SGRII Insights  ·  ISO 27001:2022  ·  2026

Twenty-Two Controls That Most Implementations Delegate to HR and Facilities. ISO 27001 Delegates Them to Nobody. They Are Information Security Controls.

Annex A.6 and A.7 are the control themes most frequently treated as administrative checklists owned by departments that do not know they are operating ISMS controls. When HR runs onboarding without security input and Facilities manages physical access without ISMS governance, twenty-two controls exist on paper and nowhere else.

S

SGRII Performance & Digital Solutions

ISMS Practice  ·  April 2026  ·  11 min read

G

SGRII Pillar Lens

Governance

Governance means controls are owned, operated, and evidenced within the ISMS — regardless of which department performs the operational activity. When A.6 controls are ‘owned by HR’ without ISMS governance, and A.7 controls are ‘owned by Facilities’ without security oversight, the ISMS has delegated control accountability to departments that are not managing controls. They are managing processes. The difference is whether information security requirements are defined, monitored, and evidenced.

The Departmental Delegation Problem

Ask who owns A.6.1 (Screening) in most certified organisations. The answer: HR. Ask who defines the screening requirements for security-sensitive roles. The answer, more often than not: also HR — without input from the ISMS on what ‘security-sensitive’ means, which roles qualify, and what screening depth is required for which classification level.

The same pattern repeats across A.6 and A.7. HR runs onboarding (A.6.2), manages disciplinary processes (A.6.4), processes leavers (A.6.5). Facilities manages perimeters (A.7.1), entry controls (A.7.2), equipment maintenance (A.7.13). Each department performs its function. None is operating an ISMS control unless the ISMS has defined the information security requirements, the department implements them with awareness of the security purpose, and evidence of implementation feeds back to the ISMS.

A screening process that checks criminal records but not financial background for a role with privileged access to financial systems is an HR process. It is not an A.6.1 control. The ISMS has not defined what screening means for that role. HR has applied its standard procedure. The standard procedure is not the ISMS requirement.

A.6.7: Remote Working — The Post-Pandemic Control Gap

A.6.7 requires security measures to be implemented when personnel are working remotely to protect information accessed, processed, or stored outside the organisation’s premises. In 2019, this was a control that applied to a minority of the workforce. In 2026, it applies to the majority.

The evidence requirements have evolved accordingly. Pre-pandemic, a remote working policy and VPN access were sufficient. Post-pandemic, auditors expect: endpoint security controls on remote devices (managed vs. BYOD), network security requirements for home environments, physical security of information in non-office locations, and clear desk / clear screen controls for remote workers.

An organisation that shifted to remote working in 2020, documented a remote working policy in 2021, and has not reviewed the control implementation since is operating A.6.7 based on assumptions that may no longer reflect operational reality. Have remote workers been assessed for physical security of their home working environment? Has the organisation verified endpoint security compliance on devices used for remote access? If not, A.6.7 is a policy, not a control.

A.7.4: Physical Security Monitoring — The New 2022 Control

A.7.4 is one of the eleven new controls introduced in the 2022 revision. It requires premises to be continuously monitored for unauthorised physical access. This is not the same as having CCTV cameras. Monitoring requires: detection capability (cameras, sensors, alarms), response capability (who receives alerts, what action is taken), and evidence (monitoring logs, incident records, maintenance records for monitoring equipment).

The control also extends to environmental monitoring — temperature, humidity, water, and fire detection in areas housing critical information processing facilities. An organisation with a server room that has no environmental monitoring has an A.7.4 gap — regardless of whether physical access to the room is controlled.

The audit test: request the monitoring log for a specific period. Ask what anomalies were detected and what action was taken. If monitoring exists but is not reviewed, the control detects nothing — because detection without review is observation without response.

The HR–Security Handshake: Onboarding, Role Changes, Offboarding

A.6.1 (Screening), A.6.2 (Terms and conditions of employment), A.6.5 (Responsibilities after termination or change of employment), and A.5.18 (Access rights) form a lifecycle chain that is critical to information security and almost universally managed as disconnected processes. The chain: screen before granting access → define security obligations at onboarding → adjust access when roles change → revoke access at termination.

The most common failure in this chain is the role change. An employee moves from a business analyst role to a project manager role. Their original system access permissions remain. New permissions are added. The access profile accumulates. No access review is triggered by the role change. Over time, the employee has access to systems they no longer require — a privilege accumulation that A.5.18 is designed to prevent and A.6.5 should address at each role transition.

The second most common failure is offboarding. An employee leaves the organisation. HR processes the leaver. IT receives the notification three days later. In those three days, the former employee’s credentials remain active. The gap between HR processing and IT access revocation is a control timing failure that represents real security risk — and it is testable in audit.

The SGRII Position

The SGRII view is that A.6 and A.7 controls are ISMS controls that happen to be operated by HR and Facilities — not HR and Facilities processes that happen to appear in the ISMS. The distinction determines whether the ISMS defines the security requirements (and verifies compliance) or whether departments define their own processes and the ISMS assumes they are adequate.

The SGRII ISMS Framework includes HR-Security Interface Procedures that define: which roles are security-sensitive (with ISMS-defined criteria), what screening is required per classification level, what security obligations are included in terms of employment, what access changes are triggered by role changes, and what the offboarding security checklist requires. These are not HR procedures. They are ISMS procedures that HR implements.

THE SGRII ISO 27001:2022 ISMS FRAMEWORK

The SGRII ISMS Framework defines A.6 and A.7 controls as ISMS obligations with departmental implementation — not departmental processes with ISMS labelling.

Includes: HR-Security Interface Procedures (screening, onboarding, role change, offboarding), Physical Security Control Procedures (A.7.1–A.7.14), Remote Working Security Requirements, and role-based security obligation matrices.

GET THE ISMS FRAMEWORK — FROM $149 ›

Join the Conversation

Who owns A.6 controls in your organisation — the ISMS Manager or HR? And does the ISMS define the screening and offboarding requirements, or does HR apply its standard process and assume it satisfies the standard?

Practitioner perspectives that challenge or extend this analysis are particularly welcome. Leave your comment below — the SGRII team responds to every substantive contribution.

Build it, don’t just read about it

SGRII ISO/IEC 27001:2022 ISMS Framework

All 93 Annex A controls, Statement of Applicability, risk register and audit pack — built for certification readiness.

View the Framework → Get the newsletter

Coverage is not compliance. SGRII frameworks provide structured coverage, templates and guidance. They are designed for audit defensibility and structured for certification readiness; they do not certify you, do not guarantee a successful audit, and are not legal advice. The official ISO standard remains the only authoritative source of requirements.

Leave a Reply

Discover more from SGRII Performance & Digital Solutions

Subscribe now to keep reading and get access to the full archive.

Continue reading