Physical security controls only work if breaches are detected, not just prevented.
Annex A 7.4 exists to ensure organisations monitor physical security effectively, so unauthorised access, intrusion, or suspicious activity is detected early and responded to before information or assets are compromised.
This control is about visibility and deterrence, not constant surveillance.

Annex A 7.4 of ISO 27001:2022 focuses on physical security monitoring.
At a practical level, this means:
The control does not mandate specific technologies or continuous monitoring everywhere. It expects risk-based monitoring aligned to physical security needs.
Even well-designed physical security perimeters and entry controls can fail.
Without monitoring:
Annex A 7.4 ensures organisations do not rely solely on barriers and locks, but actively monitor physical security to detect and deter unauthorised activity.
This control supports:
A pragmatic approach to Annex A 7.4 typically includes the following elements.
Monitoring should be focused where risk justifies it.
This commonly includes:
Not all spaces require the same level of monitoring.
Monitoring measures may include:
Controls should be appropriate to the environment and threat, not deployed by default.
Effective monitoring:
Monitoring that is not observed or acted upon adds limited value.
Monitoring should feed into:
Detection without response does not reduce risk.
Monitoring systems are security assets.
Organisations should ensure:
If monitoring systems fail silently, risk increases.
Physical security monitoring often involves people.
Organisations should ensure:
Compliance failures can create legal risk greater than the security risk being addressed.
Physical environments change.
Organisations should periodically review:
Monitoring that is not reviewed gradually loses relevance.
Annex A 7.4 does not require:
It does require organisations to:
Physical monitoring should be targeted, justified, and maintained.
Monitoring fails most often through neglect, not absence.
Annex A 7.4 is about knowing when physical security fails.
When physical security monitoring is implemented effectively:
Barriers slow attackers.
Monitoring tells you when they succeed.
That is exactly what Annex A 7.4 is designed to ensure.
We can help you understand your actual security needs and even if we cant help we can point you in the right direction
Talk to a security expert today