controls

Implementation notes

Scope which facilities store or process in-scope information. For cloud production, cite provider reports in the SoA. For offices, cover badge access, visitor logs, and basic environmental protections proportionate to risk.

Audit tip: Show SoA lines for physical threats and the CSP report extract or office controls you rely on. Be ready to explain exclusions.

Evidence auditors typically request:

  • Facility risk assessment excerpt
  • CSP SOC 2 / ISO physical control inheritance note
  • Office emergency procedures
  • Insurance or landlord attestation where used

Common gaps

  • Assuming cloud means zero physical risk
  • Ignoring backup tape or on-prem routers
  • No office fire/egress plan

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.7.5This control
SOC 2CC6.4Related SOC 2 themes (CC6.4) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Usually not for production if the CSP provides them; address office continuity separately.

Typically under remote working (A.6.7), not full facility threat modeling.

Redundancy is A.8.14; environmental threat analysis still informs site selection.

Even without owned data centers, protecting against physical and environmental threats still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with facility risk assessment excerpt, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above