ISO27001:2022 – A7.5
Protecting against physical and environmental threats
Want to fast track your ISO 27001 journey?
Our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements. Take a look, and when you buy it, you also receive our “Real Easy Guide To ISO27001” book (available on Amazon).
Introduction to ISO 27001 – A7.5
When people think about information security, they usually picture hackers, malware, and phishing emails.
ISO27001 gently reminds us of something else:
Fire, flood, power cuts, protestors, storms, and plain old gravity can take you down just as quickly.
That’s exactly what ISO27001 – A7.5 – Protecting against physical and environmental threats is all about.
What does the standard require?
The standard states that “Protection against physical and environmental threats, such as natural disasters and other intentional or unintentional physical threats to infrastructure shall be designed and implemented.” (ISO 27001 – A7.5)
Why is this required?
In plain English:
You must think about real-world threats to your buildings, equipment, and people – and do something sensible about them.
This control isn’t saying you must stop earthquakes or hurricanes. It is saying that where you can influence decisions, you must factor these risks in and apply proportionate protection.
“But I don’t control the building…”
That’s a common reaction. And it’s only half true.
You may not own the premises, but:
-
You chose the location
-
You use the facilities
-
You depend on them to keep your business running
The requirement is that protection is designed and implemented. That might involve:
-
Selecting safer locations where possible
-
Working with landlords and facilities teams
-
Putting compensating controls in place where risks exist
What the auditor is looking for
Auditors don’t expect perfection. They do expect evidence that you’ve thought this through properly.
That evidence usually falls into two buckets: process and physical controls.
Process evidence
-
Site-specific risk assessments
-
Risk register entries covering physical/environmental threats
-
Internal audit reports
-
Incident response plans (A5.26)
-
Incident investigation processes (A5.28)
-
Incident logs
-
Test results (fire drills, power failover tests, etc.)
Physical and technical controls
Depending on your risk profile, this might include:
-
Walls, fences, and controlled entry points
-
Bollards or barrier posts
-
Intruder alarms
-
Environmental alarms (e.g. underfloor water detection)
-
Smoke detectors and fire alarms
-
Evidence of fire alarm testing
-
Fire drills and evacuation tests
-
HVAC maintenance contracts
-
Shutters or reinforced doors/windows
-
Flood defences (barriers, channels, sandbags, etc.)
-
UPS devices protecting servers or critical equipment
-
Onsite generators for prolonged power outages
Not all of these will apply to you, and that’s absolutely fine but they give you an idea on what might be appropriate for this control.
What do you need to do?
This control starts and ends with risk assessment.
Assess your site
- What could realistically go wrong here?
- What has happened locally before?
Identify what’s already in place
- Many controls exist without being documented.
- our landlord may already manage several risks.
Decide what’s proportionate
-
Easy wins first
-
Then address the higher-impact risks
Take an uninterruptible power supply (UPS) as an example:
-
Simple to buy
-
Easy to install
-
Low ongoing effort
But ask the right questions:
-
How long will it keep systems running?
-
Is that long enough?
-
Does it reduce real business impact, or just delay the inevitable?
ISO27001 isn’t about buying kit – it’s about reducing risk in a meaningful way.
Difficulty rating
It’s not technically complex.
It’s mostly about:
-
Asking the right questions
-
Speaking to the right people (facilities, landlords, neighbours)
-
Documenting what you find
-
Addressing obvious gaps
Done well, A7.5 strengthens not just your ISO27001 position, but your operational resilience too.
And that’s a win, whether an auditor is involved or not.
Q&A: “What if we’re in a city centre?”
City centres come with a different threat profile:
-
Social disturbance
-
Vandalism
-
Terrorism risks
-
Transport and aviation proximity
-
Power and infrastructure dependencies
You can’t eliminate these risks — but you can:
-
Understand them
-
Document them
-
Apply sensible controls
-
Show you’ve made informed decisions
Once again: start with the site risk assessment and build from there.
More questions?
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” which is available on Amazon.
Fastback your journey to ISO27001 and buy our Policies to get started TODAY!
Take a look at our “ISO 27001:2022 Policy Pack” and when coupled with our book you’ll have everything you need to succeed in achieving ISO 27001 certification!
