A.7.5 Physical
Protecting against physical and environmental threats
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (15)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-13mostlyaligns with — Both controls focus on implementing fire detection, suppression, and related safeguards to protect information systems and media from fire damage.
- PE-14mostlyaligns with — Both controls require environmental controls to mitigate risks from temperature, humidity, water, and other physical conditions that could harm systems.
- PE-15mostlyaligns with — Both controls address protection against water damage through detection and mitigation measures to safeguard information processing areas.
- PE-23mostlyaligns with — Both controls require evaluating facility location and surrounding environmental factors to reduce exposure to natural and human-made physical threats.
- PE-9mostlyaligns with — Both controls require protecting power and cabling infrastructure against environmental and physical threats such as surges and other disruptions.
- PE-3partialaligns with — Both controls include physical access controls such as inspections to prevent introduction of explosives or weapons into sensitive facilities.
- RA-3partialaligns with — Both controls require performing risk assessments to identify and evaluate physical and environmental threats before operations begin and at regular intervals.
Aligned NIST CSF 2.0 outcomes (10)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.IR-02fullcovers — The ISO control's risk-based identification and implementation of safeguards against physical and environmental threats directly fulfills the CSF outcome of protecting technology assets from environmental threats.
- ID.RA-03mostlyaligns with — The control's requirement to identify physical and environmental threats such as fire, flood, and civil unrest aligns with the CSF outcome of identifying and recording internal and external threats to the organization.
- ID.RA-04mostlyaligns with — Performing risk assessments to identify potential consequences of physical and environmental threats aligns with the CSF outcome of identifying potential impacts and likelihoods of threats exploiting vulnerabilities.
- DE.CM-02partialaligns with — Installing detection systems for fire, flooding, and electrical surges aligns with the CSF outcome of monitoring the physical environment to find potentially adverse events.
- ID.RA-05partialaligns with — Using risk assessment results to determine appropriate physical and environmental controls aligns with the CSF outcome of using threats, vulnerabilities, likelihoods, and impacts to understand inherent risk and inform risk response prioritization.
Related weaknesses / CWE (13)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1384mostlyprevents — Directly requires protection against physical and environmental threats that the weakness describes.
- CWE-1263partialmitigates — Focuses on environmental threats rather than deliberate unauthorized physical access.
- CWE-1278partialmitigates — Protecting against physical threats indirectly covers hardware tampering and imaging scenarios.
- CWE-1300partialmitigates — Protecting against physical threats can include shielding against emanation attacks.
- CWE-200partialmitigates — By locating facilities away from high-risk urban areas and installing early-warning systems for fire or flood, the control lowers the likelihood that an adversary can physically obtain media or systems that contain sensitive data.
- CWE-1247nonenone — Physical and environmental threat controls can include hardware-level protections against voltage/clock tampering.
- CWE-1319nonenone — Physical and environmental threat protection directly addresses EM-FI risk through shielding and environmental controls.
- CWE-284nonenone — Physical access controls and site-selection measures reduce the chance that an attacker can reach hardware or storage media and directly tamper with or exfiltrate resources that the software trusts to be protected.
- CWE-552nonenone — Risk-based placement and physical barriers make it harder for external parties to reach directories or devices that would otherwise be exposed once an attacker gains proximity to the premises.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.