Physical security perimeters
Defined security perimeters around buildings and facilities
Walking the property boundary, testing fences, gates and planting for climbability, establishing which sides of the building remain visible from public ground
Clause 9.1 requires evidence that your controls work. For the fourteen controls in section A.7 we produce it on site, through non-destructive testing of locking hardware, entry routes and reporting paths, documented for every single control.
Annex A adds A.5.35 to that duty, the independent review of information security at planned intervals.
For the technological controls this evidence is routine: penetration tests, vulnerability scans and log analysis produce measurements you can rely on. The physical controls in section A.7 are mostly assessed against purchase records, installation reports and written procedures, in other words against documents that describe the intended state.
We close that gap through practical testing. Doors, gates and locking hardware are tested non-destructively for the resistance they actually offer. Planted test devices trigger the reporting paths. Entry procedures are tested during normal operations, including tailgating and visitor handling. Every observation is mapped to the control it affects and rated by its impact on your business.
For each control the requirement of the standard sits next to the method we use to establish its effectiveness. Which controls apply in your case is agreed up front in the scope.
Defined security perimeters around buildings and facilities
Walking the property boundary, testing fences, gates and planting for climbability, establishing which sides of the building remain visible from public ground
Controlled entry points and a managed visitor process
Non-destructive testing of doors and locking hardware, plus tailgating and a test of the visitor process during normal operations
Rooms secured in line with how sensitive they are
Establishing whether sensitive rooms are actually locked day to day, with particular attention to server and plant rooms
Monitoring to detect unauthorised physical access
Determining the real camera coverage from the recordings, plus an assessment of false positive rate, escalation path and response
Protection against environmental and deliberate physical threats
Visual inspection of the structural and organisational measures, plus an assessment of the attack surface reachable from outside
Governed activity inside secure areas
Observing everyday practice: escort rules, devices carried in, and how people respond to an unfamiliar face
Documents and screens secured while unattended
Recording documents left in the open, written-down credentials and workstations left unlocked
Equipment sited to minimise exposure and access
Testing siting for reachability and tampering, from the network socket to the control cabinet
Protection of assets away from the site
Testing vehicles, outdoor storage and equipment carried off site, as far as agreed in the scope
Media protected across their whole life cycle
Testing media, printouts and confidential waste containers for access and removability
Reliable power, cooling and communications
Testing how reachable service entry points, uninterruptible power supplies and plant rooms are
Data and power cabling protected from interception and damage
Testing patch areas, network sockets and cable routing for unsupervised access
Maintenance without disclosure of information
Testing maintenance access and the supervision of external service providers, as far as agreed in the scope
Secure disposal with no recoverable data
Following the disposal route for retired equipment and media through to handover to the waste contractor
Control titles follow the original English wording of ISO/IEC 27001:2022.
A report that works for two audiences. Your management finds a summary, the attack paths from the fence through to company data, and a checklist of measures sorted by the order they should be tackled in.
For your ISMS, every finding is mapped to the controls in Annex A and described with its impact, so you can carry it straight into your statement of applicability and risk treatment.
Once the measures are in place we test again on request, aimed at the documented attack paths, which gives you the effectiveness evidence for your next reporting cycle.
Certification itself is done by your certification body. We issue no statement of conformity and we do not assess how complete your documentation is, which is a job your internal audit does better.
What we contribute is the practical effectiveness evidence for the physical controls: an independent assessment under realistic conditions, with results you can put in front of your auditor.
Our physical security audit describes how an engagement runs from first contact to final report.
Tell us where you stand in the ISMS cycle and which sites fall inside your scope. We will propose an assessment scope and give you effort and timing.
Send enquiry