Skip to content

ISO 27001 Annex A: physical controls (A.7)

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 27001

For a cloud-first company, A.7 is mostly inherited from your data-centre providers — but "we use AWS" is an answer you still have to document.

What A.7 covers

The physical theme covers the tangible: physical security perimeters and secure areas, protection against environmental threats, equipment siting and maintenance, secure disposal or reuse of equipment, clear-desk/clear-screen practices, and the handling and disposal of storage media.

Most of it is inherited

If your production runs in the cloud, the heavy physical controls — data-centre access, environmental protection, hardware security — are operated by your provider and evidenced by their SOC 2 / ISO 27001 attestations. You inherit them and reference those reports rather than building data-centre security yourself.

What you still own

You remain responsible for what you physically control: any offices (access control, secure areas), employee devices and their disposal, clear-desk/clear-screen behaviour, and media handling — wiping or destroying drives before disposal. For a remote company this is mostly device management and a media-disposal process.

Document the inheritance

The Statement of Applicability should show, for each physical control, whether you operate it or inherit it (with the provider attestation referenced) — "not applicable" is rarely the right answer; "inherited from cloud provider" usually is. SentinelPanda tracks inherited controls and links the provider evidence.

ISO 27001 Annex A technological controls (A.8) Compliance for fully-remote teams

Run your compliance program in one workspace.