ISO 27001 Physical Security: Protecting Facilities and Equipment
ISO 27001 physical security controls are a cornerstone of any effective Information Security Management System (ISMS). Without robust physical protections, even the most sophisticated cybersecurity measures can be undermined by someone simply walking into a server room or walking out with a laptop. This article explains what your organisation needs to know about Annex A.11 – Physical and Environmental Security – and how to implement each control properly.
What Does Annex A.11 Cover?
Annex A.11 of ISO 27001:2022 is divided into two main sections: Secure Areas (A.11.1) and Equipment Security (A.11.2). Together they cover every physical aspect of your ISMS, from the fence around your building to the disposal of an old hard drive.
| Annex A.11 Control | Objective | Key Requirement |
|---|---|---|
| A.11.1.1 Physical security perimeter | Prevent unauthorised physical access | Define and maintain a security perimeter using walls, locked doors, or other barriers |
| A.11.1.2 Physical entry controls | Control access to secure areas | Secure areas must be protected by appropriate entry controls (badges, biometrics, guards) |
| A.11.1.3 Securing offices, rooms and facilities | Protect information in offices | Lock doors and windows, secure cabinets, and control visitor access |
| A.11.1.4 Protecting against external and environmental threats | Safeguard against fire, flood, and vandalism | Install fire suppression, UPS, and environmental monitoring |
| A.11.1.5 Working in secure areas | Restrict activities in secure zones | Define authorised personnel and monitor activities |
| A.11.1.6 Delivery and loading areas | Secure points of entry for goods | Isolate delivery zones from information-processing facilities |
| A.11.2.1 Equipment siting and protection | Prevent damage to equipment | Locate equipment to minimise environmental risks and unauthorised access |
| A.11.2.2 Supporting utilities | Ensure backup power and cooling | Provide redundant power, HVAC, and telecoms connections |
| A.11.2.3 Cabling security | Protect network and power cabling | Route cables through protected conduits and label clearly |
| A.11.2.4 Equipment maintenance | Maintain availability and integrity | Schedule maintenance and keep records |
| A.11.2.5 Removal of assets | Prevent unauthorised removal | Log and authorise any equipment leaving the premises |
| A.11.2.6 Security of equipment and assets off-premises | Protect mobile and home-working devices | Apply encryption, VPNs, and physical locks |
| A.11.2.7 Secure disposal or reuse of equipment | Eliminate residual data | Sanitise or destroy storage media before disposal |
| A.11.2.8 Unattended user equipment | Prevent unauthorised access | Enforce session locks and clear desk/clear screen policies |
| A.11.2.9 Clear desk and clear screen policy | Reduce risk of information exposure | Lock away papers, wipe whiteboards, and lock screens when away |
Establishing a Physical Security Perimeter
A physical security perimeter is the first line of defence (A.11.1.1). It does not have to be a fortress; it must be appropriate to the risk. For most organisations this means:
- Perimeter walls or fencing strong enough to deter casual intrusion.
- Locked external doors with access control (key cards, PIN pads, or biometrics).
- Reception or security desk to challenge unidentified visitors.
- CCTV coverage at entry points and critical corridors.
- Intrusion alarms monitored by a security team or third-party service.
The standard requires that the perimeter be tested regularly. For example, you should conduct quarterly walk-throughs to check that doors close properly, alarms function, and CCTV footage is retained for the required period (typically 30–90 days).
Physical Entry Controls
Control A.11.1.2 requires that access to secure areas is restricted to authorised personnel only. The most common implementation is a multi-zone access control system:
| Zone | Examples | Typical Entry Control | Access Granted To |
|---|---|---|---|
| Public zone | Reception, meeting rooms | Visitor sign-in, escort policy | Everyone (with approval) |
| Office zone | Open-plan work areas | Key card or mobile badge | All employees |
| Restricted zone | Server rooms, comms rooms | Biometric + PIN + audit log | Named IT/security staff only |
| High-security zone | Data centres, vaults | Multi-factor + mantrap + 24/7 monitoring | Approved individuals with specific business need |
Visitor management is a critical part of entry controls. Every visitor should sign a non-disclosure agreement, wear a visible badge, and be escorted at all times. Maintain a visitor log that includes name, company, purpose, time in, time out, and the name of the responsible host.
Secure Areas: Design and Operation
Secure areas (A.11.1.3–A.11.1.6) are the inner zones where information-processing activities take place. These areas demand additional controls.
Office and Room Security
All offices should have locking doors and windows. Server rooms and communications cabinets must be:
- Locked at all times with electronic access logging.
- Fitted with environmental monitoring (temperature, humidity, water detection).
- Protected by fire suppression (gas-based suppression is preferred over water sprinklers for server rooms).
- Equipped with uninterruptible power supplies (UPS) and backup generators.
