iso-27001-physical-security

By July 25th, 2026ISO Audit And Certificate9 min read

ISO 27001 Physical Security: Protecting Facilities and Equipment

ISO 27001 physical security controls are a cornerstone of any effective Information Security Management System (ISMS). Without robust physical protections, even the most sophisticated cybersecurity measures can be undermined by someone simply walking into a server room or walking out with a laptop. This article explains what your organisation needs to know about Annex A.11 – Physical and Environmental Security – and how to implement each control properly.

What Does Annex A.11 Cover?

Annex A.11 of ISO 27001:2022 is divided into two main sections: Secure Areas (A.11.1) and Equipment Security (A.11.2). Together they cover every physical aspect of your ISMS, from the fence around your building to the disposal of an old hard drive.

Annex A.11 ControlObjectiveKey Requirement
A.11.1.1 Physical security perimeterPrevent unauthorised physical accessDefine and maintain a security perimeter using walls, locked doors, or other barriers
A.11.1.2 Physical entry controlsControl access to secure areasSecure areas must be protected by appropriate entry controls (badges, biometrics, guards)
A.11.1.3 Securing offices, rooms and facilitiesProtect information in officesLock doors and windows, secure cabinets, and control visitor access
A.11.1.4 Protecting against external and environmental threatsSafeguard against fire, flood, and vandalismInstall fire suppression, UPS, and environmental monitoring
A.11.1.5 Working in secure areasRestrict activities in secure zonesDefine authorised personnel and monitor activities
A.11.1.6 Delivery and loading areasSecure points of entry for goodsIsolate delivery zones from information-processing facilities
A.11.2.1 Equipment siting and protectionPrevent damage to equipmentLocate equipment to minimise environmental risks and unauthorised access
A.11.2.2 Supporting utilitiesEnsure backup power and coolingProvide redundant power, HVAC, and telecoms connections
A.11.2.3 Cabling securityProtect network and power cablingRoute cables through protected conduits and label clearly
A.11.2.4 Equipment maintenanceMaintain availability and integritySchedule maintenance and keep records
A.11.2.5 Removal of assetsPrevent unauthorised removalLog and authorise any equipment leaving the premises
A.11.2.6 Security of equipment and assets off-premisesProtect mobile and home-working devicesApply encryption, VPNs, and physical locks
A.11.2.7 Secure disposal or reuse of equipmentEliminate residual dataSanitise or destroy storage media before disposal
A.11.2.8 Unattended user equipmentPrevent unauthorised accessEnforce session locks and clear desk/clear screen policies
A.11.2.9 Clear desk and clear screen policyReduce risk of information exposureLock away papers, wipe whiteboards, and lock screens when away

Establishing a Physical Security Perimeter

A physical security perimeter is the first line of defence (A.11.1.1). It does not have to be a fortress; it must be appropriate to the risk. For most organisations this means:

  • Perimeter walls or fencing strong enough to deter casual intrusion.
  • Locked external doors with access control (key cards, PIN pads, or biometrics).
  • Reception or security desk to challenge unidentified visitors.
  • CCTV coverage at entry points and critical corridors.
  • Intrusion alarms monitored by a security team or third-party service.

The standard requires that the perimeter be tested regularly. For example, you should conduct quarterly walk-throughs to check that doors close properly, alarms function, and CCTV footage is retained for the required period (typically 30–90 days).

Physical Entry Controls

Control A.11.1.2 requires that access to secure areas is restricted to authorised personnel only. The most common implementation is a multi-zone access control system:

ZoneExamplesTypical Entry ControlAccess Granted To
Public zoneReception, meeting roomsVisitor sign-in, escort policyEveryone (with approval)
Office zoneOpen-plan work areasKey card or mobile badgeAll employees
Restricted zoneServer rooms, comms roomsBiometric + PIN + audit logNamed IT/security staff only
High-security zoneData centres, vaultsMulti-factor + mantrap + 24/7 monitoringApproved individuals with specific business need

Visitor management is a critical part of entry controls. Every visitor should sign a non-disclosure agreement, wear a visible badge, and be escorted at all times. Maintain a visitor log that includes name, company, purpose, time in, time out, and the name of the responsible host.

Secure Areas: Design and Operation

Secure areas (A.11.1.3–A.11.1.6) are the inner zones where information-processing activities take place. These areas demand additional controls.

Office and Room Security

All offices should have locking doors and windows. Server rooms and communications cabinets must be:

  • Locked at all times with electronic access logging.
  • Fitted with environmental monitoring (temperature, humidity, water detection).
  • Protected by fire suppression (gas-based suppression is preferred over water sprinklers for server rooms).
  • Equipped with uninterruptible power supplies (UPS) and backup generators.

