Skip to main content
Category: Control Types and Framework

Physical Controls

Also known as: Physical Security Controls, Physical Access Controls
Simply put

Physical controls are the tools and procedures organizations use to protect their buildings, equipment, people, and stored information from unauthorized physical access or harm. Examples include locks, security monitoring, facility access systems, and secure handling of storage media. Their purpose is to deter, prevent, or detect someone gaining entry to a location or asset they should not reach.

Formal definition

Physical controls are security measures implemented within a defined structure to deter, prevent, or detect unauthorized physical access to sensitive facilities, systems, equipment, and materials. Typical measures include physical access control systems that authorize or restrict entry to a building or specific areas, security monitoring, facility security, maintenance provisions, and controls over storage media. Under ISO/IEC 27001, physical controls appear as a group of reference controls within Annex A (the physical controls theme in the 2022 revision); as with all Annex A controls, their selection and applicability are determined through risk assessment and documented in the Statement of Applicability rather than being universally mandated. In a SOC 2 examination, comparable physical safeguards are typically evaluated where relevant to the Security (Common Criteria) category, with the specific controls tested depending on the engagement scope.

Why it matters

Physical controls address a category of risk that logical and technical safeguards alone cannot cover: the possibility that someone gains direct physical access to a facility, a server room, an endpoint, or storage media containing sensitive information. Even a well-hardened network can be undermined if an unauthorized person can walk into a data center, remove a drive, or tamper with equipment. For this reason, physical safeguards, access control systems that authorize or restrict entry, security monitoring, facility security, maintenance provisions, and controls over storage media, form a foundational layer of an organization's overall security posture.

In a compliance context, physical controls matter because they are examined under both major frameworks, though through different mechanisms. Under ISO/IEC 27001, physical controls appear as a group of reference controls in Annex A (the physical controls theme in the 2022 revision), and their selection is driven by risk assessment and documented in the Statement of Applicability rather than being universally mandated. In a SOC 2 examination, comparable physical safeguards are typically evaluated where relevant to the Security (Common Criteria) category, with the specific controls tested depending on the engagement scope. In both cases, the assessment covers only the defined scope, so the presence of physical controls attests to what was examined and does not on its own guarantee freedom from physical compromise.

Because physical and logical risks often intersect, an attacker with physical access may bypass logical restrictions, and vice versa, organizations generally treat physical controls as complementary to their technical measures rather than as a standalone concern. Neglecting this layer can leave a gap that undermines otherwise robust controls, which is why auditors and certification bodies examine physical safeguards as part of a broader review of an organization's security environment.

Who it's relevant to

Compliance and GRC Managers
Compliance and GRC managers need to determine which physical controls are in scope for their audits and certifications. For ISO 27001, this means documenting the selection and applicability of physical reference controls in the Statement of Applicability based on risk assessment. For SOC 2, it means understanding where physical safeguards fall within the Security (Common Criteria) category and defining the engagement scope accordingly.
Auditors and Assessors
CPA firms performing SOC 2 examinations and certification bodies assessing ISO 27001 ISMS evaluate physical controls as part of a broader review. The specific controls tested depend on scope: SOC 2 assessors examine physical safeguards where relevant to the Security category, while ISO 27001 assessors verify that selected Annex A physical controls are appropriately justified through risk assessment and documented in the Statement of Applicability.
Security Engineers and Facilities Teams
Those responsible for implementing and maintaining physical safeguards, access control systems, security monitoring, facility security, maintenance provisions, and secure handling of storage media, need to ensure these measures function as intended and produce the evidence auditors will examine. Because physical and logical risks intersect, these teams typically coordinate with technical security staff so that physical controls complement, rather than duplicate or conflict with, logical protections.

Inside Physical Controls

Physical Access Controls
Mechanisms that restrict entry to facilities, data centers, and areas housing information systems, such as badge readers, biometric scanners, locks, and visitor sign-in procedures. In SOC 2 engagements these are commonly evaluated under the Common Criteria (Security) category, and in ISO 27001 they are addressed by Annex A physical reference controls selected via the Statement of Applicability.
Environmental Protections
Safeguards that protect equipment and facilities from environmental threats, including fire suppression, temperature and humidity monitoring, power redundancy, and water detection. The extent to which these are examined typically depends on scope, and where availability commitments are in scope of a SOC 2 report they may receive additional attention under the optional Availability category.
Monitoring and Surveillance
Detective measures such as video surveillance, intrusion detection, and logging of physical entry and exit events used to support accountability and investigation. The specific measures in place vary by facility, provider, and scoping decisions.
Framework Placement
Physical controls appear differently in each framework. Under SOC 2 they are assessed as controls supporting the applicable Trust Services Criteria in an attestation examination performed by a licensed CPA firm. Under ISO 27001 they are reference controls in Annex A, whose selection is informed by risk assessment and documented in the Statement of Applicability, rather than requirements from clauses 4 through 10.

