SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.7.1Physical security perimeters

Define and protect physical perimeters around areas that hold information and key equipment, using barriers appropriate to the sensitivity inside.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Physical access and visitor controls
How access to the premises and restricted areas is controlled (cards, keys, register), and how visitors are handled.
Facility resilience and media controls
The protections against power or climate failures affecting critical systems, and the control of cabling and facility security zones.
From the Sekit evidence catalog

In practice

In practice this control is the badge system and the locked server room door: a documented list of who may enter which zone, backed by an access log auditors can pull for a specific date. Auditors ask to see the physical access log for the server or comms room and check it against the current employee roster, since a common gap is terminated employees whose badge access was never revoked. They also walk the cabling and patch cabinets to see whether the boundary between public and restricted areas matches the written zone definition.

Common gaps

The badge access log for the server room still lists employees who left the company months ago, with no revocation tied to departure.
Cabling and patch cabinets sit in an area accessible from the public reception, with no physical barrier matching the zone definition on paper.
Visitor access to restricted areas is logged inconsistently, sometimes in a paper register and sometimes not at all.

Questions your auditor will ask

Who can access the server room, and how is that access recorded?
Physical access and visitor controls define the approved list, enforced by badge or key, with entries logged against the current employee roster.
Is badge access revoked when an employee leaves?
The leaver process removes badge access on departure, and the access log for a sample former employee should show no entries after that date.
How are network cabling and comms rooms physically protected from unauthorised access?
Facility resilience and media controls define the security zones for cabling and patch cabinets and record who may access them, checked on a recurring inspection.

Where regulation demands it

NIS2 13.3 requires perimeter and physical access control, the exact protection A.7.1 asks the company to place around information and equipment.
ENS mp.if.1 requires separated areas with access control, matching A.7.1's requirement for defined and protected physical perimeters.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.7.1?”
Also via MCP, free with account