What is ISO 27001 Annex A 7.4 – Physical Security Monitoring?
ISO 27001 Annex A 7.4 focuses on monitoring physical premises and areas where information and other associated assets are located.
The objective is to detect and respond to:
- Unauthorized physical entry
- Suspicious physical activity
- Security breaches
- Attempts to bypass physical controls
- Physical security incidents
- Other events that could threaten information and associated assets
Physical security monitoring can include:
- CCTV
- Security guards
- Door access logs
- Alarm systems
- Intrusion detection
- Security patrols
- Visitor monitoring
- Environmental monitoring where relevant
- Monitoring of restricted areas
Simple Explanation
A.7.2 controls who can enter. A.7.4 helps the organization detect what is happening physically and identify potential security events.
A locked door provides a preventive control.
Monitoring provides a way to detect whether something suspicious or unauthorized is happening.
Why is A.7.4 Important?
Physical security controls can fail.
Examples:
- Someone follows an employee through a secure door.
- An access card is stolen.
- A restricted door is forced open.
- An unauthorized person enters behind a visitor.
- Someone tampers with network equipment.
- A camera detects suspicious activity.
- A physical security alarm is triggered.
Without appropriate monitoring, an organization may not know that a physical security control has been bypassed.
Physical security monitoring can help with:
- Early detection
- Investigation
- Incident response
- Evidence collection
- Deterrence
- Access-control verification
- Protection of critical assets
Simple Principle
If a physical area is important enough to protect, consider how you will know when that protection is being bypassed or a security event is occurring.
What Does A.7.4 Require?
Organizations should use appropriate monitoring mechanisms for their physical security environment.
The level of monitoring should be based on:
- Risk
- Sensitivity of information
- Criticality of equipment
- Location
- Threat environment
- Regulatory requirements
- Contractual requirements
- Business needs
This does not mean that every organization must install CCTV throughout its premises.
For some organizations, appropriate monitoring may include:
- Door access logs
- Reception controls
- Security guards
- Visitor registers
- Periodic inspections
- Building security systems
- Alarm notifications
For a high-security facility, more extensive monitoring may be appropriate.
A.7.2 vs A.7.3 vs A.7.4
These controls work together.
| Control | Main Question |
|---|---|
| A.7.1 Physical Security Perimeters | Where is the protected boundary? |
| A.7.2 Physical Entry Controls | Who is allowed to enter? |
| A.7.3 Securing Offices, Rooms and Facilities | How is the physical environment protected? |
| A.7.4 Physical Security Monitoring | How do we detect and monitor physical security events? |
Example: Network Room
A.7.1
The network room is classified as a restricted physical area.
A.7.2
Only authorized IT personnel can enter.
A.7.3
The room is physically secured and appropriate environmental protections are applied.
A.7.4
Entry activity and relevant physical security events are monitored and investigated when necessary.
Activities Required to Implement A.7.4
1. Identify Areas Requiring Monitoring
Start with the organization’s physical security risk assessment.
Potential areas include:
- Office entrances
- Reception
- Restricted rooms
- Network rooms
- Server rooms
- Data centers
- Equipment storage
- Records rooms
- Loading areas
- Critical infrastructure areas
Not every location requires the same monitoring level.
2. Determine What Needs to Be Monitored
Monitoring should have a defined purpose.
Examples:
Unauthorized Entry
Monitor access to restricted areas.
Suspicious Activity
Identify unusual activity around sensitive areas.
Access-Control Events
Monitor:
- Failed access attempts
- Forced doors
- Unusual access
- After-hours access
Physical Security Equipment
Monitor relevant:
- Alarms
- Cameras
- Access-control systems
- Intrusion detection systems
3. Select Appropriate Monitoring Controls
Possible controls include:
| Monitoring Method | Example Use |
|---|---|
| CCTV | Office entrances/restricted areas |
| Access logs | Restricted rooms |
| Security guard | Building entrance |
| Visitor register | Visitor tracking |
| Door alarms | Critical areas |
| Intrusion detection | High-risk facilities |
| Security patrols | Large facilities |
| Periodic inspection | Small offices |
| Environmental monitoring | Server/equipment rooms |
The appropriate combination depends on risk.
4. Monitor Access-Control Events
Where electronic physical access systems exist, organizations may review relevant events such as:
- Successful access
- Failed access
- Access outside normal hours
- Repeated failed attempts
- Access-card use after employment termination
- Unusual access patterns
For example:
A former employee’s card is used to attempt entry.
This should trigger appropriate investigation.
5. Monitor Restricted Areas
Highly sensitive areas may require additional monitoring.
Examples:
- Server room
- Network room
- Data center
- Security operations center
- Backup media storage
- Sensitive records room
Possible controls include:
- CCTV
- Door access logging
- Alarm systems
- Security patrols
- Access alerts
Again, monitoring should be proportionate to risk.
