Cyber security starts with where people can physically go.
Annex A 7.1 exists to ensure organisations define and protect physical security perimeters, so information and associated assets are shielded from unauthorised physical access, damage, or interference.
This control is about establishing clear physical boundaries — and controlling what crosses them.

Annex A 7.1 of ISO 27001:2022 focuses on physical security perimeters.
At a practical level, this means:
The control does not prescribe specific technologies or layouts. It expects organisations to apply appropriate, risk-based physical boundaries.
Information security is not purely digital.
Many serious security incidents begin with:
Annex A 7.1 ensures organisations establish physical barriers and boundaries that reduce these risks before technical controls are even tested.
This control applies to:
If information can be accessed physically, physical security matters.
A pragmatic approach to Annex A 7.1 typically includes the following elements.
Organisations should identify where physical boundaries are required, based on:
Perimeters may exist at multiple levels, including:
Clear definition supports consistent protection.
Physical security perimeters are commonly implemented using:
Barriers should be appropriate to the environment and the level of risk being managed.
Perimeters are only as effective as their weakest point.
Organisations should consider:
Overlooked access points are a common cause of perimeter failure.
Physical perimeters are often supported by additional measures, such as:
These measures act as both deterrents and detection mechanisms.
Annex A 7.1 is not limited to buildings.
Organisations should also consider:
Perimeter controls should align with what is being protected inside them.
Physical security perimeters work best as part of a layered approach.
They typically support:
No single control is effective in isolation.
Annex A 7.1 does not require:
It does require organisations to:
Physical security should be visible, consistent, and maintained.
Physical breaches are often silent — prevention is critical.
Annex A 7.1 is about controlling physical access before digital controls are tested.
When physical security perimeters are implemented effectively:
Information security does not start at the firewall.
It starts at the front door, boundary, and barrier.
That is exactly what Annex A 7.1 is designed to reinforce.
We can help you understand your actual security needs and even if we cant help we can point you in the right direction
Talk to a security expert today