A.7.6A.7 Physical controls

Working in secure areas

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.7.6 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Protect information and assets in secure areas from damage and interference by the people working in them.

How to meet this control

In short: Implement measures for working within secure areas.

  1. Step 01Define rules for working inside secure areas, covering supervision, recording devices and what may be brought in or used
  2. Step 02Brief staff on the area and its activities strictly on a need-to-know basis and keep the existence of the work discreet
  3. Step 03Prohibit personal cameras, phones or recording equipment in sensitive rooms unless specifically authorised
  4. Step 04Avoid unsupervised lone working in secure areas and lock and inspect the area when vacant
  5. Step 05Control how user devices are brought into and used within the secure area
  6. Step 06Display emergency and evacuation procedures clearly within the area

Tip: Rules on devices, recording and unaccompanied access in sensitive rooms.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Apply the secure-area security measures to all personnel and all activities in the area
  • ›Tell staff about the area or its activities only on a need-to-know basis
  • ›Avoid unsupervised work in secure areas, for safety and to reduce malicious activity
  • ›Physically lock and periodically inspect vacant secure areas
  • ›Ban photographic, video or audio recording equipment unless specifically authorised
  • ›Control how user endpoint devices are brought into and used within secure areas
  • ›Display emergency procedures somewhere easy to see and reach

Audit evidence to keep

  • - The procedure governing work in secure areas
  • - Records of authorisation for any recording or device use in the area
  • - Inspection logs for vacated secure areas
  • - Acknowledgement by staff of the secure-area rules
  • - Evidence of supervision arrangements for work in the area

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.7.6. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all physical controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.