Equipment siting and protection
Purpose
Site and protect equipment to reduce risks from physical and environmental threats and unauthorised access.
How to meet this control
In short: Site and protect equipment to reduce risk.
- Step 01Position equipment to limit unnecessary foot traffic and place screens handling sensitive data so they cannot be overlooked
- Step 02Apply controls against theft, fire, smoke, water, dust and vibration appropriate to where the equipment sits
- Step 03Set and enforce rules on eating, drinking and smoking near information-processing equipment
- Step 04Monitor temperature and humidity in equipment rooms and fit surge protection on incoming power and communications lines
- Step 05Physically separate equipment the organisation manages from equipment managed by others, such as in shared or landlord spaces
- Step 06Consider shielding for equipment handling confidential information where emanation leakage is a concern
Tip: Keep equipment away from public/uncontrolled areas and environmental risk.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Position equipment to limit unnecessary entry into work areas
- ›Place screens handling sensitive data so unauthorised people cannot view them
- ›Apply controls against theft, fire, smoke, water, dust, vibration, chemicals and power interference
- ›Set rules for eating, drinking and smoking near information processing facilities
- ›Monitor environmental conditions such as temperature and humidity
- ›Apply lightning protection and surge filters on incoming power and communications lines
- ›Shield equipment handling confidential information against electromagnetic emanation leakage
- ›Physically separate facilities the organisation manages from those it does not
Audit evidence to keep
- - Records or photographs of equipment siting and screen positioning
- - Environmental monitoring readings for equipment rooms
- - The equipment siting and protection standard
- - Surge-protection installation records
- - Evidence of separation between organisation-managed and third-party equipment
Common mistakes
- - Relying on office trust without logs
- - Not tracking assets used away from the office
- - Disposing equipment without wipe or destruction evidence
Owner, cadence, and proof
Assign one accountable owner for A.7.8. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.