A.7.5 Physical
Protecting against physical and environmental threats
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (26)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-13mostlyaligns with — Both controls focus on implementing fire detection, suppression, and related safeguards to protect information systems and media from fire damage.
- PE-14mostlyaligns with — Both controls require environmental controls to mitigate risks from temperature, humidity, water, and other physical conditions that could harm systems.
- PE-15mostlyaligns with — Both controls address protection against water damage through detection and mitigation measures to safeguard information processing areas.
- PE-23mostlyaligns with — Both controls require evaluating facility location and surrounding environmental factors to reduce exposure to natural and human-made physical threats.
- PE-3mostlycovers — A.7.5's broad mandate to prevent/reduce physical and environmental threat consequences accounts for the bulk of PE-3's physical access enforcement, verification, ingress/egress control, and logging requirements; a residual of scoped facility-area controls sits outside the source.
- PE-9mostlyaligns with — Both controls require protecting power and cabling infrastructure against environmental and physical threats such as surges and other disruptions.
- PE-13partialcovers — A.7.5's broad requirement to protect against physical/environmental threats (including fire) accounts for a slice of PE-13's specific fire-detection-and-suppression mandate, but the bulk of the target's prescriptive implementation, maintenance, and independent-power details sit outside the source.
- PE-14partialcovers — A.7.5's broad objective to prevent/reduce physical/environmental threats accounts for only a slice of PE-14's specific requirements to maintain and monitor defined temperature/humidity levels; the bulk of the target's parametric implementation detail sits outside the source.
- PE-15partialcovers — A.7.5's broad mandate to prevent/reduce physical-and-environmental consequences accounts for a slice of PE-15's specific water-leakage valve requirement, but the bulk of the target's concrete mechanism (master shutoff valves, accessibility, verification, key-personnel knowledge) sits in other controls such as PE-3 or PE-13.
- PE-23partialcovers — A.7.5's requirement to prevent/reduce physical and environmental threat consequences accounts for the bulk of PE-23's planning and risk-strategy consideration of those same hazards; a residual slice of pure site-selection geography remains uncovered by the ISO control's focus on protective measures.
- PE-3partialaligns with — Both controls include physical access controls such as inspections to prevent introduction of explosives or weapons into sensitive facilities.
- PE-9partialcovers — A.7.5's broad mandate to protect against physical/environmental threats addresses a slice of PE-9 (power-specific damage protection) but leaves the bulk of the target's explicit power-equipment-and-cabling requirements uncovered.
- RA-3partialaligns with — Both controls require performing risk assessments to identify and evaluate physical and environmental threats before operations begin and at regular intervals.
Aligned NIST CSF 2.0 outcomes (18)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.IR-02fullcovers — The ISO control's risk-based identification and implementation of safeguards against physical and environmental threats directly fulfills the CSF outcome of protecting technology assets from environmental threats.
- ID.RA-03mostlyaligns with — The control's requirement to identify physical and environmental threats such as fire, flood, and civil unrest aligns with the CSF outcome of identifying and recording internal and external threats to the organization.
- ID.RA-04mostlyaligns with — Performing risk assessments to identify potential consequences of physical and environmental threats aligns with the CSF outcome of identifying potential impacts and likelihoods of threats exploiting vulnerabilities.
- DE.CM-02partialaligns with — Installing detection systems for fire, flooding, and electrical surges aligns with the CSF outcome of monitoring the physical environment to find potentially adverse events.
- ID.RA-05partialaligns with — Using risk assessment results to determine appropriate physical and environmental controls aligns with the CSF outcome of using threats, vulnerabilities, likelihoods, and impacts to understand inherent risk and inform risk response prioritization.
- DE.CM-02implements — A.7.5's physical/environmental protection directly operationalizes monitoring the physical environment for adverse events as a core means within its domain (though not the only means, and not explicitly named by the control text)
- ID.RA-03implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.RA-04implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.RA-05implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related weaknesses / CWE (9)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1263mitigates — Focuses on environmental threats rather than deliberate unauthorized physical access.
- CWE-1278mitigates — Protecting against physical threats indirectly covers hardware tampering and imaging scenarios.
- CWE-1300mitigates — Protecting against physical threats can include shielding against emanation attacks.
- CWE-1384prevents — Directly requires protection against physical and environmental threats that the weakness describes.
- CWE-200mitigates — By locating facilities away from high-risk urban areas and installing early-warning systems for fire or flood, the control lowers the likelihood that an adversary can physically obtain media or systems that contain sensitive data.
