ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 4. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 7.3 Securing offices, rooms and facilities

ISO 27001 Annex A 7.3 Securing offices, rooms and facilities

What is ISO 27001 Annex A 7.3 – Securing Offices, Rooms and Facilities?

ISO 27001 Annex A 7.3 focuses on protecting offices, rooms and facilities where information and associated assets are located.

The objective is to prevent unauthorized access, damage, interference, or other physical security risks affecting people, information, systems, and equipment.

This can apply to:

  • Corporate offices
  • Server rooms
  • Network rooms
  • Data centers
  • HR and finance areas
  • Records/storage rooms
  • Security operations rooms
  • Meeting rooms
  • Research and development areas
  • Equipment rooms
  • Utility areas supporting critical systems

Simple Explanation

A.7.2 controls who can enter. A.7.3 focuses on how the offices, rooms and facilities themselves are secured.

For example, simply restricting access to a server room may not be enough.

The organization should also consider:

  • Where the room is located
  • Whether doors and walls provide appropriate protection
  • Whether visitors can see sensitive information
  • Whether equipment is exposed to environmental risks
  • Whether emergency exits are secure
  • Whether utilities are protected
  • Whether sensitive rooms are appropriately separated

Why is A.7.3 Important?

Physical security is not only about preventing someone from walking into an office.

A poorly designed or inadequately protected facility can expose an organization to:

  • Unauthorized access
  • Theft
  • Equipment damage
  • Information disclosure
  • Tampering
  • Eavesdropping
  • Fire
  • Water damage
  • Power-related incidents
  • Environmental damage
  • Unauthorized photography
  • Physical disruption
  • Loss of critical infrastructure

For example, a network room located in an unrestricted public area may create a significant risk even if the organization has a good cybersecurity program.

Simple Principle

Protect the room according to what is inside it, what happens there, and what could happen if it is compromised.


What Does A.7.3 Require?

Organizations should design and apply appropriate physical security measures for offices, rooms and facilities.

The controls should consider:

  • Information sensitivity
  • Criticality of equipment
  • Physical location
  • Threats to the organization
  • Environmental risks
  • Access requirements
  • Business continuity requirements
  • Legal and contractual requirements

The organization should avoid both extremes:

Too Little Protection

Example:

Sensitive customer records are stored in an unlocked room accessible to visitors.

Too Much Protection

Example:

A small startup installs expensive biometric systems for ordinary meeting rooms that contain no sensitive assets.

The objective is risk-based physical protection.


A.7.2 vs A.7.3

These controls are closely related.

ControlMain Question
A.7.1 Physical Security PerimetersWhere does the protected physical boundary exist?
A.7.2 Physical Entry ControlsWho is allowed to enter?
A.7.3 Securing Offices, Rooms and FacilitiesHow are the offices, rooms and facilities protected?

Example

Consider a network room.

A.7.1:

The network room is identified as a restricted physical area.

A.7.2:

Only authorized IT personnel can enter.

A.7.3:

The room is appropriately located, secured, protected from unauthorized observation, and maintained to reduce relevant physical and environmental risks.


Activities Required to Implement A.7.3

1. Identify Offices, Rooms and Facilities Requiring Protection

Start by identifying areas that require physical security based on risk.

Examples:

  • Main office
  • Network room
  • Server room
  • Data center
  • HR room
  • Finance room
  • Records storage
  • Backup storage
  • Security operations area
  • Equipment room

Not every room needs the same level of protection.


2. Assess the Risks Associated With Each Area

Consider:

Unauthorized Access

Could unauthorized people enter the area?

Information Exposure

Could sensitive information be seen, copied or photographed?

Equipment Damage

Could critical equipment be damaged or disconnected?

Environmental Threats

Could the area be affected by:

  • Fire
  • Water
  • Heat
  • Humidity
  • Dust
  • Power problems

Operational Disruption

Could an incident prevent the organization from operating?

