Physical Controls
Physical controls are the tools and procedures organizations use to protect their buildings, equipment, people, and stored information from unauthorized physical access or harm. Examples include locks, security monitoring, facility access systems, and secure handling of storage media. Their purpose is to deter, prevent, or detect someone gaining entry to a location or asset they should not reach.
Physical controls are security measures implemented within a defined structure to deter, prevent, or detect unauthorized physical access to sensitive facilities, systems, equipment, and materials. Typical measures include physical access control systems that authorize or restrict entry to a building or specific areas, security monitoring, facility security, maintenance provisions, and controls over storage media. Under ISO/IEC 27001, physical controls appear as a group of reference controls within Annex A (the physical controls theme in the 2022 revision); as with all Annex A controls, their selection and applicability are determined through risk assessment and documented in the Statement of Applicability rather than being universally mandated. In a SOC 2 examination, comparable physical safeguards are typically evaluated where relevant to the Security (Common Criteria) category, with the specific controls tested depending on the engagement scope.
Why it matters
Physical controls address a category of risk that logical and technical safeguards alone cannot cover: the possibility that someone gains direct physical access to a facility, a server room, an endpoint, or storage media containing sensitive information. Even a well-hardened network can be undermined if an unauthorized person can walk into a data center, remove a drive, or tamper with equipment. For this reason, physical safeguards, access control systems that authorize or restrict entry, security monitoring, facility security, maintenance provisions, and controls over storage media, form a foundational layer of an organization's overall security posture.
In a compliance context, physical controls matter because they are examined under both major frameworks, though through different mechanisms. Under ISO/IEC 27001, physical controls appear as a group of reference controls in Annex A (the physical controls theme in the 2022 revision), and their selection is driven by risk assessment and documented in the Statement of Applicability rather than being universally mandated. In a SOC 2 examination, comparable physical safeguards are typically evaluated where relevant to the Security (Common Criteria) category, with the specific controls tested depending on the engagement scope. In both cases, the assessment covers only the defined scope, so the presence of physical controls attests to what was examined and does not on its own guarantee freedom from physical compromise.
Because physical and logical risks often intersect, an attacker with physical access may bypass logical restrictions, and vice versa, organizations generally treat physical controls as complementary to their technical measures rather than as a standalone concern. Neglecting this layer can leave a gap that undermines otherwise robust controls, which is why auditors and certification bodies examine physical safeguards as part of a broader review of an organization's security environment.
Who it's relevant to
Inside Physical Controls
Common questions
Answers to the questions practitioners most commonly ask about Physical Controls.