A.7.1 Physical
Physical security perimeters
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (13)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-3mostlycovers — Both controls require physical barriers and entry controls around areas housing information assets, with the ISO guidance on perimeter strength and locking directly supporting the NIST requirement to enforce physical access authorization at defined boundaries.
- PE-2partialaligns with — Defining and siting security perimeters according to asset sensitivity aligns with the need to authorize and document who may physically access specific system components or areas.
- PE-4partialaligns with — Protecting external doors, windows, and ventilation points on the perimeter helps control physical access to transmission media and cabling that may traverse or terminate at the boundary.
- PE-6partialaligns with — The requirement to alarm and monitor fire doors and perimeter openings supports ongoing surveillance of physical access points to detect unauthorized entry attempts.
- PE-2covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PE-4covers — A.7.1's broad physical-perimeter mandate reaches the slice of transmission-medium physical access inside facilities but leaves the bulk of PE-4's specific transmission-focused requirements (e.g., exact media types, parameters, and controls) uncovered.
- PE-6covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (14)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.IR-02fullcovers — The ISO control's focus on constructing and maintaining physically sound perimeters directly implements the CSF outcome of protecting technology assets from environmental threats.
- PR.AA-06mostlycovers — By specifying perimeter strength, access controls on doors/windows, and monitoring of fire doors, the ISO control satisfies the CSF requirement to manage, monitor, and enforce physical access commensurate with risk.
- ID.AM-05partialaligns with — The control's requirement to site and strengthen perimeters according to the security needs of the assets inside aligns with prioritizing assets based on classification, criticality, and mission impact.
- PR.IR-01partialaligns with — Establishing physical perimeters and locking mechanisms contributes to preventing unauthorized logical access by first securing the physical boundary around networks and environments.
- ID.AM-05implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related weaknesses / CWE (11)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1191mitigates — Physical perimeters can limit access to debug ports but do not address on-chip access-control logic.
- CWE-1263prevents — Defines physical perimeters that directly limit unauthorized physical access to restricted areas.
- CWE-1278mitigates — Physical perimeters deter unauthorized access to IC imaging equipment but do not address chip-level protections.
- CWE-1300mitigates — Physical perimeters can limit attacker proximity needed for side-channel capture.
- CWE-1384mitigates — Physical perimeters reduce exposure to external environmental threats.
- CWE-200prevents — By physically restricting who can approach information-processing equipment, the control reduces the chance that an unauthorized actor can observe or extract sensitive information stored or processed on those systems.
- CWE-284mitigates — Physical perimeters with locked doors, solid construction, and alarms directly block unauthorized physical entry that would otherwise allow an attacker to bypass logical access controls and reach protected resources.
- CWE-552mitigates — Solid perimeters and locked external access points stop files, devices, or directories containing sensitive data from being reachable by external parties who could otherwise walk in or break in.
Mitigated MITRE ATT&CK techniques (63)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1003.003prevents — A.7.1's physical perimeters and barriers can stop an adversary from reaching a domain controller (or its backups) to run any of the listed tools, but this is only a minority slice of the class: the technique is routinely executed remotely or by an already-privileged insider who needs no physical access.
- T1005prevents — A.7.1's physical perimeters and barriers stop adversaries who lack physical presence from reaching the local system to run T1005 at all; once physical access is obtained the control has no effect on the technique (which runs via interpreters or automation against files/process memory).
- T1052detects — A.7.1's alarming/monitoring of physical perimeters and fire doors can surface unauthorized introduction or removal of a physical medium at the perimeter, but this is limited to boundary events and does not broadly detect the exfiltration technique once the medium is inside or used for data transfer.
- T1052prevents — A.7.1's physical perimeters, solid construction, locked doors/windows, and alarms directly stop an adversary from entering to introduce or remove a physical medium on air-gapped systems, but do not address insider-introduced media or post-perimeter device handling.
- T1052.001detects — A.7.1 requires alarming, monitoring and testing of physical perimeters (including doors and access points), which can surface the physical insertion or presence of a USB device at the boundary in air-gapped scenarios, but this is only a minority slice of the technique's possible vectors and does not address the data exfiltration act itself.
- T1052.001prevents — A.7.1's physical perimeter (solid walls, locked/protected doors/windows, alarms) stops an adversary from physically entering the facility to introduce or retrieve the USB device, but leaves open user-introduced devices (e.g. by authorized insiders) and does not address the data exfiltration act once a device is inside.
