The physical theme holds 14 controls, about 15% of the 93 — and it is the theme that most often draws "surely this does not apply to us."
That instinct is half right. For a fully remote organisation with no leased office, or a cloud-only SaaS business with no servers of its own, a substantial share of the 14 is either excluded or reassigned to supplier management. The difficulty is that the standard alone does not make clear how far "substantial" reaches, or what you must then demonstrate at the place you reassigned it to.
This article groups the 14 into five clusters and then works through three patterns: with an office, without an office, and without any facilities of your own. For a healthcare SaaS company, being light on facilities does not stop hospital customers from asking physical questions — so that is covered too.
For the overall map see Annex A 2022: 93 Controls Across Four Themes.
Disclaimer: This article is general information. Control titles and requirement text live in the standard; we describe intent in our own words rather than quoting. Whether an exclusion is acceptable is the certification body's judgement. Base decisions on ISO/IEC 27001 (JIS Q 27001) and the bodies' publications.
Five Clusters Cover the 14
| Cluster | What it is for | Main outputs |
|---|---|---|
| ① Perimeters and entry | Prevent physical intrusion where information and equipment live | Zone plan, entry procedures and logs, visitor records, monitoring records |
| ② Environmental threats and utilities | Protect against fire, water, power loss, cabling failure; maintain equipment | Environmental risk assessment, power and cooling requirements, cable management, maintenance records |
| ③ Behaviour in working areas | Prevent leakage where people are | Rules for working in secure areas, clear desk and clear screen policy |
| ④ Equipment and assets off premises | Protect the devices themselves, including those that leave | Siting standards, removal approval and records, mobile device requirements |
| ⑤ Media and disposal | Close the lifecycle of objects carrying information | Media register, removal and disposal procedures, certificates of destruction |
The essence of this theme is risk while information sits on a physical object — inside a rack, on paper, on a USB stick, on a laptop SSD. If you can trace which objects carry information and where those objects are, most of the 14 fall into place.
Pattern 1: You Have an Office
The straightforward case. Desks, filing cabinets, network equipment — all five clusters apply.
For ① perimeters and entry, first decide where the boundary sits: the building, your floor, or a zone within the floor. If there is a zone holding servers with medical information or printed customer data, define it as a stricter inner zone. Card-key logs satisfy the entry records. For visitors, define reception records, badges, and an explicit rule that nobody enters working areas unaccompanied.
The monitoring control does not necessarily mean CCTV. Cameras, guards, or review of entry logs — alone or combined — satisfy the intent of detecting unauthorised physical access. For a small office, lock management plus a monthly log review can carry it.
③ Clear desk and clear screen is trivial to write and the single most directly observed item during a site audit. An auditor walking the floor who sees an unlocked, unattended laptop has a finding on the spot. Allow time for the practice to actually take hold after the policy is written.
For ⑤ media and disposal, settle how paper and USB devices are handled. A common healthcare pattern is receiving data migrations on USB drives or external disks. If that happens, receipt, storage, return, and erasure must be traceable in a register. Disposal means shredding or pulping for paper and physical destruction or verified erasure for electronic media, with a certificate retained.
Pattern 2: Fully Remote, No Office
Now the real question. With no leased workspace and everyone working from home or coworking spaces, what happens to the 14?
In short: the perimeter cluster is a plausible exclusion; behaviour, equipment, and media remain. What remains is explained through the remote working control on the people side.
| Cluster | Typical treatment when fully remote | How to explain it |
|---|---|---|
| ① Perimeters and entry | Exclusion usually holds | No physical facility under our management — subject to the caveats below |
| ② Environmental threats and utilities | Excluded, or reassigned to supplier management | We own no such facilities; the service platform sits under the cloud provider |
| ③ Behaviour in working areas | Remains (absorbed into remote working rules) | Restated as handling of screens and documents at home or in coworking spaces |
| ④ Equipment and assets off premises | Remains, and matters more | Issued devices are permanently "off premises"; loss and theft dominate |
| ⑤ Media and disposal | Remains, reduced | Partly excluded if no paper; erasure on device return always stays |
Two traps when excluding on "no office"
First, regular use of coworking or shared offices. A corporate contract with fixed desks, or a rented locker holding documents or hardware, is in practice a zone you manage. Full exclusion is hard; the workable response is writing the conditions you require of any facility you use into policy.
