ISO 27001 Annex A: physical controls (A.7)
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 27001
For a cloud-first company, A.7 is mostly inherited from your data-centre providers — but "we use AWS" is an answer you still have to document.
What A.7 covers
The physical theme covers the tangible: physical security perimeters and secure areas, protection against environmental threats, equipment siting and maintenance, secure disposal or reuse of equipment, clear-desk/clear-screen practices, and the handling and disposal of storage media.
Most of it is inherited
If your production runs in the cloud, the heavy physical controls — data-centre access, environmental protection, hardware security — are operated by your provider and evidenced by their SOC 2 / ISO 27001 attestations. You inherit them and reference those reports rather than building data-centre security yourself.
What you still own
You remain responsible for what you physically control: any offices (access control, secure areas), employee devices and their disposal, clear-desk/clear-screen behaviour, and media handling — wiping or destroying drives before disposal. For a remote company this is mostly device management and a media-disposal process.
Document the inheritance
The Statement of Applicability should show, for each physical control, whether you operate it or inherit it (with the provider attestation referenced) — "not applicable" is rarely the right answer; "inherited from cloud provider" usually is. SentinelPanda tracks inherited controls and links the provider evidence.