ISO/IEC 27001:2022 Annex A · 14 controls
Physical controls
The controls about places and things: who can get into the building, where equipment sits, what happens to a laptop when it is retired, and what is left on a desk overnight. Small companies often assume these do not apply to them, and the ones that are genuinely out of scope have to be argued rather than skipped.
- A.7.1Defining the physical boundary you protect
- A.7.2Controlling who gets through the door
- A.7.3Securing the rooms themselves
- A.7.4Watching the premises for intruders
- A.7.5Guarding against fire, flood and the like
- A.7.6Rules for working inside restricted areas
- A.7.7Leaving nothing sensitive on desks or screens
- A.7.8Placing equipment where it is safe
- A.7.9Protecting equipment taken off site
- A.7.10Handling disks, drives and removable media
- A.7.11Depending safely on power, cooling and water
- A.7.12Protecting power and network cabling
- A.7.13Maintaining equipment so it keeps working
- A.7.14Wiping equipment before disposal or reuse
Every control here needs an applicability decision and a justification in your Statement of Applicability, including the ones you exclude. What certification costs, and which clauses StandardOS covers.
Decide all 14 in one pass
StandardOS pre-fills applicability and a draft justification for every Annex A control from a seven-question profile, keeps each draft marked as unreviewed until you have made it yours, and tracks implementation against each one.