Protection Against Physical and Environmental Threats
Protection against physical and environmental threats refers to the precautions an organization puts in place to guard its facilities, systems, and supporting equipment against events such as natural disasters, crime, and civil unrest. The goal is to prevent unauthorized physical access, damage, or interference to information and information processing facilities. In practice, this means designing and maintaining secure areas and safeguards that reduce the consequences of physical and environmental incidents.
In the ISO/IEC 27001:2022 revision, this maps to Annex A control 7.5, a preventive control (detailed in ISO/IEC 27002) that requires organizations to assess and mitigate the risks arising from physical and environmental threats, including natural disasters, civil unrest, and crime. It is one of the reference controls that an organization may select through its Statement of Applicability, informed by its risk assessment, rather than a certifiable ISMS requirement in clauses 4 through 10. The control focuses on preventing or reducing the consequences of physically or environmentally originating events affecting secure areas, buildings, systems, and supporting equipment; its applicability, implementation depth, and specific measures depend on the organization's scope and risk profile. Note that earlier editions structured related requirements differently (for example, under the ISO 27001:2013 Annex A.11 physical and environmental security domain), so control identifiers and counts should be cited with reference to the specific standard version.
Why it matters
Physical and environmental threats represent a distinct category of risk that technical safeguards alone cannot address. An organization can maintain strong logical access controls, encryption, and network defenses, yet still suffer significant harm if an intruder gains physical access to a server room, a fire damages information processing facilities, or a flood renders supporting equipment inoperable. Protection against physical and environmental threats is intended to prevent or reduce the consequences of events originating from natural disasters, crime, and civil unrest, closing a gap that purely digital controls leave open.
Because this control focuses on preventing unauthorized physical access, damage, or interference to information and information processing facilities, its relevance extends beyond the data center to buildings, secure areas, and the supporting equipment on which systems depend. The consequences of a physical or environmental incident can be severe and immediate: loss of availability, damage to systems, or exposure of information held on-site. Addressing these risks proactively is generally more effective than responding after an incident has occurred.
Within an ISO/IEC 27001:2022 program, this maps to Annex A control 7.5, a preventive control that an organization may select through its Statement of Applicability based on its risk assessment. Because it is a reference control rather than a certifiable ISMS requirement in clauses 4 through 10, its applicability and implementation depth depend on the organization's scope and risk profile. Organizations that operate their own facilities or house sensitive equipment on-premises typically place greater weight on this control than those relying primarily on third-party or cloud-hosted infrastructure, though the underlying threats warrant consideration in most environments.
Who it's relevant to
Inside Protection Against Physical and Environmental Threats
Common questions
Answers to the questions practitioners most commonly ask about Protection Against Physical and Environmental Threats.