External Threats

Consider the surrounding environment:

  • Public access
  • Adjacent businesses
  • Construction
  • Flooding
  • Crime
  • Industrial activity
  • Shared buildings

3. Define Physical Security Requirements

Different rooms may require different controls.

Example:

AreaRiskPossible Controls
ReceptionVisitor accessReception desk, visitor controls
General OfficeUnauthorized entryDoor access control
HR RoomConfidential informationRestricted access, locked storage
Finance RoomFinancial recordsRestricted access, secure storage
Network RoomCritical infrastructureRestricted access, locked room
Server RoomCritical infrastructureStrong access control, environmental protection
Records RoomSensitive recordsLocked room, controlled access

4. Secure Doors, Walls and Windows

Physical boundaries should be appropriate for the sensitivity of the area.

Consider:

  • Strong doors
  • Locks
  • Access-control mechanisms
  • Secure windows
  • Appropriate walls/partitions
  • Door closers
  • Emergency exits
  • Ceiling/floor vulnerabilities
  • Visibility through windows

For highly sensitive areas, the organization should consider whether someone could bypass the intended physical boundary through:

  • Adjacent rooms
  • Windows
  • False ceilings
  • Service corridors
  • Unsecured doors
  • Shared building spaces

The appropriate level of protection depends on the risk.


5. Protect Sensitive Areas From Public Visibility

Physical security also includes visual exposure.

For example:

A meeting room may have access control, but confidential information displayed on a large screen could still be visible through a glass wall.

Potential controls include:

  • Blinds
  • Privacy film
  • Screen positioning
  • Restricted meeting-room use
  • Clear-screen practices
  • Controlled photography
  • Visitor restrictions

This connects with A.7.7 Clear Desk and Clear Screen.


6. Secure Critical Equipment Areas

Where critical information-processing equipment is located, consider additional controls.

Examples:

  • Network racks
  • Servers
  • Firewalls
  • Switches
  • Storage systems
  • Backup systems
  • UPS systems
  • Telecommunications equipment

Potential controls include:

  • Locked rooms
  • Locked cabinets/racks
  • Restricted access
  • Appropriate environmental controls
  • Cable protection
  • Monitoring
  • Equipment labeling

7. Protect Supporting Facilities

Physical security should also consider facilities that support information processing.

Examples:

  • Electrical rooms
  • UPS rooms
  • Generator areas
  • HVAC systems
  • Network connection points
  • Telecommunications rooms
  • Fire protection systems
  • Water supply
  • Building management systems

A cybersecurity incident does not always begin with a computer.

For example:

A power failure affecting a critical network room can become an information-security availability incident.


8. Consider Fire and Environmental Risks

The organization should consider appropriate protection against environmental threats.

Depending on the facility, this may include:

  • Fire detection
  • Fire suppression
  • Smoke detection
  • Temperature monitoring
  • Humidity monitoring
  • Water-leak detection
  • Flood protection
  • Appropriate ventilation
  • Air conditioning
  • Dust control

The controls should be appropriate to the equipment and risk.

A small office laptop area does not necessarily require the same environmental controls as a dedicated data center.


9. Protect Emergency Exits

Emergency exits must support life safety requirements while also considering security.

Organizations should ensure that:

  • Emergency exits are not unnecessarily blocked
  • Doors operate as required during emergencies
  • Exit arrangements are understood
  • Security controls do not create unsafe evacuation conditions

Physical security should never be implemented in a way that creates an unacceptable safety risk.


10. Secure Sensitive Rooms During Visits and Maintenance

Maintenance personnel, vendors and contractors may need temporary access.

