Skip to content
arrow_back
search
Annex A 7.5 verified ISO/IEC 27001:2022

Protecting against physical and environmental threats

Plan and implement actions to prevent damage from natural and human threats to physical infrastructure.

record_voice_over

Plain language

This control means setting up safeguards to protect your business’s physical infrastructure from potential hazards like natural disasters or intentional harm. Imagine a flood or fire hitting your office unexpectedly; without preparations, your important documents and systems could be destroyed, potentially halting operations and leading to significant losses.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Physical controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Protection against physical and environmental threats, such as natural disasters and other intentional or unintentional physical threats to infrastructure shall be designed and implemented.
verified ISO/IEC 27001:2022 Annex A 7.5
priority_high

Why it matters

Without protections for fire, flood, power loss or unauthorised access, facilities and equipment may be damaged, causing outages, data loss and major financial/reputational harm.

settings

Operational notes

Test and maintain controls for fire, flood and power events (alarms, UPS/generators, HVAC, leak detection), and review site risks and physical access arrangements after changes.

Mapping detail

Mapping

Direction

Controls