ISO/IEC 27001:2022 Annex A · Control 7.1
Physical Security Perimeters: A Practical Implementation Guide
Use layered physical boundaries to protect locations where sensitive information and critical systems are handled.
This control concerns defining and using physical security perimeters to protect areas containing information and associated assets.
What should the control achieve?
- Security zones and boundaries are defined.
- Protection matches the assets and threats within each zone.
- Entry points, walls, doors and openings support the boundary.
- Perimeter effectiveness is inspected and maintained.
Step-by-step implementation
Map assets and activities
Identify sensitive information, critical equipment, personnel and dependencies by location.
Assess physical threats
Consider intrusion, tailgating, theft, protest, neighboring tenants, fire and environmental exposure.
Define security zones
Create public, controlled, restricted and high-security areas with clear boundaries.
Design the perimeter
Select doors, walls, locks, reception, barriers, alarms and lighting appropriate to risk.
Control openings and shared areas
Address windows, loading bays, ceilings, ducts, shared corridors and emergency exits.
Inspect and test
Review damage, access paths, alarm coverage and changes to layout or tenancy.
What this could look like in practice
A data-processing office separates public reception from staff areas using badge-controlled doors. The server room forms a second restricted perimeter with stronger construction, separate authorization and monitored entry.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Site boundary | Lighting, fencing and clear approaches deter unauthorized access. | Inspection record |
| Office zone | Reception controls visitors before staff-space entry. | Visitor and access logs |
| Server room | Independent restricted zone limits authorized roles. | Access configuration |
| Emergency exit | Exit allows safe egress but alarms unauthorized entry. | Alarm test |
Implementation evidence
- Physical risk assessment
- Site and zone diagrams
- Perimeter standards
- Door and lock inventory
- Access authorization
- Alarm tests
- Inspection records
- Corrective maintenance
Useful metrics
- Perimeter defects overdue
- Forced or unauthorized entry events
- Alarm tests passed
- High-security areas reviewed
Common mistakes
- Treating every area as equally sensitive.
- Ignoring shared-building routes and ceilings.
- Blocking emergency egress.
- Leaving loading areas uncontrolled.
- Failing to reassess after office redesign.
Questions an auditor may ask
- How were security zones defined?
- Which threats influenced perimeter design?
- Show inspection and alarm testing.
- How are shared premises controlled?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.