Examples:

  • HVAC maintenance
  • Electrical work
  • Network installation
  • Equipment repair
  • Cleaning
  • Building maintenance

The organization should determine whether:

  • Access needs approval
  • The person needs an escort
  • Work needs supervision
  • Equipment needs protection
  • Access needs to be logged
  • Sensitive information needs to be removed or covered

11. Consider Shared Buildings and Coworking Spaces

Many startups operate from:

  • Coworking spaces
  • Serviced offices
  • Shared commercial buildings
  • Incubators
  • Managed offices

In these environments, some physical controls may be provided by the facility operator.

The organization should understand:

Which controls are provided by the facility and which remain the organization’s responsibility?

For example:

ControlFacility ProviderStartup
Building entrance✓
Security guards✓
Common-area CCTV✓
Employee access cardsShared✓
Visitor managementShared✓
Laptop protection✓
Confidential documents✓
Screen protection✓
Restricted internal roomsShared✓

This should be documented where relevant.


Startup Example

Consider a 35-person SaaS company.

The office contains:

  • Reception
  • Open workspace
  • HR/Finance room
  • Meeting rooms
  • Network room
  • Storage area

The company applies different controls.

General Workspace

Employees use controlled office access.

HR/Finance

Restricted access is applied because confidential employee and financial information is processed there.

Network Room

The room is locked and access is limited to authorized IT personnel.

Meeting Rooms

Employees are instructed not to leave confidential information visible after meetings.

Visitors

Visitors remain in designated areas unless access to another area is approved.

Equipment

Network equipment is kept in a secured room/rack rather than in an open workspace.

Environmental Risks

The company assesses power, heat, fire and water risks for its critical equipment.

This provides a proportionate physical-security model without requiring a large enterprise security infrastructure.


Physical Security Area Register

A simple register can help demonstrate implementation.

AreaPurposeSecurity LevelKey AssetsMain RisksControls
ReceptionVisitor managementPublicVisitor recordsUnauthorized entryReception
General OfficeEmployee workspaceGeneralLaptopsTheftControlled entry
HR RoomHR operationsRestrictedEmployee recordsDisclosureLocked access
Finance RoomFinance operationsRestrictedFinancial recordsDisclosureRestricted access
Network RoomIT infrastructureHighly RestrictedNetwork equipmentTamperingLocked room
Storage RoomAsset storageRestrictedEquipmentTheftLocked access

Physical Room Risk Assessment

A practical assessment can look like this:

AreaThreatImpactExisting ControlAdditional Action
Network RoomUnauthorized entryHighLocked doorAccess review
HR RoomUnauthorized viewingHighRestricted accessPrivacy film
StorageEquipment theftMediumLocked roomAsset register
Meeting RoomInformation exposureMediumControlled accessClear-screen reminders
Server RoomHeat/fireHighHVAC/fire systemPeriodic inspection

The assessment should be proportional to the organization’s size and risk.


What About Cloud-Only Startups?

A cloud-first startup may not operate its own server room.

That does not mean A.7.3 is irrelevant.

The startup may still have:

  • Office space
  • Laptops
  • Network equipment
  • Physical records
  • Employee work areas
  • Meeting rooms
  • Backup devices
  • Home-working environments

For cloud infrastructure, the physical facility may be operated by a cloud provider.

The organization should understand the provider’s responsibilities through appropriate supplier assurance.

For example:

  • Cloud provider certifications
  • SOC reports
  • Contractual commitments
  • Supplier assessments
  • Security documentation

The startup should avoid claiming that it physically controls a cloud data center when it does not.


Audit Evidence for A.7.3

An auditor may request:

Policies

  • Physical Security Policy
  • Physical Facility Security Procedure
  • Office Security Procedure
  • Secure Area Procedure

Registers

  • Physical Security Area Register
  • Restricted Area Register
  • Physical Asset Register
  • Facility Risk Assessment

Operational Evidence

  • Physical security inspections
  • Maintenance records
  • Environmental monitoring
  • Fire-system inspection records
  • Access-control records
  • Visitor records
  • Security incident records

Facility Evidence

Where applicable:

  • Office photographs
  • Floor plans
  • Restricted-area identification
  • Door/access-control arrangements
  • CCTV arrangements
  • Fire protection records
  • HVAC records
  • UPS maintenance records

Third-Party Evidence

For leased/shared facilities:

  • Facility security documentation
  • Building security procedures
  • Supplier assessments
  • Contractual requirements
  • Relevant certifications/reports

Audit Checklist for A.7.3

An auditor may ask:

Facilities

  • Have you identified the offices and facilities requiring protection?
  • Which areas are considered restricted?
  • What information or equipment is located there?

