blueredix logo

The physical controls of ISO 27001, tested for effectiveness in live operation

Clause 9.1 requires evidence that your controls work. For the fourteen controls in section A.7 we produce it on site, through non-destructive testing of locking hardware, entry routes and reporting paths, documented for every single control.

Perimeter A.7.1 Building envelope A.7.2 Room A.7.3 Equipment A.7.8 Attack path

What the standard requires

Annex A adds A.5.35 to that duty, the independent review of information security at planned intervals.

For the technological controls this evidence is routine: penetration tests, vulnerability scans and log analysis produce measurements you can rely on. The physical controls in section A.7 are mostly assessed against purchase records, installation reports and written procedures, in other words against documents that describe the intended state.

We close that gap through practical testing. Doors, gates and locking hardware are tested non-destructively for the resistance they actually offer. Planted test devices trigger the reporting paths. Entry procedures are tested during normal operations, including tailgating and visitor handling. Every observation is mapped to the control it affects and rated by its impact on your business.

The fourteen controls in detail

For each control the requirement of the standard sits next to the method we use to establish its effectiveness. Which controls apply in your case is agreed up front in the scope.

A.7.1

Physical security perimeters

Defined security perimeters around buildings and facilities

Walking the property boundary, testing fences, gates and planting for climbability, establishing which sides of the building remain visible from public ground

A.7.2

Physical entry

Controlled entry points and a managed visitor process

Non-destructive testing of doors and locking hardware, plus tailgating and a test of the visitor process during normal operations

A.7.3

Securing offices, rooms and facilities

Rooms secured in line with how sensitive they are

Establishing whether sensitive rooms are actually locked day to day, with particular attention to server and plant rooms

A.7.4

Physical security monitoring

Monitoring to detect unauthorised physical access

Determining the real camera coverage from the recordings, plus an assessment of false positive rate, escalation path and response

A.7.5

Protecting against physical and environmental threats

Protection against environmental and deliberate physical threats

Visual inspection of the structural and organisational measures, plus an assessment of the attack surface reachable from outside

A.7.6

Working in secure areas

Governed activity inside secure areas

Observing everyday practice: escort rules, devices carried in, and how people respond to an unfamiliar face

A.7.7

Clear desk and clear screen

Documents and screens secured while unattended

Recording documents left in the open, written-down credentials and workstations left unlocked

A.7.8

Equipment siting and protection

Equipment sited to minimise exposure and access

Testing siting for reachability and tampering, from the network socket to the control cabinet

A.7.9

Security of assets off-premises

Protection of assets away from the site

Testing vehicles, outdoor storage and equipment carried off site, as far as agreed in the scope

A.7.10

Storage media

Media protected across their whole life cycle

Testing media, printouts and confidential waste containers for access and removability

A.7.11

Supporting utilities

Reliable power, cooling and communications

Testing how reachable service entry points, uninterruptible power supplies and plant rooms are

A.7.12

Cabling security

Data and power cabling protected from interception and damage

Testing patch areas, network sockets and cable routing for unsupervised access

A.7.13

Equipment maintenance

Maintenance without disclosure of information

Testing maintenance access and the supervision of external service providers, as far as agreed in the scope

A.7.14

Secure disposal or re-use of equipment

Secure disposal with no recoverable data

Following the disposal route for retired equipment and media through to handover to the waste contractor

Control titles follow the original English wording of ISO/IEC 27001:2022.

What you receive

A report that works for two audiences. Your management finds a summary, the attack paths from the fence through to company data, and a checklist of measures sorted by the order they should be tackled in.

For your ISMS, every finding is mapped to the controls in Annex A and described with its impact, so you can carry it straight into your statement of applicability and risk treatment.

Once the measures are in place we test again on request, aimed at the documented attack paths, which gives you the effectiveness evidence for your next reporting cycle.

Audit report mapping each finding to the controls in Annex A of ISO 27001

Where we stop

Certification itself is done by your certification body. We issue no statement of conformity and we do not assess how complete your documentation is, which is a job your internal audit does better.

What we contribute is the practical effectiveness evidence for the physical controls: an independent assessment under realistic conditions, with results you can put in front of your auditor.

Our physical security audit describes how an engagement runs from first contact to final report.

Agree a scope

Tell us where you stand in the ISMS cycle and which sites fall inside your scope. We will propose an assessment scope and give you effort and timing.

Send enquiry