Not all security threats are digital.
Some arrive as fire, water, heat, power loss, or civil disruption.
Annex A 7.5 exists to ensure organisations identify and protect against physical and environmental threats that could damage information, systems, or supporting infrastructure.
This control is about anticipating what could physically go wrong — and designing for it.

Annex A 7.5 of ISO 27001:2022 focuses on protecting information and assets from physical and environmental threats.
At a practical level, this means:
The control does not require elimination of all risk. It expects reasonable, risk-based protection against foreseeable threats.
Physical and environmental threats include:
These threats can lead to:
Annex A 7.5 ensures organisations do not assume buildings and environments are inherently safe, but assess and manage physical risk deliberately.
A pragmatic approach to Annex A 7.5 typically includes the following elements.
Organisations should identify threats relevant to their:
Different sites face different risks. Controls should reflect reality, not templates.
Risk assessment should consider:
This assessment informs which protections are justified.
Controls may include:
Controls should protect both information and the infrastructure that supports it.
Annex A 7.5 supports considering physical risk when:
Avoidable exposure should be addressed early rather than mitigated later.
Physical threats are not limited to natural events.
Organisations should also consider:
Environmental design, layout, and physical security controls all contribute to risk reduction.
Protective controls must remain effective.
Organisations should:
Unmaintained controls create false confidence.
Physical and environmental protection supports:
Annex A 7.5 works closely with continuity-focused controls, ensuring prevention and preparedness align.
Annex A 7.5 does not require:
It does require organisations to:
Many major outages are environmental, not malicious.
Physical threats rarely announce themselves in advance.
Annex A 7.5 is about protecting information from the physical world it depends on.
When physical and environmental threats are managed effectively:
Cyber controls protect data from attackers.
Annex A 7.5 protects it from fire, water, power, and gravity.
Both are essential.
We can help you understand your actual security needs and even if we cant help we can point you in the right direction
Talk to a security expert today