Recent Breaches
Breaches
2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen
View All →
ISO 27001

Physical Enforcement of Annex A Controls

ISO 27001 requires organisations to implement appropriate controls from Annex A. Control provides physical enforcement for network segmentation, access control, and business continuity controls that demonstrate a higher standard of protection.

Back to Control
Control by Firevault product icon

ISO 27001

ISO 27001 certification demonstrates intent. Physical control enforcement demonstrates reality. The gap between the two is where breaches happen.

14

Annex A controls with physical enforcement

100%

Network segmentation physical evidence

A.8

Technology controls with physical backing

Full

Continuous ISMS evidence generation

The Certification Challenge

Demonstrating control effectiveness is difficult.

Point-in-Time Audits

ISO 27001 surveillance audits capture a snapshot. Between audits, control effectiveness can degrade through configuration drift, human error, or undocumented changes.

Network Control Evidence

Demonstrating continuous network segmentation effectiveness requires evidence that logical controls have been maintained without interruption.

Access Control Gaps

Access reviews happen periodically, but between reviews, excessive access can accumulate as roles change and projects begin and end.

The Scenario

Scenario: Surveillance Audit with Physical Evidence

During an ISO 27001 surveillance audit, the auditor examines network segmentation controls under Annex A.8.22 (Network segmentation). The organisation presents twelve months of continuous physical boundary state logs showing unbroken zone separation. Every conduit activation is documented with multi-party authorisation records, time stamps, and data flow logs. The auditor notes that this level of continuous evidence exceeds what they typically see with software-only implementations, where gaps between configuration audits leave uncertainty about control effectiveness. With Control, the evidence is irrefutable. Physical boundaries were maintained continuously, and every exception was explicitly authorised and logged.

"Our previous auditor accepted our firewall rules as evidence of network segmentation. Our new auditor asked how we knew the rules had been continuously correct between audits. We could not answer that question with software-only controls."

ISO 27001 mapping

Where ISO 27001 Annex A controls meet Control modules.

ISO 27001:2022 reorganised Annex A into 93 controls across four themes. Control provides the physical and operational enforcement for the technological and people-facing controls that hold the boundary.

Reference: ISO/IEC 27001:2022 Annex A, themed under Organisational, People, Physical and Technological controls.

SEC 01

Organisational controls

  • A.5.14

    Information transfer

    Outbound and inter-zone data movement is a governed Transfer event with inventory and evidence.

    FV-Transfer module iconTransferFV-Validate module iconValidate
  • A.5.15

    Access control

    Reach is named, scoped and time-bound, not standing.

    FV-Lock module iconLockFV-Relay module iconRelay
  • A.5.16

    Identity management

    Departures and changes revoke standing trust at the boundary.

    FV-Unlink module iconUnlink
SEC 02

People controls

  • A.6.8

    Information security event reporting

    Reportable events are captured in tamper-evident form and sealed offline.

    FV-Archive module iconArchiveFV-Validate module iconValidate
SEC 03

Technological controls

  • A.8.13

    Information backup

    Backups live in an offline vault that is not reachable on the live network.

    FV-Archive module iconArchiveFV-Transfer module iconTransfer
  • A.8.16

    Monitoring activities

    Continuous attestation of conduit and vault state, signed and stored offline.

    FV-Validate module iconValidate
  • A.8.20

    Network security

    Zone boundaries are physically severed by default.

    FV-Firebreak module iconFirebreakFV-Isolate module iconIsolate
  • A.8.22

    Segregation of networks

    Cross-zone reach is a named Relay session, not a permanent route.

    FV-Isolate module iconIsolateFV-Relay module iconRelay

Modules & symbols

FV-Transfer module iconTransferControlled move
FV-Validate module iconValidateIntegrity check
FV-Lock module iconLockNamed access
FV-Relay module iconRelayTime-bound path
FV-Unlink module iconUnlinkRemove trust
FV-Archive module iconArchiveDisconnected copy
FV-Firebreak module iconFirebreakPhysical sever
FV-Isolate module iconIsolateZone boundary
Direct mapModule satisfies clause

Featured In

TechRadar Pro logoSecurity Buyer logoYahoo Finance logoSecurityBrief logoChannel Insider logo

Key Capabilities

Physical Control Enforcement

Annex A controls are enforced physically, providing a higher standard of protection than software-only implementations.

Access Control Evidence

Every access authorisation, session, and revocation is documented in tamper-proof logs for ISMS records.

Continuous ISMS Evidence

Automated logging generates continuous evidence for Statement of Applicability controls, eliminating gaps between surveillance audits.

Segmentation Assurance

Physical network segmentation provides irrefutable evidence of zone separation for A.8.22 compliance.

Audit-Ready Documentation

Tamper-proof logs and automated reports provide complete audit trails ready for certification and surveillance audits.

Recovery Assurance

Verified control-plane baselines demonstrate ICT readiness for business continuity beyond what network-connected systems can provide.

Demo to Live

Adoption Guide

Step 1

SoA Mapping Assessment

Map your Statement of Applicability against Control module capabilities to identify where physical enforcement strengthens your ISMS.

Step 2

Control Architecture Design

Design physical enforcement for priority Annex A controls, starting with network segmentation and access control.

Step 3

Pre-Audit Validation

Deploy and validate continuous evidence generation before your next surveillance audit to demonstrate physical control effectiveness.

Step 4

ISMS Integration

Full integration with your ISMS including continuous evidence generation, automated reporting, and tamper-evident compliance record preservation.

Step 1

SoA Mapping Assessment

Map your Statement of Applicability against Control module capabilities to identify where physical enforcement strengthens your ISMS.

Step 2

Control Architecture Design

Design physical enforcement for priority Annex A controls, starting with network segmentation and access control.

Step 3

Pre-Audit Validation

Deploy and validate continuous evidence generation before your next surveillance audit to demonstrate physical control effectiveness.

Step 4

ISMS Integration

Full integration with your ISMS including continuous evidence generation, automated reporting, and tamper-evident compliance record preservation.

Questions

Frequently Asked

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy