How to Meet ISO 27001 Requirements for Physical Security
Annex A.11 is the most overlooked part of most ISO 27001 implementations. Here's what auditors look for and how AI surveillance helps you pass.
What ISO 27001 requires for physical security
ISO 27001:2022 Annex A includes a dedicated physical and environmental security domain (A.7 in the 2022 edition, previously A.11). The controls cover secure areas, equipment security, and physical access management. For surveillance-related controls, the key requirements are: defined physical security perimeters, monitored access to sensitive areas, visitor logging, and documented evidence of control operation.
The critical word in that last item is "documented." Passing an ISO 27001 audit is not just about having the right security controls in place — it's about demonstrating that they operate consistently and that you can prove it. A CCTV system that records footage to an NVR that nobody monitors satisfies the hardware requirement but fails on operational evidence. An auditor will ask: "Show me the last 30 days of access events and how anomalies were handled."
The five Annex A physical security controls most commonly failed
- A.7.1 Physical security perimeters — must be documented with defined secure zones and monitoring coverage maps
- A.7.2 Physical entry controls — visitor logs must be maintained and access events timestamped
- A.7.4 Physical security monitoring — continuous monitoring of secure areas must be evidenced
- A.7.11 Supporting utilities — power, cooling, and environmental controls must be monitored
- A.7.14 Secure disposal — equipment disposal events must be logged and witnessed
How AI surveillance satisfies these controls
AI-monitored video surveillance directly satisfies A.7.4 (physical security monitoring) and provides evidence for A.7.1 and A.7.2. More importantly, a properly configured AI platform generates the compliance documentation automatically: timestamped alert logs, operator action records, incident reports, and camera uptime statistics are all produced as a byproduct of normal operation.
For ISO 27001 specifically, ImageDeep's Enterprise plan includes a monthly compliance reporting module that generates an Annex A.7 evidence pack: camera coverage maps, alert event logs, operator verification records, and SLA performance data. This is designed to be dropped directly into your ISO 27001 evidence folder ahead of a surveillance audit.
Data protection and GDPR intersection
ISO 27001 physical security controls must be implemented in a way that doesn't breach GDPR obligations around surveillance data. This creates a compliance tension: you need comprehensive monitoring evidence for ISO 27001, but GDPR Article 5 requires data minimisation and storage limitation for personal data captured by CCTV.
The resolution is a retention architecture that retains incident evidence (verified alerts with footage) for the ISO-required period while applying automated deletion to non-incident footage within the GDPR-appropriate window (typically 30 days). ImageDeep's platform handles this automatically: incident footage is tagged and retained to the configured compliance period; non-incident recordings are purged on schedule with audit-trail entries confirming deletion.
Get Your ISO 27001 Compliance Audit
We'll review your current physical security controls against Annex A.7 requirements and identify your gaps.
Request Free Security Audit