Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.7: Physical Controls

Purpose & Objective

This domain defines the physical and environmental security perimeters used to protect anDREa B.V. (anDREa) assets, facilities, and underlying multi-tenant cloud infrastructure. Structured in absolute alignment with the ISO/IEC 27001:2023 (Control A.7) taxonomy and NIS 2 physical security mandates, these controls mitigate risks stemming from unauthorized physical access, equipment tampering, and environmental disruptions. Because anDREa operates under a remote-first, cloud-agnostic architecture, this framework explicitly enforces security boundaries across two vital layers: the physical enrollment and monitoring of corporate hardware under our Onboarding & Offboarding Process, and the continuous oversight of our third-party datacenter facilities (such as Microsoft Azure) to ensure that sensitive research assets remain physically isolated and protected from external threats.

Scope

The operational scope of these physical safeguards is fully detailed within Clause 4 (Context of the Organisation) of the master ISMS Manual.

  • A.07.07 (Clear desk and clear screen)
  • A.07.09 (Security of Assets Off-Premises)
  • A.07.09 (Storage Media)
  • A.07.13 (Equipment Maintenance)
  • A.07.14 (Secure Disposal or Re-Use of Equipment)

The following controls are formally declared not applicable, with documented justifications in the control:

  • A.07.01, A.07.02, A.07.03, A.07.04, A.07.05, A.07.06, A.07.08, A.07.11, and A.07.12.
  • These controls (covering physical perimeters, physical entry, securing offices/rooms, physical monitoring, environmental threats, working in secure areas, equipment siting, supporting utilities, and cabling security) are declared Not Applicable.
  • anDREa does not maintain physical corporate offices, server rooms, or physical hardware datacenters.
  • All operational infrastructure is managed virtually, and physical protections are delegated entirely to our certified cloud provider's physical security layers.

Availability

This document is classified as Public and is managed under the following access parameters:

  • Required Reading: Mandatory for all anDREa employees and contractors, requiring annual review and technical policy sign-off.
  • General Availability: Accessible to all external interested parties.