Working in secure areas
Purpose
Protect information and assets in secure areas from damage and interference by the people working in them.
How to meet this control
In short: Implement measures for working within secure areas.
- Step 01Define rules for working inside secure areas, covering supervision, recording devices and what may be brought in or used
- Step 02Brief staff on the area and its activities strictly on a need-to-know basis and keep the existence of the work discreet
- Step 03Prohibit personal cameras, phones or recording equipment in sensitive rooms unless specifically authorised
- Step 04Avoid unsupervised lone working in secure areas and lock and inspect the area when vacant
- Step 05Control how user devices are brought into and used within the secure area
- Step 06Display emergency and evacuation procedures clearly within the area
Tip: Rules on devices, recording and unaccompanied access in sensitive rooms.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Apply the secure-area security measures to all personnel and all activities in the area
- ›Tell staff about the area or its activities only on a need-to-know basis
- ›Avoid unsupervised work in secure areas, for safety and to reduce malicious activity
- ›Physically lock and periodically inspect vacant secure areas
- ›Ban photographic, video or audio recording equipment unless specifically authorised
- ›Control how user endpoint devices are brought into and used within secure areas
- ›Display emergency procedures somewhere easy to see and reach
Audit evidence to keep
- - The procedure governing work in secure areas
- - Records of authorisation for any recording or device use in the area
- - Inspection logs for vacated secure areas
- - Acknowledgement by staff of the secure-area rules
- - Evidence of supervision arrangements for work in the area
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.7.6. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.