Purpose | Guide the ISMS owner through correctly marking physical security controls Not Applicable in the Statement of Applicability (SoA), and updating this in the ComplyJet platform. |
Applies to | Organizations with no company-owned or leased physical premises (fully remote organizations). |
Audience | ISMS Manager / Information Security Lead, and anyone preparing or updating the SoA. |
Owner | ISMS Manager / Information Security Lead |
Approved by | Chief Executive Officer (CEO), or designated Management Representative |
Review cycle | Annually, or upon significant change to premises or working arrangements |
1. Purpose
This SOP explains when and how to mark ISO/IEC 27001:2022 Annex A Physical controls (Annex A 7) as Not Applicable in the Statement of Applicability (SoA), and how to record that change on the ComplyJet platform.
2. When This Applies
Use this SOP when the organization has no physical office, data centre, warehouse, or other company-owned or leased premises to secure — i.e. staff work fully remotely from locations the organization does not own, lease, or manage. If the organization has any office, co-working membership, or physical facility, do not use this SOP without reassessing which controls genuinely apply.
3. Controls to Mark Out of Scope
Mark the following Physical controls (Annex A 7) as Not Applicable, because there is no organization-owned or leased premises for them to govern:
Ref | Control | Why it is Not Applicable |
7.1 | Physical security perimeters | No owned/leased premises to define a perimeter for. |
7.2 | Physical entry | No office entry points to control. |
7.3 | Securing offices, rooms and facilities | No offices, rooms, or facilities exist. |
7.4 | Physical security monitoring | No premises to monitor (CCTV, alarms, etc.). |
7.6 | Working in secure areas | No designated secure areas exist. |
7.8 | Equipment siting and protection | No company-sited equipment to protect. |
7.11 | Supporting utilities | No premises with power/cooling/utilities to protect. |
7.12 | Cabling security | No office cabling to secure. |
Do not blanket-exclude the rest of Annex A 7. The following controls typically remain Applicable even with no office, because they govern remote workspaces and company-issued equipment rather than premises:
Ref | Control | Why it usually stays Applicable |
7.5 | Protecting against physical & environmental threats | May still apply to home/remote workspaces, or be inherited from a cloud/coworking provider. |
7.7 | Clear desk and clear screen | Applies to remote/home workspaces via the remote working policy, even with no office. |
7.9 | Security of assets off-premises | Applies whenever staff use laptops/devices remotely. |
7.10 | Storage media | Applies if any physical or removable media is used or issued to staff. |
7.13 | Equipment maintenance | Applies if the organization issues and maintains any equipment (laptops, phones). |
7.14 | Secure disposal or re-use of equipment | Applies whenever company-owned equipment is retired or reassigned. |
How to Mark a Control Out of Scope on the ComplyJet Platform
Marking a control out of scope is done by unmapping it from the ISO 27001 requirement it belongs to, not by editing a status field on the requirement itself. Once you know which requirements to exclude (Section above), update each one as follows:
STEP 1 Go to Compliance → Frameworks
In the left-hand navigation, under Prove, open Compliance, then Frameworks.
STEP 2 Select ISO 27001
Click into the ISO 27001 framework card. This opens the framework's Requirements tab by default.
Compliance → Frameworks — select the ISO 27001 card.
STEP 3 Locate the requirement
On the Requirements tab, scroll to (or search for) the specific Annex A requirement — for example 7.1 (Physical security perimeters) — and click Map Controls next to it.
ISO 27001 → Requirements — each requirement (e.g. A.5.1) has its own Map Controls button.
STEP 4 Open Map Controls
Click Map Controls on that requirement. This opens the “Map Controls to Section” panel, listing every internal control currently checked/mapped to it (e.g. GOV-105, IAC-197).
STEP 5 Unselect the mapped controls
Uncheck every control that is currently linked to that requirement, so none remain selected.
Map Controls to Section — uncheck every control mapped to the requirement, then save.
STEP 6 Save with Remap Controls
Click Remap Controls to save. With no controls mapped, the requirement no longer counts toward the framework's Controls Readiness, reflecting that it is out of scope.
STEP 7 Repeat for each requirement
Repeat Steps 3–6 for every requirement listed in the table above.
STEP 8 Record the justification in the SoA
Unmapping controls in Compliance → Frameworks does not itself capture a written reason. Separately update the Statement of Applicability record for that control (Applicable = No, Implementation Status = Not applicable, Justification = reason — see wording below) so the SoA stays consistent with what is mapped on the platform.
STEP 9 Review before audit
Confirm the framework's Controls Readiness and the finished SoA agree, then route the SoA for CEO/ISMS Manager approval.
Justification Wording to Use
“The organization has no physical premises; staff operate remotely from locations not owned, leased, or managed by the organization. Physical security perimeter, entry, and monitoring controls are therefore not applicable to the ISMS scope.” |
Adjust the wording to the specific control — e.g. for 7.11 (Supporting utilities): “No organization-owned or leased premises exist requiring management of supporting utilities (power, cooling, etc.).”
Common Pitfalls
Marking all 14 Physical controls Not Applicable instead of assessing each one — several (7.5, 7.7, 7.9, 7.10, 7.13, 7.14) usually still apply via the remote working / asset management policy.
Leaving the justification generic (“N/A”) instead of explaining why the control does not apply.
Forgetting to revisit this SoA section if the organization later opens an office or takes on a co-working membership.
Review, Approval and Maintenance
Changes to the SoA must be reviewed and approved by the document owner (typically the CEO or ISMS Manager) before being relied on as an audit record, and revisited whenever the organization's premises or working arrangements change.
