A.7.3A.7 Physical controls

Securing offices, rooms and facilities

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.7.3 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Design and apply physical security for offices, rooms and facilities to prevent unauthorised access, damage or interference.

How to meet this control

In short: Design and apply physical security for offices and rooms.

  1. Step 01Site critical facilities such as server and comms rooms away from public access, ground-floor windows and external walls
  2. Step 02Keep the premises low-profile, avoiding signage or public listings that advertise the information assets held inside
  3. Step 03Arrange rooms and screens so confidential information cannot be seen or overheard from corridors, windows or shared spaces
  4. Step 04Restrict knowledge of where sensitive facilities sit to those who need it, and avoid publishing internal maps that mark them
  5. Step 05Apply extra restrictions to server and comms rooms, such as separate locks and limited key-holders
  6. Step 06Consider acoustic or electromagnetic shielding where the sensitivity of the work warrants it

Tip: Comms/server rooms get extra restriction.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Locate critical facilities away from public access
  • ›Keep buildings low-profile so they do not advertise the information activities inside
  • ›Set up rooms so confidential information or activity cannot be seen or heard from outside
  • ›Consider electromagnetic shielding where appropriate
  • ›Do not publish directories or maps that reveal where sensitive facilities are located
  • ›Restrict knowledge of facility locations to those who need it

Audit evidence to keep

  • - Floor plans showing placement of sensitive rooms away from public areas
  • - The policy on securing offices, rooms and facilities
  • - Records restricting access to sensitive-room locations and keys
  • - Evidence that signage and directories do not reveal sensitive facilities
  • - Photographs showing screens and rooms positioned against overlooking

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.7.3. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all physical controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.