Skip to main content

Marking Physical Security Controls Out of Scope in SOA

Marking physical security controls out of scope if you are working remote

Written by Upendra Varma

Purpose

Guide the ISMS owner through correctly marking physical security controls Not Applicable in the Statement of Applicability (SoA), and updating this in the ComplyJet platform.

Applies to

Organizations with no company-owned or leased physical premises (fully remote organizations).

Audience

ISMS Manager / Information Security Lead, and anyone preparing or updating the SoA.

Owner

ISMS Manager / Information Security Lead

Approved by

Chief Executive Officer (CEO), or designated Management Representative

Review cycle

Annually, or upon significant change to premises or working arrangements

1. Purpose

This SOP explains when and how to mark ISO/IEC 27001:2022 Annex A Physical controls (Annex A 7) as Not Applicable in the Statement of Applicability (SoA), and how to record that change on the ComplyJet platform.

2. When This Applies

Use this SOP when the organization has no physical office, data centre, warehouse, or other company-owned or leased premises to secure — i.e. staff work fully remotely from locations the organization does not own, lease, or manage. If the organization has any office, co-working membership, or physical facility, do not use this SOP without reassessing which controls genuinely apply.

3. Controls to Mark Out of Scope

Mark the following Physical controls (Annex A 7) as Not Applicable, because there is no organization-owned or leased premises for them to govern:

Ref

Control

Why it is Not Applicable

7.1

Physical security perimeters

No owned/leased premises to define a perimeter for.

7.2

Physical entry

No office entry points to control.

7.3

Securing offices, rooms and facilities

No offices, rooms, or facilities exist.

7.4

Physical security monitoring

No premises to monitor (CCTV, alarms, etc.).

7.6

Working in secure areas

No designated secure areas exist.

7.8

Equipment siting and protection

No company-sited equipment to protect.

7.11

Supporting utilities

No premises with power/cooling/utilities to protect.

7.12

Cabling security

No office cabling to secure.

Do not blanket-exclude the rest of Annex A 7. The following controls typically remain Applicable even with no office, because they govern remote workspaces and company-issued equipment rather than premises:

Ref

Control

Why it usually stays Applicable

7.5

Protecting against physical & environmental threats

May still apply to home/remote workspaces, or be inherited from a cloud/coworking provider.

7.7

Clear desk and clear screen

Applies to remote/home workspaces via the remote working policy, even with no office.

7.9

Security of assets off-premises

Applies whenever staff use laptops/devices remotely.

7.10

Storage media

Applies if any physical or removable media is used or issued to staff.

7.13

Equipment maintenance

Applies if the organization issues and maintains any equipment (laptops, phones).

7.14

Secure disposal or re-use of equipment

Applies whenever company-owned equipment is retired or reassigned.

How to Mark a Control Out of Scope on the ComplyJet Platform

Marking a control out of scope is done by unmapping it from the ISO 27001 requirement it belongs to, not by editing a status field on the requirement itself. Once you know which requirements to exclude (Section above), update each one as follows:

STEP 1 Go to Compliance → Frameworks

In the left-hand navigation, under Prove, open Compliance, then Frameworks.

STEP 2 Select ISO 27001

Click into the ISO 27001 framework card. This opens the framework's Requirements tab by default.

Compliance → Frameworks — select the ISO 27001 card.

STEP 3 Locate the requirement

On the Requirements tab, scroll to (or search for) the specific Annex A requirement — for example 7.1 (Physical security perimeters) — and click Map Controls next to it.

ISO 27001 → Requirements — each requirement (e.g. A.5.1) has its own Map Controls button.

STEP 4 Open Map Controls

Click Map Controls on that requirement. This opens the “Map Controls to Section” panel, listing every internal control currently checked/mapped to it (e.g. GOV-105, IAC-197).

STEP 5 Unselect the mapped controls

Uncheck every control that is currently linked to that requirement, so none remain selected.

Map Controls to Section — uncheck every control mapped to the requirement, then save.

STEP 6 Save with Remap Controls

Click Remap Controls to save. With no controls mapped, the requirement no longer counts toward the framework's Controls Readiness, reflecting that it is out of scope.

STEP 7 Repeat for each requirement

Repeat Steps 3–6 for every requirement listed in the table above.

STEP 8 Record the justification in the SoA

Unmapping controls in Compliance → Frameworks does not itself capture a written reason. Separately update the Statement of Applicability record for that control (Applicable = No, Implementation Status = Not applicable, Justification = reason — see wording below) so the SoA stays consistent with what is mapped on the platform.

STEP 9 Review before audit

Confirm the framework's Controls Readiness and the finished SoA agree, then route the SoA for CEO/ISMS Manager approval.

Justification Wording to Use

“The organization has no physical premises; staff operate remotely from locations not owned, leased, or managed by the organization. Physical security perimeter, entry, and monitoring controls are therefore not applicable to the ISMS scope.”

Adjust the wording to the specific control — e.g. for 7.11 (Supporting utilities): “No organization-owned or leased premises exist requiring management of supporting utilities (power, cooling, etc.).”

Common Pitfalls

  • Marking all 14 Physical controls Not Applicable instead of assessing each one — several (7.5, 7.7, 7.9, 7.10, 7.13, 7.14) usually still apply via the remote working / asset management policy.

  • Leaving the justification generic (“N/A”) instead of explaining why the control does not apply.

  • Forgetting to revisit this SoA section if the organization later opens an office or takes on a co-working membership.

Review, Approval and Maintenance

Changes to the SoA must be reviewed and approved by the document owner (typically the CEO or ISMS Manager) before being relied on as an audit record, and revisited whenever the organization's premises or working arrangements change.

Did this answer your question?