Delivery and Loading Areas

Control A.11.1.6 specifically mentions delivery and loading areas because they are a common weak point. These areas must be physically separated from information-processing facilities. Deliveries should be inspected, logged, and held in a secure holding area before being moved into the main facility.

Equipment Security

Section A.11.2 covers the security of equipment both on and off the premises. The guiding principle is that equipment should be protected from theft, damage, and environmental hazards at all times.

Equipment Siting and Supporting Utilities

Equipment should be sited to minimise unnecessary access. For example:

  • Servers must be in locked racks inside locked rooms.
  • Network switches should be in locked cabinets.
  • Printers (which often store document images) should be in controlled areas away from public lobbies.

Supporting utilities (A.11.2.2) must be redundant where the business impact of downtime is high. This means dual power feeds, automatic transfer switches, and contracted maintenance for generators and HVAC systems.

Cabling Security

Control A.11.2.3 requires that power and data cabling be protected from interception and damage. Best practices include:

  • Running cables in closed conduit or trunking.
  • Separating power cables from data cables to reduce electromagnetic interference.
  • Labeling both ends of every cable and maintaining a patch-panel schedule.
  • Using fibre-optic cabling in high-security zones (fibre is far harder to tap than copper).

Clear Desk and Clear Screen Policy

Control A.11.2.9 mandates a clear desk and clear screen policy. This is one of the simplest yet most effective ISO 27001 physical security controls and it applies to every employee. A good policy includes:

RequirementWhat It Means in Practice
Clear desk at end of dayAll papers locked in cabinets; no sticky notes with passwords; whiteboards erased
Clear screen when awayWorkstations lock automatically after 5–10 minutes of inactivity
No unattended confidential documentsPrinted documents collected immediately; shred bins used for disposal
Mobile device securityLaptops and phones locked away or secured with cable locks
Visitor visibilityNo screens visible to visitors that display customer data or internal systems

You can test compliance through spot checks and include clear-desk adherence as a metric in your internal audit programme.

Off-Site Equipment and Remote Working

Control A.11.2.6 addresses equipment and assets off-premises. With hybrid working now the norm, this control is more important than ever. Required measures include:

  • Full-disk encryption on all laptops and mobile devices.
  • VPN requirement for accessing corporate resources.
  • Remote wipe capability in case of loss or theft.
  • Physical locks for equipment left in hotel rooms or co-working spaces.
  • Home-working assessments to ensure employees have a lockable room and secure Wi-Fi.

Secure Disposal and Reuse of Equipment

Control A.11.2.7 is where physical security meets data protection. When equipment reaches end of life, you must ensure that no residual data can be recovered. The appropriate method depends on the storage medium:

  • Degaussing for magnetic media (HDDs, tapes).
  • Cryptographic wipe for self-encrypting drives.
  • Physical destruction (shredding, crushing) for SSDs, phones, and damaged drives.
  • Certified vendor for large-scale disposal with a chain-of-custody certificate.

Always maintain a disposal log that records the asset tag, serial number, date, method of destruction, and the name of the person who authorised and performed the disposal.

Frequently Asked Questions

Is ISO 27001 physical security mandatory?

Yes, if you claim conformity to ISO 27001. All controls in Annex A.11 must be addressed in your Statement of Applicability. You can justify an exclusion if the control is not relevant, but for most organisations physical security controls are applicable.

Do small businesses need a physical security perimeter?

Yes, but it must be proportionate. For a small office this might mean a locked front door with a keypad, a visitor sign-in book, and a lockable cabinet for documents and servers. The standard requires a perimeter, not a fortress.

How often should we review our physical security controls?

At least annually as part of your internal audit programme. Quarterly walk-throughs for perimeter and entry controls are a good practice. Access logs should be reviewed monthly as a detective control.

What is the difference between A.11.1.1 and A.11.1.2?

A.11.1.1 (Physical security perimeter) is about the outer boundary of your facility. A.11.1.2 (Physical entry controls) is about who gets through that boundary and how. You need both: a perimeter keeps people out; entry controls manage the people you let in.

Can we use cloud services to avoid physical security responsibilities?

Not entirely. If you use an Infrastructure-as-a-Service provider such as AWS or Azure, they are responsible for the physical security of their data centres. However, you are still responsible for endpoint security at your own premises and for the devices your staff use to access the cloud.

What records do we need for an ISO 27001 audit on physical security?

Your auditor will expect to see: the physical security perimeter definition; access control lists and review records; visitor logs; the clear desk policy; equipment disposal logs; maintenance records; and evidence of regular testing (alarm tests, fire drills, CCTV reviews).

Get Expert Help with ISO 27001

Implementing ISO 27001 physical security controls correctly takes planning and expertise. Whether you are starting from scratch or closing gaps in your existing ISMS, our consultants can help you design, document, and implement controls that meet the standard and protect your business.

Prefer instant support? Chat with us on WhatsApp.