Second, the registered head office address. Even a virtual office may receive post and hold original contracts. If so, physical management of that location is fair game. If you have decided that no information assets are stored at the registered address and that is actually true, saying so is enough.
Absorbing what remains into the remote working policy
For a remote organisation, the decisive move is making clusters ③ and ④ concrete in a home-working context. Cover:
- Working environment: screen not visible to third parties, lock on leaving the desk, care around family and housemates
- Issued device requirements: disk encryption, automatic lock timeout, remote wipe capability
- While travelling: whether work on public transport is permitted, conditions in cafés, never leaving devices in vehicles
- Loss or theft: who to tell, how quickly, who executes remote lock or wipe
- Printing and disposal: whether home printing is allowed and, if so, how output is destroyed
- Erasure on return: wiping at departure or device refresh, and the record of it
The remote working control itself sits in the people theme — see Reading the 8 People Controls.
Pattern 3: Cloud-Only, No Facilities at All
If the platform is entirely IaaS/PaaS/SaaS with no data centre or rack of your own, cluster ② and part of cluster ① move into supplier management.
Writing "not applicable" in the SoA is not enough. The correct form shows that the provider manages it and that you verify their management. Three things:
- Selection rationale — that physical security formed part of the assessment when the provider was chosen
- Basis of verification — the provider's published third-party certifications (ISO/IEC 27001, ISO 27017, SOC 2 and so on) and their validity periods
- Ongoing verification — a routine, typically annual, of re-checking certification validity and changes to service terms, with records
The third is what organisations miss. Checked once at certification and never again also fails the supplier-monitoring requirement on the organizational side. Put "confirm certification validity" as a line item in the annual supplier review and both are satisfied at once.
See Reading the 37 Organizational Controls and Supplier Security Management.
Hospital customers ask a different set of questions
This is the healthcare-specific twist. Being light on facilities yourself is separate from being able to answer your customers.
Hospitals assessing suppliers under the three-ministry guidelines routinely ask:
- Where is medical information physically stored — in Japan, and in which region?
- How is physical security of the data centre assured?
- Where are backups held, and how are they physically protected?
- What happens to the data if the provider fails or exits the market?
These need answers regardless of your exclusions. Producing a "customer-facing version" alongside the exclusion rationale avoids doing the work twice. See Cloud Security for Medical Institutions and Shared Responsibility in AI EMR Security Design.
Data residency in particular can become a discussion point under the guidelines; for the basics see The Three-Ministry Guidelines.
How to Write the Exclusions
Badly worded physical exclusions invite follow-up questions. The rule is state the fact and the substitute together.
| Poor | Better |
|---|---|
| Not applicable | Excluded because no physical facility under our management exists within scope. Staff working environments are governed by the Remote Working Policy; protection of issued devices is addressed by the equipment controls |
| Out of scope because we use the cloud | Excluded because platform facilities sit under supplier management. Provider physical security is verified at selection and in the annual review (Supplier Management Procedure, Art. X) |
| Unnecessary as we handle no paper | Excluded because neither paper nor removable media are handled in our operations. Procedures for exceptional cases are set out in the Information Handling Procedure |
What the better versions share is a factual basis for exclusion plus a pointer to where the residual risk is handled. "It is written here" moves the audit along; "it is not written" does not. See Writing the Statement of Applicability.
Conclusion
- The physical theme is fundamentally about risk while information rides on an object
- In a fully remote organisation, what remains is behaviour, equipment, and media; perimeters and utilities tend to be excluded or reassigned
- The traps are habitual coworking use and the registered head office — "no facilities at all" is harder to sustain than it looks
- Absorb what remains into a concrete remote working policy: encryption, loss procedures, erasure on return
- Cloud-only organisations reassign via selection rationale, certification verification, and annual re-verification
- Independently of your exclusions, prepare answers to the physical questions hospitals ask
- "Not applicable" is not an exclusion. State the factual basis and where the risk is instead handled
Pottech supports ISMS certification with a focus on healthcare. Physical controls vary enormously with business structure. We can work through your office, cloud, and media situation and produce both the SoA exclusion rationale and the customer-facing explanation in one pass.
See ISMS Certification Support for scope and pricing, or contact us.
See also What Is an ISMS? A Complete Guide for Healthcare Companies and Reading the 34 Technological Controls.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- ISO/IEC 27002 Information security controls | ISO
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- Telework Security Guidelines | MIC
Note: acceptability of exclusions is the certification body's judgement, and interpretation of controls can change with revisions to the standard.