About this program
Annex A.7 has 14 physical security controls covering perimeters, entry, monitoring (NEW in 2022), equipment, off-premises assets, media handling and disposal. After each answer, expand the “Auditor’s view” for testing, evidence and the ideal response.
Controls (10)
-
A.7.1 — Are physical security perimeters defined and used to protect areas containing information and information processing facilities?
MediumThis control requires organizations to establish and maintain clearly defined physical security perimeters—such as walls, card-controlled entry gates, reception desks, and manned barriers—around areas where sensitive information and information processing facilities are located. These perimeters create defensive layers that prevent…
How to test + evidence
Risk: Multi-layer (reception → office → secure area) gives defence in depth. A single perimeter is one tail-gate away from the server room.
Testing procedure: Walk the perimeter. Identify reception, badge-controlled doors, secure-area boundaries (server room, data centre, finance), and any tail-gating risk. Compare against the documented site security plan.
Evidence to collect: Site security plan / floor plan with perimeters marked Photos / video walkthrough showing physical layers Access control system zone configuration
-
A.7.2 — Are entry controls (badges, escorts, visitor logs) in place for secure areas?
MediumThis control ensures that physical access to secure areas (server rooms, data centers, restricted offices) is managed through documented entry mechanisms including badge readers, biometric scanners, escort requirements for visitors, and maintained visitor logs. Organizations must define what constitutes a…
How to test + evidence
Risk: Defence in depth (multiple controls, all logged) makes social-engineering tail-gating harder and produces an evidence trail when something goes wrong.
Testing procedure: Test the visitor process: arrive unannounced. Inspect the visitor log for the audit period — sample 25 entries and verify each has signed in, was escorted, and signed out. Compare badge access logs to schedules.
Evidence to collect: Visitor log sample (25 entries) Badge access log for sensitive areas CCTV footage retention configuration Reception SOP document
-
A.7.3 — Are sensitive offices/rooms (server rooms, finance, HR) secured separately from general office space?
MediumThis control requires physical separation and independent access restrictions for areas containing sensitive information or critical systems—such as server rooms, data centers, HR offices, and finance departments—from general office areas accessible to all employees. Implementation typically involves dedicated locked doors…
How to test + evidence
Risk: Auditors specifically test that "everyone with a building badge can't walk into the server room" — co-located badge zones are a common finding.
Testing procedure: Walk the office and identify sensitive rooms. For each, verify a separate badge zone or key control with a documented holder list. Sample badge access logs to confirm only authorised people enter.
Evidence to collect: List of sensitive rooms + badge zones Authorised holder list per zone Sample of badge access logs Key register if physical keys are used
-
A.7.4 — Is physical security monitored continuously (cameras, intrusion detection, alarms)? (NEW in 2022)
MediumThis control requires organizations to implement continuous monitoring of physical security perimeters and sensitive areas using cameras, intrusion detection systems, motion sensors, and alarm systems. Monitoring systems must operate 24/7, generate alerts for security events, and maintain logs of access…
How to test + evidence
Risk: A.7.4 is new in 2022 — auditors specifically test that monitoring is active, not just installed. Cameras with no review are common findings.
Testing procedure: Inspect the camera system, intrusion detection, and any alarm response. Verify retention period for footage (typically 30+ days) and that alerts route to a monitored 24/7 location.
Evidence to collect: CCTV camera coverage map Footage retention policy + actual retention Intrusion detection alarm history Response SLA + tested response
-
A.7.5 / A.7.11 — Are environmental threats (fire, water, power loss) and supporting utilities protected?
MediumThis control addresses physical protection of information processing facilities and supporting infrastructure from environmental hazards including fire, flood, extreme weather, and utility failures. It requires organizations to implement detection and suppression systems (fire alarms, sprinklers), drainage and flood barriers, climate…
How to test + evidence
Risk: Environmental controls only matter if they're tested. UPS that has never been load-tested fails when the lights go out.
Testing procedure: Walk the server room / data centre. Inspect UPS test logs, fire suppression service records, water sensor placement, and dual power feeds where applicable.
Evidence to collect: UPS service + test reports Fire suppression certification (recent) Water leak sensor locations + alerts Power redundancy diagram
-
A.7.7 — Is a clear-desk and clear-screen policy in place and enforced?
