A.7.1 Physical
Physical security perimeters
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (7)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-3mostlycovers — Both controls require physical barriers and entry controls around areas housing information assets, with the ISO guidance on perimeter strength and locking directly supporting the NIST requirement to enforce physical access authorization at defined boundaries.
- PE-2partialaligns with — Defining and siting security perimeters according to asset sensitivity aligns with the need to authorize and document who may physically access specific system components or areas.
- PE-4partialaligns with — Protecting external doors, windows, and ventilation points on the perimeter helps control physical access to transmission media and cabling that may traverse or terminate at the boundary.
- PE-6partialaligns with — The requirement to alarm and monitor fire doors and perimeter openings supports ongoing surveillance of physical access points to detect unauthorized entry attempts.
Aligned NIST CSF 2.0 outcomes (8)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.IR-02fullcovers — The ISO control's focus on constructing and maintaining physically sound perimeters directly implements the CSF outcome of protecting technology assets from environmental threats.
- PR.AA-06mostlycovers — By specifying perimeter strength, access controls on doors/windows, and monitoring of fire doors, the ISO control satisfies the CSF requirement to manage, monitor, and enforce physical access commensurate with risk.
- ID.AM-05partialaligns with — The control's requirement to site and strengthen perimeters according to the security needs of the assets inside aligns with prioritizing assets based on classification, criticality, and mission impact.
- PR.IR-01partialaligns with — Establishing physical perimeters and locking mechanisms contributes to preventing unauthorized logical access by first securing the physical boundary around networks and environments.
Related weaknesses / CWE (12)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1263mostlyprevents — Defines physical perimeters that directly limit unauthorized physical access to restricted areas.
- CWE-1191partialmitigates — Physical perimeters can limit access to debug ports but do not address on-chip access-control logic.
- CWE-1278partialmitigates — Physical perimeters deter unauthorized access to IC imaging equipment but do not address chip-level protections.
- CWE-1300partialmitigates — Physical perimeters can limit attacker proximity needed for side-channel capture.
- CWE-1384partialmitigates — Physical perimeters reduce exposure to external environmental threats.
- CWE-200partialprevents — By physically restricting who can approach information-processing equipment, the control reduces the chance that an unauthorized actor can observe or extract sensitive information stored or processed on those systems.
- CWE-284partialmitigates — Physical perimeters with locked doors, solid construction, and alarms directly block unauthorized physical entry that would otherwise allow an attacker to bypass logical access controls and reach protected resources.
- CWE-552partialmitigates — Solid perimeters and locked external access points stop files, devices, or directories containing sensitive data from being reachable by external parties who could otherwise walk in or break in.
- CWE-732nonenone — Requiring locked doors and controlled entry points prevents the default or accidental exposure of critical hardware and storage media that would result from leaving physical resources accessible to anyone on site.
Mitigated MITRE ATT&CK techniques (4)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1200mostlyprevents — Physical perimeters with locked doors, solid construction, and alarms directly impede an adversary's ability to introduce unauthorized hardware into the facility.
- T1052partialmitigates — Controlled physical entry points and monitoring make it harder for an attacker to physically remove storage media containing exfiltrated data.
- T1052.001partialmitigates — Locked and monitored perimeters limit opportunities to carry USB devices out of the facility without detection.
- T1091partialprevents — Strong physical barriers and access controls reduce the likelihood that malware can be introduced or spread via removable media brought into the premises.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.