Delivery and Loading Areas
Control A.11.1.6 specifically mentions delivery and loading areas because they are a common weak point. These areas must be physically separated from information-processing facilities. Deliveries should be inspected, logged, and held in a secure holding area before being moved into the main facility.
Equipment Security
Section A.11.2 covers the security of equipment both on and off the premises. The guiding principle is that equipment should be protected from theft, damage, and environmental hazards at all times.
Equipment Siting and Supporting Utilities
Equipment should be sited to minimise unnecessary access. For example:
- Servers must be in locked racks inside locked rooms.
- Network switches should be in locked cabinets.
- Printers (which often store document images) should be in controlled areas away from public lobbies.
Supporting utilities (A.11.2.2) must be redundant where the business impact of downtime is high. This means dual power feeds, automatic transfer switches, and contracted maintenance for generators and HVAC systems.
Cabling Security
Control A.11.2.3 requires that power and data cabling be protected from interception and damage. Best practices include:
- Running cables in closed conduit or trunking.
- Separating power cables from data cables to reduce electromagnetic interference.
- Labeling both ends of every cable and maintaining a patch-panel schedule.
- Using fibre-optic cabling in high-security zones (fibre is far harder to tap than copper).
Clear Desk and Clear Screen Policy
Control A.11.2.9 mandates a clear desk and clear screen policy. This is one of the simplest yet most effective ISO 27001 physical security controls and it applies to every employee. A good policy includes:
| Requirement | What It Means in Practice |
|---|---|
| Clear desk at end of day | All papers locked in cabinets; no sticky notes with passwords; whiteboards erased |
| Clear screen when away | Workstations lock automatically after 5–10 minutes of inactivity |
| No unattended confidential documents | Printed documents collected immediately; shred bins used for disposal |
| Mobile device security | Laptops and phones locked away or secured with cable locks |
| Visitor visibility | No screens visible to visitors that display customer data or internal systems |
You can test compliance through spot checks and include clear-desk adherence as a metric in your internal audit programme.
Off-Site Equipment and Remote Working
Control A.11.2.6 addresses equipment and assets off-premises. With hybrid working now the norm, this control is more important than ever. Required measures include:
- Full-disk encryption on all laptops and mobile devices.
- VPN requirement for accessing corporate resources.
- Remote wipe capability in case of loss or theft.
- Physical locks for equipment left in hotel rooms or co-working spaces.
- Home-working assessments to ensure employees have a lockable room and secure Wi-Fi.
Secure Disposal and Reuse of Equipment
Control A.11.2.7 is where physical security meets data protection. When equipment reaches end of life, you must ensure that no residual data can be recovered. The appropriate method depends on the storage medium:
- Degaussing for magnetic media (HDDs, tapes).
- Cryptographic wipe for self-encrypting drives.
- Physical destruction (shredding, crushing) for SSDs, phones, and damaged drives.
- Certified vendor for large-scale disposal with a chain-of-custody certificate.
Always maintain a disposal log that records the asset tag, serial number, date, method of destruction, and the name of the person who authorised and performed the disposal.
Frequently Asked Questions
Is ISO 27001 physical security mandatory?
Yes, if you claim conformity to ISO 27001. All controls in Annex A.11 must be addressed in your Statement of Applicability. You can justify an exclusion if the control is not relevant, but for most organisations physical security controls are applicable.
Do small businesses need a physical security perimeter?
Yes, but it must be proportionate. For a small office this might mean a locked front door with a keypad, a visitor sign-in book, and a lockable cabinet for documents and servers. The standard requires a perimeter, not a fortress.
How often should we review our physical security controls?
At least annually as part of your internal audit programme. Quarterly walk-throughs for perimeter and entry controls are a good practice. Access logs should be reviewed monthly as a detective control.
What is the difference between A.11.1.1 and A.11.1.2?
A.11.1.1 (Physical security perimeter) is about the outer boundary of your facility. A.11.1.2 (Physical entry controls) is about who gets through that boundary and how. You need both: a perimeter keeps people out; entry controls manage the people you let in.
Can we use cloud services to avoid physical security responsibilities?
Not entirely. If you use an Infrastructure-as-a-Service provider such as AWS or Azure, they are responsible for the physical security of their data centres. However, you are still responsible for endpoint security at your own premises and for the devices your staff use to access the cloud.
What records do we need for an ISO 27001 audit on physical security?
Your auditor will expect to see: the physical security perimeter definition; access control lists and review records; visitor logs; the clear desk policy; equipment disposal logs; maintenance records; and evidence of regular testing (alarm tests, fire drills, CCTV reviews).
Get Expert Help with ISO 27001
Implementing ISO 27001 physical security controls correctly takes planning and expertise. Whether you are starting from scratch or closing gaps in your existing ISMS, our consultants can help you design, document, and implement controls that meet the standard and protect your business.
Prefer instant support? Chat with us on WhatsApp.