A.7.12A.7 Physical controls

Cabling security

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.7.12 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Protect power, data and supporting service cabling from interception, interference or damage.

How to meet this control

In short: Protect power and telecom cabling from interception/damage.

  1. Step 01Route power and telecom cabling underground or through protected conduit, separating power cables from data cables to limit interference
  2. Step 02Secure patch panels, cable rooms and inspection points behind controlled access
  3. Step 03Label both ends of cables to support identification and inspection and to reduce the risk of accidental disconnection
  4. Step 04For sensitive systems, use armoured conduit, locked termination points and consider fibre to resist interception
  5. Step 05Run periodic technical sweeps to detect unauthorised taps or devices attached to cabling
  6. Step 06Take specialist advice on cabling risk for high-sensitivity environments

Tip: Route and label cabling; secure patch panels.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Route power and telecom lines underground where possible, or otherwise protect them
  • ›Separate power cables from communications cables to prevent interference
  • ›For sensitive systems, use armoured conduit and lock cable inspection and termination points
  • ›Apply electromagnetic shielding to cables for sensitive systems
  • ›Run periodic technical sweeps and inspections to detect unauthorised devices attached to cables
  • ›Control access to patch panels and cable rooms, and consider fibre-optic cabling
  • ›Label both ends of cables to allow easy identification and inspection
  • ›Seek specialist advice on managing risks from cabling incidents

Audit evidence to keep

  • - Cabling diagrams showing routing and power-versus-data separation
  • - Records of access controls on patch panels and cable rooms
  • - Cable labelling standard or photographs of labelled cabling
  • - Technical sweep or inspection records
  • - The cabling security standard or specification

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.7.12. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all physical controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.