Skip to content
arrow_back
search
Annex A 7.2 verified ISO/IEC 27001:2022

Physical access controls for secure areas

Ensure only authorised people can enter secure areas and prevent unauthorised access.

record_voice_over

Plain language

This control is about making sure only people who are allowed can enter secure areas of a business, like server rooms or archives. It matters because if unauthorised people can get in, they might steal or damage important information or equipment, putting the organisation at risk.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Physical controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Secure areas shall be protected by appropriate entry controls and access points.
verified ISO/IEC 27001:2022 Annex A 7.2
priority_high

Why it matters

Unauthorised access to secure areas can enable theft or tampering with systems and media, leading to data breaches, outages and reputational damage.

settings

Operational notes

Review access lists and entry logs for secure areas, test door and badge controls, and revoke access promptly when roles change or staff leave.

Mapping detail

Mapping

Direction

Controls