MediumA clear-desk and clear-screen policy requires employees to secure physical and digital information when not in active use. Clear-desk mandates removal of sensitive documents from workspaces at end-of-day or when unattended; clear-screen requires locking computer sessions during absences. The policy…
How to test + evidence
Risk: Auto-lock alone is necessary but not sufficient — auditors look for active enforcement (walkthroughs, follow-ups) because most data leaks at the desk are paper-based.
Testing procedure: Inspect the clear-desk policy. Walk the office at lunch / end of day. Note unattended sensitive paper, unlocked screens, sticky notes with passwords. Compare against periodic walkthrough records.
Evidence to collect: Clear-desk + clear-screen policy MDM/GPO showing screen auto-lock at 5 minutes Walkthrough records / spot-check log Disciplinary record if violations found
-
A.7.8 / A.7.13 — Are equipment siting, protection and maintenance schedules documented and applied?
MediumThis control requires organizations to document and implement formal procedures for the physical placement, environmental protection, and preventive maintenance of information processing equipment. It addresses location risk assessments (distance from hazards, public access, environmental controls), physical protective measures (locked rooms,…
How to test + evidence
Risk: Equipment that fails because of skipped maintenance is a security event when it carries sensitive data. The register + schedule is the auditor's starting point.
Testing procedure: Inspect the equipment register. Sample 10 critical equipment items (servers, network kit, printers handling sensitive data) and verify siting is appropriate and maintenance is current.
Evidence to collect: Equipment register with location + owner Maintenance schedule + completed work orders Vendor maintenance contracts where applicable Photos showing protected siting (no public access, etc.)
-
A.7.9 — Are off-site assets (laptops, mobile devices) protected with documented controls?
MediumThis control requires organizations to maintain documented security measures for assets used outside the organization's physical premises, including laptops, tablets, mobile phones, and removable media. Controls typically include encryption requirements, remote wipe capabilities, VPN usage mandates, physical security guidelines, acceptable…
How to test + evidence
Risk: Stolen laptops are the most common physical security incident. MDM + encryption + wipe is the standard expectation; any gap is a finding.
Testing procedure: Sample 10 employee laptops. Verify each is enrolled in MDM, has full-disk encryption enabled, and has remote-wipe capability. Inspect lost/stolen device records for the period and confirm wipe occurred.
Evidence to collect: MDM enrolment report Encryption coverage report (BitLocker / FileVault) Lost device register + remote-wipe logs Off-site asset issue procedure
-
A.7.10 — Is removable media (USB, portable drives) controlled, encrypted and tracked?
MediumThis control ensures that removable media devices such as USB flash drives, external hard drives, and portable storage are inventoried, authorized before use, encrypted to protect data at rest, and tracked throughout their lifecycle. Organizations implement technical controls (device control…
How to test + evidence
Risk: Block by default + exception list is the only practical control. "Don't copy data to USBs" as a policy with no enforcement is consistently violated.
Testing procedure: Inspect endpoint policy. Test by inserting an unapproved USB on a sample device — confirm it is blocked. For approved devices, verify encryption is enforced.
Evidence to collect: Endpoint policy showing USB block by default Approved encrypted device list + register Test result showing unapproved USB blocked DLP rules covering removable media
-
A.7.14 — Is equipment securely disposed of or re-used (data wiped, certificates of destruction)?
MediumThis control ensures that storage media and equipment containing sensitive or organizational data are sanitized, destroyed, or securely wiped before disposal, transfer, or reuse to prevent unauthorized data recovery. It includes physical destruction of media, cryptographic erasure, overwriting using approved…
How to test + evidence
Risk: Disposal is a recurring audit finding: equipment leaves the building with data still on it. Certified destruction with serial-matching is the only defensible position.
Testing procedure: Sample 10 disposed devices from the asset register. For each, request the certificate of destruction or wipe log + serial number match. Auditors specifically look for unmatched serial numbers.
Evidence to collect: Disposal procedure + standard (NIST SP 800-88 r1 or equivalent) Certificates of destruction with serial numbers Asset register marking disposed items + date Vendor contract for certified destruction