ISO 27001A.7 — Protecting against physical and environmental threats
A.7.5
Protecting against physical and environmental threats
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Protect against physical and environmental threats such as fire, flood, earthquake, and civil unrest consistent with risk assessment.
Points of focus
- Identify facilities in scope
- Assess environmental threats
- Inherit CSP physical controls where applicable
- Document residual office/colo controls
Implementation notes
Scope which facilities store or process in-scope information. For cloud production, cite provider reports in the SoA. For offices, cover badge access, visitor logs, and basic environmental protections proportionate to risk.
Audit tip: Show SoA lines for physical threats and the CSP report extract or office controls you rely on. Be ready to explain exclusions.
Evidence auditors typically request:
- Facility risk assessment excerpt
- CSP SOC 2 / ISO physical control inheritance note
- Office emergency procedures
- Insurance or landlord attestation where used
Common gaps
- Assuming cloud means zero physical risk
- Ignoring backup tape or on-prem routers
- No office fire/egress plan
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.7.5 | This control |
| SOC 2 | CC6.4 | Related SOC 2 themes (CC6.4) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.7.5)
Frequently Asked Questions
Usually not for production if the CSP provides them; address office continuity separately.
Typically under remote working (A.6.7), not full facility threat modeling.
Redundancy is A.8.14; environmental threat analysis still informs site selection.
Even without owned data centers, protecting against physical and environmental threats still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with facility risk assessment excerpt, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.