How the 2026 amendments are reshaping personal grievances
This article provides a comprehensive overview of how these amendments will impact the way the...
Annex A:11 of the ISO 27001 Controls focuses on physical and environmental security programs. It defines various controls to protect organisations from loss of information caused by theft, fire, flood, intentional destruction, unintentional damage, mechanical equipment failure, and power failures.
Physical security measures should be sufficient to deal with foreseeable threats and should be tested periodically for their effectiveness and functionality. This increases the rate of risk-based thinking and planning regarding information security.
Best practices and ISO standards can assist with evaluating physical security controls, such as ISO/IEC 27002:2013, to ensure your organisation remains protected.
Annex A:11 is all about the physical and environmental security of your office and related areas. It helps understand how to maintain a secure environment around your organisation’s workspace.
To prevent unauthorised physical access, damage, and interference with the organisation’s information and information processing facilities.
Security perimeters should be established based on the security requirements of the assets inside the perimeter and the results of the risk assessment. This includes office premises, corridors, and facilities.
A physical security perimeter is defined as “any transition boundary between two areas of differing security protection requirements.”
Examples include:
The organisation must establish secure areas to protect valuable information and information assets that only authorised people can access.
This clause covers building security. For ISO 27001 certification, the information secured area must be protected from unauthorised entry.
This clause addresses the security of the organisation’s electronic assets, such as computers, laptops, servers, and other physical equipment. For ISO 27001 certification, information should be stored and retained securely.
Things to remember:
This clause focuses on protecting against inevitable attacks on the organisation, whether environmental or cyber threats. Natural disasters like floods, earthquakes, and fires require organisations to have procedures and policies to deal with these threats.
Identify the risks around your business areas and understand your location and immediate vicinity to recognise potential threats. Physical and environmental threats must be recognised and controlled by the organisation.
This clause deals with the safety of the organisation’s personnel. Procedures for working in secure areas should be designed and applied, including:
Complete control of all access points is necessary. Information stored within the building should be secured and considered a legal responsibility. The Statement of Applicability (SOA) will assess delivery and pick-up points for monitored and valid key entry.
Digital or virtual workplaces might not need policies or controls around delivery and loading areas and can exclude this from the SOA.
Examples of controls include:
For more guidance and support on achieving ISO 27001 certification and understanding Annex A:11, contact Citation Certification today. We provide comprehensive support and training to help your organisation meet all necessary requirements and achieve compliance with ISO 27001 standards.