Physical Protection

  • How are sensitive rooms protected?
  • Are doors, windows and other physical boundaries appropriate?
  • Are critical equipment areas separately secured?

Environmental Protection

  • How do you protect critical equipment from fire?
  • How are temperature and environmental risks managed?
  • How do you address water leakage or flooding?

Visitors and Contractors

  • How are visitors controlled?
  • Can contractors enter restricted rooms?
  • Are maintenance activities supervised where necessary?

Shared Facilities

  • Do you use a coworking or serviced office?
  • Which physical controls are provided by the facility?
  • What responsibilities remain with your organization?

Evidence

  • Can you show your physical security area register?
  • Can you show a recent physical security inspection?
  • Can you show evidence of environmental or facility maintenance?

Common Mistakes

1. Treating Physical Security as Only Door Locks

Physical security includes much more than controlling entry.

Organizations should also consider:

  • Walls
  • Windows
  • Equipment
  • Environmental risks
  • Utilities
  • Visibility
  • Visitors
  • Maintenance activities

2. Ignoring Environmental Risks

A secured server room can still be vulnerable to:

  • Fire
  • Heat
  • Water
  • Humidity
  • Power failure

3. Putting Critical Equipment in Open Areas

Network equipment should not be left exposed simply because the office itself is access-controlled.


4. Ignoring Glass Walls and Windows

A person may not need to enter a room to see sensitive information.

Visual exposure can also be a security risk.


5. Giving Contractors Unrestricted Access

A maintenance contractor may need access to a facility, but that does not automatically mean they need unrestricted access to sensitive rooms.


6. Assuming the Building Owner Handles Everything

In a leased or coworking environment, responsibilities should be understood rather than assumed.


7. Overengineering Physical Security

ISO 27001 does not mean every organization needs:

  • Biometrics
  • Security guards
  • Mantraps
  • Military-grade doors
  • Complex surveillance

The controls should correspond to risk.


Practical Startup Implementation Model

A startup can implement A.7.3 using this lifecycle:

Identify → Assess → Classify → Protect → Monitor → Maintain → Review → Improve

Identify

Identify offices, rooms and facilities that require protection.

Assess

Determine physical, environmental and operational risks.

Classify

Assign appropriate security levels.

Protect

Implement appropriate physical and environmental controls.

Monitor

Monitor relevant conditions and security events.

Maintain

Keep doors, locks, equipment, HVAC, fire systems and other relevant controls functional.

Review

Periodically reassess physical security.

Improve

Address weaknesses, incidents and audit findings.


Policy vs. Process vs. Evidence

ElementExample
PolicyPhysical Security Policy
ProcessPhysical Facility Security Process
ProcedureSecure Room Procedure
RegisterPhysical Security Area Register
Risk AssessmentFacility Security Risk Assessment
ControlLocked network room
EvidenceAccess logs, inspection records
ReviewPeriodic physical security inspection

Remember

A control is not the same as evidence of a control.

A locked room is a control.

A documented inspection showing that the room was checked is evidence that the control is being monitored.


