Back to Columns
ISMS & Certification12 min read

Reading the 14 Physical Controls

September 14, 2026

Reading the 14 Physical Controls
Share this article

The physical theme holds 14 controls, about 15% of the 93 — and it is the theme that most often draws "surely this does not apply to us."

That instinct is half right. For a fully remote organisation with no leased office, or a cloud-only SaaS business with no servers of its own, a substantial share of the 14 is either excluded or reassigned to supplier management. The difficulty is that the standard alone does not make clear how far "substantial" reaches, or what you must then demonstrate at the place you reassigned it to.

This article groups the 14 into five clusters and then works through three patterns: with an office, without an office, and without any facilities of your own. For a healthcare SaaS company, being light on facilities does not stop hospital customers from asking physical questions — so that is covered too.

For the overall map see Annex A 2022: 93 Controls Across Four Themes.

Disclaimer: This article is general information. Control titles and requirement text live in the standard; we describe intent in our own words rather than quoting. Whether an exclusion is acceptable is the certification body's judgement. Base decisions on ISO/IEC 27001 (JIS Q 27001) and the bodies' publications.

Five Clusters Cover the 14

ClusterWhat it is forMain outputs
① Perimeters and entryPrevent physical intrusion where information and equipment liveZone plan, entry procedures and logs, visitor records, monitoring records
② Environmental threats and utilitiesProtect against fire, water, power loss, cabling failure; maintain equipmentEnvironmental risk assessment, power and cooling requirements, cable management, maintenance records
③ Behaviour in working areasPrevent leakage where people areRules for working in secure areas, clear desk and clear screen policy
④ Equipment and assets off premisesProtect the devices themselves, including those that leaveSiting standards, removal approval and records, mobile device requirements
⑤ Media and disposalClose the lifecycle of objects carrying informationMedia register, removal and disposal procedures, certificates of destruction

The essence of this theme is risk while information sits on a physical object — inside a rack, on paper, on a USB stick, on a laptop SSD. If you can trace which objects carry information and where those objects are, most of the 14 fall into place.

Pattern 1: You Have an Office

The straightforward case. Desks, filing cabinets, network equipment — all five clusters apply.

For ① perimeters and entry, first decide where the boundary sits: the building, your floor, or a zone within the floor. If there is a zone holding servers with medical information or printed customer data, define it as a stricter inner zone. Card-key logs satisfy the entry records. For visitors, define reception records, badges, and an explicit rule that nobody enters working areas unaccompanied.

The monitoring control does not necessarily mean CCTV. Cameras, guards, or review of entry logs — alone or combined — satisfy the intent of detecting unauthorised physical access. For a small office, lock management plus a monthly log review can carry it.

③ Clear desk and clear screen is trivial to write and the single most directly observed item during a site audit. An auditor walking the floor who sees an unlocked, unattended laptop has a finding on the spot. Allow time for the practice to actually take hold after the policy is written.

For ⑤ media and disposal, settle how paper and USB devices are handled. A common healthcare pattern is receiving data migrations on USB drives or external disks. If that happens, receipt, storage, return, and erasure must be traceable in a register. Disposal means shredding or pulping for paper and physical destruction or verified erasure for electronic media, with a certificate retained.

Pattern 2: Fully Remote, No Office

Now the real question. With no leased workspace and everyone working from home or coworking spaces, what happens to the 14?

In short: the perimeter cluster is a plausible exclusion; behaviour, equipment, and media remain. What remains is explained through the remote working control on the people side.

ClusterTypical treatment when fully remoteHow to explain it
① Perimeters and entryExclusion usually holdsNo physical facility under our management — subject to the caveats below
② Environmental threats and utilitiesExcluded, or reassigned to supplier managementWe own no such facilities; the service platform sits under the cloud provider
③ Behaviour in working areasRemains (absorbed into remote working rules)Restated as handling of screens and documents at home or in coworking spaces
④ Equipment and assets off premisesRemains, and matters moreIssued devices are permanently "off premises"; loss and theft dominate
⑤ Media and disposalRemains, reducedPartly excluded if no paper; erasure on device return always stays

Two traps when excluding on "no office"

First, regular use of coworking or shared offices. A corporate contract with fixed desks, or a rented locker holding documents or hardware, is in practice a zone you manage. Full exclusion is hard; the workable response is writing the conditions you require of any facility you use into policy.

Second, the registered head office address. Even a virtual office may receive post and hold original contracts. If so, physical management of that location is fair game. If you have decided that no information assets are stored at the registered address and that is actually true, saying so is enough.