Mitigated MITRE ATT&CK techniques (47)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1052detects — A.7.5 explicitly calls for early-stage detection systems (fire, flooding) and random inspections for weapons/explosives at entry points to sensitive facilities, which can surface an introduced removable medium in some physical-threat scenarios but does not broadly instrument or observe the exfiltration act itself across Linux/macOS/Windows platforms.
- T1052prevents — A.7.5's risk-driven physical safeguards (site selection, fire/flood/electrical protections, random inspections for weapons/explosives) can stop an insider or visitor from introducing or removing a removable medium in sensitive facilities, but this is only a minority slice of T1052 which is mainly about any user-introduced device in air-gapped or disconnected scenarios, not comprehensively blocked by physical-threat controls.
- T1200detects — A.7.5 explicitly calls for early detection systems (fire/flood sensors, random inspections for explosives/weapons on personnel/vehicles/goods entering facilities) that surface physical introduction attempts; this covers only a narrow slice of T1200 vectors such as obvious hardware carried by people, not passive taps, DMA devices, or wireless implants once inside.
- T1200prevents — A.7.5 requires risk-driven physical safeguards (site selection, inspections, environmental sensors) that can stop unauthorized hardware additions at the facility perimeter or during entry; this covers only a minority slice of the technique because it is silent on post-entry abuse of added devices already inside the authorized perimeter and on non-facility vectors such as supply-chain or remote-site insertions.
- T1485detects — A.7.5 explicitly calls for early-stage detection systems (fire, flooding) plus ongoing threat monitoring and risk reassessment that can surface physical/environmental precursors to destructive events, but has no view of logical, malware-driven, or cloud API-based data destruction on endpoints or infrastructure.
- T1485recovers — A.7.5 explicitly calls for safeguards that reduce consequences of physical/environmental events (fire, flood, electrical surges) that can destroy data, and for recovery-capable design of premises and systems; this partially overlaps the post-destruction availability restoration goal of T1485 but does not address logical overwriting, deletion, or propagation by malware.
- T1486recovers — A.7.5 explicitly requires safeguards (fire suppression, flood detection/pumps, surge protection) that enable recovery of information assets after physical/environmental events that could otherwise render data permanently lost, aligning with the recovery verb against T1486's impact of data inaccessibility.
- T1486responds — A.7.5's purpose is to prevent/reduce consequences of physical/environmental events and its guidance explicitly requires implementing safeguards (fire detection/suppression, flood detection/pumps, surge protection) plus monitoring for changes in threats; this directly matches the EVENT-LANE definition of `responds` (technique ran; contained and eradicated once underway) for a realized ransomware encryption event by bounding damage and enabling eradication via early detection and suppression before full propagation/impact.
- T1490recovers — A.7.5 requires risk-driven physical/environmental safeguards (fire/flood/electrical detection, suppression, pumps, surge protection) that enable recovery of systems and data after such events, directly addressing the post-impact restoration goal of `recovers` even though the technique's primary digital deletion vectors sit outside its physical focus.
- T1499recovers — A.7.5's purpose explicitly includes reducing consequences of physical/environmental events (with examples like fire suppression, flood detection/pumps, surge protection) that can cause endpoint resource exhaustion or crashes, thereby restoring availability after the event.
- T1561recovers — A.7.5 explicitly requires safeguards (fire suppression, flood detection/pumps, surge protection) that enable recovery of information assets after physical/environmental events that could cause or enable disk wipe, with the named remainder being non-physical logical wipes (e.g. malware using admin shares or CLI erase).
- T1561.001detects — A.7.5 explicitly requires early-stage detection systems for physical/environmental threats (fire, flooding, electrical surges) that can trigger alarms or suppression before damage occurs, which surfaces the realization of a disk-wipe technique when it manifests through those vectors, but the control is silent on detecting logical/software-based disk-content overwrite (the dominant form described in the T1561.001 prose).
- T1561.001prevents — A.7.5 requires risk-driven physical safeguards (fire/flood/electrical detection and suppression, site selection, random inspections) that can stop some physical-access vectors an adversary would need to directly overwrite disk content, but leaves the dominant software-propagated malware path (worm-like spread via credentials and shares) untouched.
- T1561.001recovers — A.7.5 explicitly requires safeguards (fire suppression, flood detection/pumps, surge protection) that enable recovery of information processing systems and storage media after physical/environmental events that could otherwise cause permanent data loss, and disk-content wipe is one such destructive physical-access event; however, it does not address logical/worm-like propagation or post-wipe restoration of erased data itself.
- T1561.002recovers — A.7.5 requires risk-driven physical safeguards (fire/flood/electrical surge detection and suppression, site selection) that enable recovery of information-processing assets after certain physical destruction events; this partially overlaps the post-wipe recovery of boot structures on surviving hardware but does not address logical disk-structure wipes performed by malware over the network.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.