- T1074.001detects — A.7.1's alarming, monitoring and testing of physical perimeters can surface anomalous physical access that precedes or accompanies local staging on compromised assets, but this is limited to the physical vector and does not address the dominant logical/file-system/registry staging techniques on the listed platforms.
- T1091prevents — Strong physical barriers and access controls reduce the likelihood that malware can be introduced or spread via removable media brought into the premises.
- T1200prevents — Physical perimeters with locked doors, solid construction, and alarms directly impede an adversary's ability to introduce unauthorized hardware into the facility.
- T1200detects — A.7.1 requires monitoring (and alarming/testing) of physical perimeters and entry points, which can surface unauthorized hardware additions when they cross or affect a monitored boundary, but this is limited to observable perimeter events rather than reliably detecting all post-insertion abuse (e.g. passive tapping, DMA, or already-installed devices).
- T1219.003detects — A.7.1 requires alarming, monitoring and testing of physical perimeters (including doors, walls, and entry points) which can surface the physical installation or presence of unauthorized remote-access hardware inside the perimeter, but only for the subset of cases where the hardware crosses or is visible at a monitored boundary rather than being introduced via allowed peripherals or insider placement.
- T1219.003prevents — A.7.1's physical perimeter, solid construction, locked/protected doors/windows, and alarms directly stop unauthorized physical installation of remote access hardware (e.g. KVM) inside the facility, but the technique can still be introduced via allowed peripherals, supply-chain compromise, or post-perimeter insider action, leaving a genuine minority slice prevented.
- T1485prevents — Physical perimeters and barriers can stop an adversary from reaching on-prem systems to run local destruction commands or malware, but do nothing against remote/cloud deletion, credentialed network propagation, or virtualized/ESXi/IaaS vectors that require no physical presence.
- T1486recovers — A.7.1's physical perimeters and solid-construction barriers (with alarms, locked doors, etc.) protect information-processing facilities and the assets inside them from physical damage or interference that would otherwise prevent restoration of encrypted data (e.g. destroyed backups, offline media, or hypervisor hosts), directly supporting the recover verb in the event-lane anchors.
- T1495prevents — A.7.1's physical perimeters, solid construction, locked/protected doors/windows, and alarms directly stop many physical-access vectors that firmware attacks (e.g. malicious insertion, direct hardware tampering, or supply-chain interference at the site) require; partial because the technique can also be delivered remotely via malware or compromised updates without ever crossing a physical perimeter.
- T1542.003prevents — A.7.1 physical perimeters and solid-construction barriers (with locks/alarms) stop many raw-access vectors needed to overwrite MBR/VBR/ESP at rest, but leave open insider, supply-chain, and post-compromise logical paths that the technique explicitly allows.
- T1561.001detects — A.7.1's alarming/monitoring of physical perimeters and fire doors can surface direct physical access to hardware (a prerequisite explicitly named in the T1561.001 prose) but does not address logical/remote vectors, third-party drivers, worm-like propagation, or post-access wiping itself.
- T1561.001prevents — A.7.1's physical perimeters and access controls can stop adversaries from gaining the on-premises physical proximity or direct hardware access needed to wipe local disks (especially on servers or devices inside the perimeter), but this leaves the large remainder of remote/network-propagated wiping (via malware, credentials, admin shares, or third-party drivers) untouched.
- T1561.002recovers — A.7.1's physical perimeters and solid-construction barriers (with alarms, monitoring, and failsafe fire doors) protect the physical hardware containing the disks from the adversary gaining the on-site or local access needed to perform disk-structure wipe, thereby enabling post-incident recovery of the wiped systems via unaffected backups or spares.
- T1669detects — A.7.1 requires alarming, monitoring and testing of physical perimeters (including doors, windows, roofs, walls) to detect unauthorized physical access or interference, which would surface an adversary physically positioning themselves near a target Wi-Fi network for close-access operations; this does not address remote/dual-homed bridging, non-physical discovery of open networks, or post-connection activities.
- T1669prevents — A.7.1's physical perimeters, solid construction, locked doors/windows, and alarms directly stop the adversary's need for physical proximity to discover/connect to Wi-Fi (the dominant close-access vector in the technique description), but leave the dual-homed bridge vector, open networks, and valid-account usage untouched.
Prevented OWASP Web Top 10 (2025) risks (1)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A01mitigates — Physical perimeters bound the blast radius of a realised logical access-control failure (e.g. stolen credentials or bypassed authorization) by keeping the attacker outside the facility, but do nothing to stop the authorization decision itself from failing inside the perimeter.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.