Common questions

Answers to the questions practitioners most commonly ask about Physical Controls.

Does a SOC 2 report certify that an organization's physical controls are effective?
No. SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, resulting in a report rather than a certificate. A SOC 2 report describes and evaluates the physical controls within the defined scope over the covered period, but it does not issue a certification and does not guarantee freedom from breaches. It attests only to the controls and period examined.
Are physical controls governed by the same requirements under SOC 2 and ISO 27001?
Not identically. Under SOC 2, physical safeguards are addressed through the Trust Services Criteria, primarily the Security category (Common Criteria). Under ISO 27001, physical controls appear among the Annex A reference controls, which are selected via a Statement of Applicability and informed by a risk assessment. The Trust Services Criteria and Annex A controls are distinct structures, and mapping between them is possible but partial, so satisfying one framework's physical control expectations does not automatically satisfy the other's.
How does an organization decide which physical controls to include in its ISO 27001 scope?
In most implementations, physical controls relevant to the ISMS are identified through the risk assessment and documented in the Statement of Applicability, which records which Annex A reference controls are applicable and why. The applicable controls depend on the defined scope of the ISMS, the assets involved, and the identified risks, so the selection varies by organization and engagement.
What kinds of evidence typically support physical controls in a SOC 2 Type II examination?
Because a SOC 2 Type II assesses both the design and operating effectiveness of controls over a defined review period, evidence typically demonstrates that physical controls operated consistently throughout that period rather than at a single point in time. The specific evidence expected depends on the auditor, the scope, and the applicable criteria, and the length of the review period is set by scoping decisions rather than a fixed duration.
Do physical controls factor into a SOC 2 Type I examination?
A SOC 2 Type I assesses the suitability of the design of controls at a point in time, so it may evaluate whether physical controls are designed appropriately as of a specified date. It does not, however, evaluate operating effectiveness over a period. That distinction typically influences how physical controls are documented and reviewed depending on which type of examination is scoped.
How should an organization handle physical controls when it maintains both a SOC 2 report and an ISO 27001 certificate?
In most engagements, organizations coordinate the two efforts by mapping common physical control activities across the frameworks, while recognizing the mapping is partial. A SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS, so the boundaries of each should be tracked separately even where the underlying physical safeguards overlap.

Common misconceptions

Physical controls are mandatory line items that every organization must implement identically to pass an audit or certification.
The applicable physical controls depend on scope, risk assessment, and the auditor or certification body. In ISO 27001, Annex A controls are selected via the Statement of Applicability and may be excluded with justification, while in SOC 2 the relevant controls follow from the criteria in scope. Requirements are not universal beyond what each standard itself mandates.
If a cloud provider's data center passes physical controls in one framework, the same evidence automatically satisfies the other framework.
Mapping between SOC 2 and ISO 27001 is possible but partial, and satisfying one does not automatically satisfy the other. Physical controls evaluated in a SOC 2 attestation and those documented as Annex A reference controls in an ISO 27001 ISMS are assessed under different processes and outputs.
A clean SOC 2 report or ISO 27001 certificate covering physical controls guarantees a facility cannot be breached.
A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches, and an ISO 27001 certificate covers only the defined scope of the ISMS. Neither outcome is a guarantee of security beyond those boundaries.

Best practices

Document the physical control boundary clearly in scope, distinguishing facilities you operate from those operated by third parties such as cloud or colocation providers, and obtain their reports or certificates for controls you rely on.
For ISO 27001, justify the inclusion or exclusion of physical Annex A reference controls in the Statement of Applicability based on your risk assessment, and specify the standard version when referencing control structure since counts differ between editions.
For SOC 2, map physical controls to the applicable Trust Services Criteria, recognizing that Security (the Common Criteria) is required while categories such as Availability are included only when in scope.
Retain evidence of operating effectiveness over the review period for a SOC 2 Type II engagement, since it assesses both design and operating effectiveness across a period whose length is set by scoping decisions.
Coordinate physical controls with your service providers' attestations or certifications, and confirm what each provider's report or certificate actually covers rather than assuming full coverage.
Periodically reassess physical controls against changes in facilities, threats, and scope so that documentation reflects current arrangements rather than a prior point-in-time state.