Relationship With Other ISO 27001 Controls

A.7.3 connects closely with several other controls:

  • A.5.9 – Inventory of information and other associated assets
  • A.5.11 – Return of assets
  • A.5.15 – Access control
  • A.5.18 – Access rights
  • A.5.19 – Information security in supplier relationships
  • A.5.23 – Information security for use of cloud services
  • A.6.5 – Responsibilities after termination or change of employment
  • A.6.7 – Remote working
  • A.7.1 – Physical security perimeters
  • A.7.2 – Physical entry controls
  • A.7.4 – Physical security monitoring
  • A.7.5 – Protecting against physical and environmental threats
  • A.7.6 – Working in secure areas
  • A.7.7 – Clear desk and clear screen
  • A.7.8 – Equipment siting and protection
  • A.7.9 – Security of assets off-premises

How They Work Together

A.7.1
Defines the physical security boundary.

↓

A.7.2
Controls who enters.

↓

A.7.3
Secures the offices, rooms and facilities.

↓

A.7.4
Monitors physical security where appropriate.

↓

A.7.5
Addresses physical and environmental threats.

This creates a connected physical-security framework rather than isolated controls.


Useful Resources and Draft Documents

Organizations implementing A.7.3 may consider creating:

  1. Physical Security Policy
    [Insert Draft Document Link]
  2. Physical Facility Security Procedure
    [Insert Draft Document Link]
  3. Physical Security Area Register
    [Insert Draft Document Link]
  4. Physical Facility Risk Assessment
    [Insert Draft Document Link]
  5. Restricted Area Register
    [Insert Draft Document Link]
  6. Physical Security Inspection Checklist
    [Insert Draft Document Link]
  7. Server Room Security Checklist
    [Insert Draft Document Link]
  8. Network Room Security Checklist
    [Insert Draft Document Link]
  9. Facility Maintenance Checklist
    [Insert Draft Document Link]
  10. Physical Security Incident Report
    [Insert Draft Document Link]
  11. Environmental Risk Assessment
    [Insert Draft Document Link]
  12. Coworking / Shared Facility Security Assessment
    [Insert Draft Document Link]

Questions an Auditor May Ask Management

“Which areas of your office are considered physically sensitive?”

The organization should be able to identify them and explain why.

“Why is the network room restricted?”

The answer should connect the restriction to the criticality of the equipment and potential security impact.

“How do you protect sensitive information from being viewed by unauthorized people?”

The organization should explain room access, screen positioning, privacy controls and relevant procedures.

“How do you address fire, water and environmental risks?”

The answer should reflect the actual facility and risk assessment.

“What happens when maintenance personnel need access?”

The organization should have a defined process for authorization and supervision where appropriate.

“You work from a coworking facility. Who controls physical security?”

The organization should be able to explain the division of responsibility between itself and the facility provider.


Startup-Focused Quick Summary

A startup does not need to build a complex physical-security infrastructure to address A.7.3.

Start with:

1. Identify

Which rooms and facilities contain sensitive information or critical assets?

2. Assess

What could happen if the area were accessed, damaged or disrupted?

3. Classify

Which areas are public, general, restricted or highly restricted?

4. Protect

Use appropriate locks, access controls, secure storage and environmental safeguards.

5. Control Visitors

Prevent unnecessary access to sensitive areas.

6. Protect Equipment

Secure critical equipment rather than leaving it exposed.

7. Maintain

Make sure physical and environmental controls continue to work.

8. Review

Periodically inspect the facility and address weaknesses.

Simple Startup Principle

Secure the physical environment according to the value and risk of what it protects—not according to how expensive the security technology looks.


Startup-Focused Final Takeaway

A.7.3 is about making sure that offices, rooms and facilities are physically appropriate for the information and assets they contain.

A practical implementation is:

Identify sensitive areas → Assess risks → Classify areas → Apply appropriate protection → Control visitors and maintenance → Protect equipment → Manage environmental risks → Inspect → Improve

The key question is not:

“Does the company have locks?”

The better question is:

“Are our offices, rooms and facilities appropriately protected against the physical risks that could affect our information, people, equipment and business operations?”

For a startup, the best approach is usually simple, risk-based and evidence-driven rather than expensive or overly complicated.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *