ISO 27001 Annex A 7.5 Audit Checklist

The ultimate audit guide to ISO 27001 Annex A 7.5 Protecting against physical and environmental threats

1. Working Area Security Policy Formalisation Verified

Verification Criteria: A documented policy exists that defines the security requirements for different types of working areas, including open-plan offices and restricted zones.

Required Evidence: Approved Physical Security Policy or Working Area Standard Operating Procedure (SOP).

Pass/Fail Test: If the organisation cannot produce a formal document defining the security rules for general vs. restricted working areas, mark as Non-Compliant.

2. Restricted Zone Designation and Delineation Confirmed

Verification Criteria: High-risk working areas (e.g. HR, Finance, or R&D) are clearly designated and physically separated from general-access areas.

Required Evidence: Physical site map showing “Restricted Zones” and visual confirmation of physical barriers (walls/locked doors).

Pass/Fail Test: If sensitive departments like HR or Finance are located in open-access areas without a secondary physical perimeter, mark as Non-Compliant.

3. “Clean Desk” Operational Adherence Validated

Verification Criteria: Working areas are free from sensitive paper documents and removable storage media when unattended.

Required Evidence: Physical inspection reports from “out-of-hours” security sweeps or photographic evidence of compliance.

Pass/Fail Test: If a physical walkthrough reveals sensitive PII or passwords on sticky notes in an unattended workspace, mark as Non-Compliant.

4. Working Area Visitor Escorting Verified

Verification Criteria: All visitors within secure working areas are escorted at all times to prevent unauthorised access to information on screens or desks.

Required Evidence: Visitor Management Procedure and observational verification of visitor tags/hosts during the audit.

Pass/Fail Test: If a visitor is found unescorted within a restricted working zone (e.g. the development floor), mark as Non-Compliant.

5. Working Area Surveillance Monitoring Confirmed

Verification Criteria: Restricted working areas are monitored via CCTV or alarm sensors to detect and record unauthorised entry during non-business hours.

Required Evidence: CCTV coverage map and NVR (Network Video Recorder) logs for sensors in restricted zones.

Pass/Fail Test: If a designated high-risk working area lacks either 24/7 CCTV coverage or an active intruder alarm, mark as Non-Compliant.

6. Privacy Screen Implementation for Sensitive Areas Verified

Verification Criteria: Monitors in areas accessible to visitors or non-cleared staff are fitted with privacy filters or positioned to prevent “shoulder surfing.”

Required Evidence: Visual confirmation of privacy screens on HR/Finance workstations or physical partitioning.

Pass/Fail Test: If an HR workstation monitor is visible from a public corridor or reception area, mark as Non-Compliant.

7. Secure Document Storage Availability Confirmed

Verification Criteria: Locking cabinets or pedestals are provided and utilised in working areas to secure sensitive information during breaks or at the end of the day.

Required Evidence: Physical sighting of lockable storage and verification of key management (i.e., keys are not left in the locks).

Pass/Fail Test: If the organisation mandates a clean desk policy but fails to provide lockable storage for sensitive files at the desk, mark as Non-Compliant.

8. Unattended Device Locking Enforcement Validated

Verification Criteria: Workstations in working areas are configured to automatically lock after a defined period of inactivity (typically 5-15 minutes).

Required Evidence: GPO (Group Policy Object) configuration settings or MDM (Mobile Device Management) profiles for idle-lock timeouts.

Pass/Fail Test: If an auditor can access an unattended workstation in a secure working area that has been idle for >15 minutes without a password prompt, mark as Non-Compliant.

9. Shared Working Space (Hot-Desking) Security Confirmed

Verification Criteria: In hot-desking environments, procedures ensure that no sensitive data is left behind on desks or shared peripherals (printers/scanners).

Required Evidence: Hot-desking policy and inspection of shared storage/print trays for “orphaned” documents.

Pass/Fail Test: If uncollected sensitive printouts are found in a shared printer tray in a communal working area, mark as Non-Compliant.

10. Periodic Physical Security Inspections Verified

Verification Criteria: Regular, documented checks are performed to ensure working area security standards (Clean Desk/Clear Screen) are being maintained.

Required Evidence: Completed inspection checklists or “After-Hours Security Audit” logs from the current audit cycle.

Pass/Fail Test: If there is no evidence of a physical security check being conducted on the working areas within the last six months, mark as Non-Compliant.

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top