Absorbing what remains into the remote working policy

For a remote organisation, the decisive move is making clusters ③ and ④ concrete in a home-working context. Cover:

  • Working environment: screen not visible to third parties, lock on leaving the desk, care around family and housemates
  • Issued device requirements: disk encryption, automatic lock timeout, remote wipe capability
  • While travelling: whether work on public transport is permitted, conditions in cafés, never leaving devices in vehicles
  • Loss or theft: who to tell, how quickly, who executes remote lock or wipe
  • Printing and disposal: whether home printing is allowed and, if so, how output is destroyed
  • Erasure on return: wiping at departure or device refresh, and the record of it

The remote working control itself sits in the people theme — see Reading the 8 People Controls.

Pattern 3: Cloud-Only, No Facilities at All

If the platform is entirely IaaS/PaaS/SaaS with no data centre or rack of your own, cluster ② and part of cluster ① move into supplier management.

Writing "not applicable" in the SoA is not enough. The correct form shows that the provider manages it and that you verify their management. Three things:

  1. Selection rationale — that physical security formed part of the assessment when the provider was chosen
  2. Basis of verification — the provider's published third-party certifications (ISO/IEC 27001, ISO 27017, SOC 2 and so on) and their validity periods
  3. Ongoing verification — a routine, typically annual, of re-checking certification validity and changes to service terms, with records

The third is what organisations miss. Checked once at certification and never again also fails the supplier-monitoring requirement on the organizational side. Put "confirm certification validity" as a line item in the annual supplier review and both are satisfied at once.

See Reading the 37 Organizational Controls and Supplier Security Management.

Hospital customers ask a different set of questions

This is the healthcare-specific twist. Being light on facilities yourself is separate from being able to answer your customers.

Hospitals assessing suppliers under the three-ministry guidelines routinely ask:

  • Where is medical information physically stored — in Japan, and in which region?
  • How is physical security of the data centre assured?
  • Where are backups held, and how are they physically protected?
  • What happens to the data if the provider fails or exits the market?

These need answers regardless of your exclusions. Producing a "customer-facing version" alongside the exclusion rationale avoids doing the work twice. See Cloud Security for Medical Institutions and Shared Responsibility in AI EMR Security Design.

Data residency in particular can become a discussion point under the guidelines; for the basics see The Three-Ministry Guidelines.

How to Write the Exclusions

Badly worded physical exclusions invite follow-up questions. The rule is state the fact and the substitute together.

PoorBetter
Not applicableExcluded because no physical facility under our management exists within scope. Staff working environments are governed by the Remote Working Policy; protection of issued devices is addressed by the equipment controls
Out of scope because we use the cloudExcluded because platform facilities sit under supplier management. Provider physical security is verified at selection and in the annual review (Supplier Management Procedure, Art. X)
Unnecessary as we handle no paperExcluded because neither paper nor removable media are handled in our operations. Procedures for exceptional cases are set out in the Information Handling Procedure

What the better versions share is a factual basis for exclusion plus a pointer to where the residual risk is handled. "It is written here" moves the audit along; "it is not written" does not. See Writing the Statement of Applicability.

Conclusion

  1. The physical theme is fundamentally about risk while information rides on an object
  2. In a fully remote organisation, what remains is behaviour, equipment, and media; perimeters and utilities tend to be excluded or reassigned
  3. The traps are habitual coworking use and the registered head office — "no facilities at all" is harder to sustain than it looks
  4. Absorb what remains into a concrete remote working policy: encryption, loss procedures, erasure on return
  5. Cloud-only organisations reassign via selection rationale, certification verification, and annual re-verification
  6. Independently of your exclusions, prepare answers to the physical questions hospitals ask
  7. "Not applicable" is not an exclusion. State the factual basis and where the risk is instead handled

Pottech supports ISMS certification with a focus on healthcare. Physical controls vary enormously with business structure. We can work through your office, cloud, and media situation and produce both the SoA exclusion rationale and the customer-facing explanation in one pass.

See ISMS Certification Support for scope and pricing, or contact us.

See also What Is an ISMS? A Complete Guide for Healthcare Companies and Reading the 34 Technological Controls.

References and Sources

Note: acceptability of exclusions is the certification body's judgement, and interpretation of controls can change with revisions to the standard.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 34 Technological Controls

The 34 technological controls of Annex A.8 in six clusters: access control and authentication, vulnerabilities and configuration, the data protection lifecycle, logging and monitoring, networks, and secure development — written in the context of building and operating healthcare SaaS.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.