ISO/IEC 27001:2022 Annex A · Control 7.5
Protecting Against Physical and Environmental Threats: A Practical Implementation Guide
Protect people, information and equipment from fire, water, temperature, power and location-specific hazards.
This control concerns designing and implementing protection against physical and environmental threats.
What should the control achieve?
- Site-specific threats are assessed.
- Preventive, detective and response measures are layered.
- Environmental conditions are monitored.
- Exercises and maintenance demonstrate readiness.
Step-by-step implementation
Identify hazards
Consider fire, flood, leak, heat, humidity, earthquake, storm, pollution, civil disturbance and nearby hazards.
Assess exposure and impact
Map critical rooms, floor level, utilities, drainage, construction and single points of failure.
Reduce likelihood
Use suitable location, fire separation, leak prevention, maintenance and safe storage.
Detect early
Deploy smoke, heat, water, temperature and humidity monitoring with alerts.
Prepare response
Coordinate evacuation, shutdown, salvage, emergency services and continuity.
Test and maintain
Inspect sensors, extinguishing systems, drainage and response plans.
What this could look like in practice
A basement comms room is found vulnerable to water ingress. Equipment is raised, leak sensors alert Facilities, shutoff valves are labeled and a migration plan moves the most critical service to a safer room.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Fire | Detection and suitable suppression protect the equipment area. | Inspection and test |
| Water | Sensors, raised racks and drainage reduce damage. | Alarm test |
| Temperature | Redundant cooling and threshold alerts are monitored. | Environmental log |
| Storm | Continuity plan addresses site inaccessibility and power loss. | Exercise record |
Implementation evidence
- Environmental risk assessment
- Hazard maps
- Sensor configuration
- Maintenance records
- Alarm tests
- Emergency procedures
- Exercise results
- Corrective actions
Useful metrics
- Environmental alarms tested
- Threshold excursions
- Protective maintenance overdue
- High-risk findings unresolved
Common mistakes
- Using a generic hazard list without site inspection.
- Placing critical equipment below water pipes.
- Sending alerts to unattended mailboxes.
- Installing suppression unsuitable for equipment.
- Failing to include climate and neighborhood changes.
Questions an auditor may ask
- Which hazards are most relevant here?
- How are conditions monitored?
- Show maintenance and alarm tests.
- What happens after hours?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.