Annex A — Physical Controls (7.1-7.14)
Cover all 14 Physical controls, and learn how the shared responsibility model with cloud providers changes — but doesn't eliminate — an organization's physical control obligations.
Learning Objectives
- → List all 14 Physical controls grouped into 4 practical clusters
- → Explain which Physical controls typically transfer to a cloud/IaaS provider, and which never do
- → Justify a Physical control transfer in an SoA using supplier certifications as evidence
- → Identify what 'clear desk and clear screen' actually requires in practice
Physical controls cover protecting information and systems from physical and environmental threats. For any organization using cloud infrastructure, this theme raises a question that trips up many Foundation-level learners: if you don't own a data center, do these controls even apply to you? The short answer is: mostly transferred, never fully eliminated.
The 14 controls in 4 clusters
| Cluster | Controls | Core idea |
|---|---|---|
| Perimeter & entry | 7.1-7.4 | Physical boundaries, controlled entry, secured facilities, and monitoring of physical access |
| Environmental & infrastructure protection | 7.5, 7.8, 7.11, 7.12 | Protection from fire/flood/power loss, correct equipment placement, reliable utilities, secure cabling |
| Secure work practices | 7.6, 7.7 | Behavior in secure areas, and the clear desk/clear screen discipline |
| Asset lifecycle & off-site handling | 7.9, 7.10, 7.13, 7.14 | Protecting assets outside the office, managing storage media, maintaining equipment, and disposing of it securely |
The shared responsibility model, applied to Annex A
If your organization runs entirely on cloud infrastructure (as many modern software companies do), controls like 7.1 (perimeters), 7.2 (entry), 7.4 (physical monitoring), 7.5 (environmental threats), 7.11 (utilities), and 7.12 (cabling) are, in practice, the cloud provider's responsibility — they operate the data center. This is a completely legitimate SoA position, but it must be documented as a transfer with evidence, not silently assumed:
- A defensible SoA entry looks like: "Control 7.1 is addressed via our IaaS provider [Provider], whose data centers hold [specific certification, e.g. ISO/IEC 27001] covering physical security — see supplier certification on file, reviewed [date]."
- An indefensible SoA entry looks like: leaving the control blank, or writing "not applicable" with no explanation, when your organization is clearly relying on someone else's physical security without having verified it.
What never transfers to a cloud provider
Some Physical controls remain entirely your own responsibility regardless of hosting model, because they concern your own premises, equipment, and staff behavior:
- 7.6 (working in secure areas) and 7.7 (clear desk/clear screen) — your employees' actual desks, screens, and home offices
- 7.9 (security of assets off-premises) — the laptop an employee takes home or to a coffee shop
- 7.10 (storage media) — how you physically handle backup drives, USB keys, or printed documents, wherever they live
- 7.13/7.14 (maintenance and disposal) — your own laptops and office equipment, even if servers are cloud-hosted
Clear desk, clear screen — more than a tidiness rule
Control 7.7 is frequently underestimated as a minor housekeeping matter. In practice it means: sensitive documents are not left visible on a desk when unattended, screens automatically lock after a short period of inactivity, and printed sensitive material isn't left at a shared printer. The security rationale is simple — a locked front door (7.2) does nothing if a visitor, cleaner, or unauthorized colleague can casually read a customer contract left open on a monitor.
Secure disposal (7.14) — the forgotten control
7.14 requires that equipment (and the storage media inside it) be securely wiped or destroyed before disposal or reuse — a control that's easy to forget precisely because disposal happens rarely and doesn't feel like "daily security work." A donated old laptop with an unwiped hard drive, or a decommissioned server sold on secondary markets with data still recoverable, is a real, recurring category of data breach in the wild — not a hypothetical exam scenario.
A fully cloud-hosted SaaS company (no owned data center, all staff remote) is building its SoA. For each control, decide whether it can reasonably be marked as addressed via the cloud provider's certification, or whether it remains the company's own direct responsibility: (a) 7.2 Physical entry, (b) 7.9 Security of assets off-premises, (c) 7.11 Supporting utilities, (d) 7.7 Clear desk and clear screen.
Can control 7.9 (security of assets off-premises) be addressed via the cloud provider's certification?
Can control 7.11 (supporting utilities) reasonably be addressed via the cloud provider's certification, for a fully cloud-hosted company?
Draft one SoA entry (2-3 sentences) for control 7.1 (physical security perimeters) for a company hosted entirely on a named cloud provider of your choosing, following the pattern from the lesson content (naming the provider, citing a certification, noting a review date).
What is the key difference between a defensible SoA transfer entry and an indefensible blank/silent one?