A.7.4New in 2022A.7 Physical controls

Physical security monitoring

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.7.4 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Continuously watch premises to detect and deter unauthorised physical access.

How to meet this control

In short: Continuously monitor premises for unauthorised physical access.

  1. Step 01Install CCTV covering external doors, loading areas and entries to sensitive rooms, with footage retained for a defined period that respects privacy law
  2. Step 02Fit intruder alarms with contact, motion and glass-break sensors, keeping unoccupied areas armed out of hours
  3. Step 03Place the alarm control panel inside a protected, tamper-monitored zone and connect to a monitoring service or guard response
  4. Step 04Test detection and alarm systems periodically and keep the test records
  5. Step 05Protect the monitoring system itself so feeds and recordings cannot be viewed or disabled by unauthorised people, and keep its design confidential
  6. Step 06Post privacy signage and align camera placement with the Privacy Act and surveillance-device laws of the relevant state

Tip: CCTV and/or alarm with retained footage/logs.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Use surveillance such as guards, CCTV, intruder alarms or security software, in-house or outsourced
  • ›Install video monitoring to view and record access to sensitive areas
  • ›Fit and periodically test contact, motion and glass-break detectors that trigger alarms
  • ›Cover all external doors and accessible windows, keeping unoccupied areas alarmed
  • ›Keep the monitoring system's design confidential to avoid helping break-ins
  • ›Protect monitoring systems so feeds cannot be accessed or disabled by unauthorised parties
  • ›Place the alarm control panel in an alarmed, tamperproof zone and test the system regularly
  • ›Account for local privacy and data protection laws when monitoring people

Audit evidence to keep

  • - CCTV coverage map and a sample of retained footage or retention configuration
  • - Alarm system configuration and zone list
  • - Alarm and detector test records
  • - The monitoring or guard-response service agreement
  • - Evidence of privacy signage and compliance with surveillance laws

Common mistakes

  • - Relying on office trust without logs
  • - Not tracking assets used away from the office
  • - Disposing equipment without wipe or destruction evidence

Owner, cadence, and proof

Assign one accountable owner for A.7.4. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all physical controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.