6. Monitor Visitors
Visitor monitoring can help establish:
- Who entered
- Who they were visiting
- When they entered
- When they left
- Whether they entered restricted areas
A visitor should not normally be able to move through sensitive areas without appropriate authorization.
7. Establish Alert and Escalation Procedures
Monitoring is useful only if someone knows what to do when something suspicious occurs.
Example:
Physical security alert → Initial review → Assess event → Escalate if required → Investigate → Respond → Record → Learn
Examples of escalation triggers:
- Forced door
- Unauthorized entry
- Lost access card used
- Suspicious activity
- Physical tampering
- Theft
- Damage to equipment
This connects A.7.4 with the organization’s incident-management process.
8. Protect Monitoring Records
Monitoring information can itself be sensitive.
Examples:
- CCTV recordings
- Access logs
- Visitor records
- Security guard logs
- Alarm records
The organization should consider:
- Who can access records
- How records are protected
- Retention requirements
- Privacy requirements
- Secure deletion
- Investigation requirements
Access should be limited to authorized personnel.
9. Define Retention Requirements
The organization should determine how long monitoring records need to be retained.
The appropriate period may depend on:
- Legal requirements
- Privacy requirements
- Contractual requirements
- Investigation needs
- Business requirements
- Storage limitations
The organization should avoid retaining personal surveillance data indefinitely without a defined purpose.
10. Test and Review Monitoring Controls
Monitoring systems can fail.
Examples:
- Camera stops recording
- Door sensor fails
- Access logs stop updating
- Alarm is disabled
- Storage becomes full
- Camera angle changes
- Monitoring personnel stop reviewing alerts
Therefore, organizations should periodically verify that important monitoring mechanisms are functioning.
CCTV and ISO 27001
CCTV is one possible physical-security monitoring control.
It is not automatically mandatory for every ISO 27001-certified organization.
Whether CCTV is appropriate depends on factors such as:
- Physical risk
- Premises type
- Asset sensitivity
- Location
- Threat environment
- Customer requirements
- Legal/privacy requirements
For example:
Small 10-Person Office
Potentially sufficient:
- Building security
- Controlled office entrance
- Visitor process
- Access cards
- Periodic inspection
Data Center
Potentially appropriate:
- CCTV
- Access logs
- Security personnel
- Intrusion detection
- Alarm monitoring
- Restricted access
The controls should be justified through risk assessment.
Startup Example
Consider a 50-person SaaS startup operating from an office.
The organization has:
- Main entrance
- Reception
- Employee workspace
- HR/Finance room
- Network room
- Storage room
The startup implements:
Main Entrance
Building security and access control monitor entry.
Reception
Visitors are registered and linked to an employee host.
Network Room
Access is restricted and physical entry is logged.
Office
Appropriate security monitoring is provided through building controls and access management.
Security Events
A forced-door alert or suspicious physical activity is reported to the responsible security/facilities contact.
Investigation
If a physical security incident occurs, relevant access logs and available CCTV footage can be reviewed.
This provides a practical monitoring model without creating an unnecessarily complex surveillance environment.
Physical Security Monitoring Matrix
| Area | Asset/Risk | Monitoring Method | Frequency | Responsible Person |
|---|---|---|---|---|
| Main Entrance | Unauthorized entry | Access system/building security | Continuous | Facilities |
| Reception | Visitor risk | Visitor register | Per visit | Reception |
| HR Room | Confidential records | Access logs | As applicable | HR/Facilities |
| Network Room | Equipment tampering | Access logs/CCTV where appropriate | Continuous/periodic review | IT |
| Storage Room | Equipment theft | Restricted access/inspection | Periodic | Facilities |
| Data Center | Critical infrastructure | CCTV/access/alarm | Continuous | Data Center Provider |
Physical Security Monitoring Register
A simple register can document the monitoring controls.
| Area | Monitoring Control | Purpose | Owner | Record Generated | Review |
|---|---|---|---|---|---|
| Network Room | Access logs | Detect unauthorized entry | IT | Access log | Monthly |
| Main Entrance | CCTV | Detect suspicious activity | Facilities | Video | As required |
| Reception | Visitor Register | Track visitors | Reception | Visitor record | Per visit |
| Storage Room | Periodic inspection | Detect unauthorized access | Facilities | Inspection record | Monthly |
Physical Security Event Workflow
A useful workflow is:
Detection
↓
Initial Assessment
↓
Security Event?
↓
Yes → Investigate / Escalate
↓
Incident?
↓
Activate Incident Response
↓
Collect Evidence
↓
Resolve
↓
Lessons Learned
This connects A.7.4 with:
- A.5.24 Incident Management Planning and Preparation
- A.5.25 Assessment and Decision on Information Security Events
- A.5.26 Response to Information Security Incidents
- A.5.27 Learning from Information Security Incidents
- A.5.28 Collection of Evidence
Audit Evidence for A.7.4
An auditor may request:
Policies and Procedures
- Physical Security Policy
- Physical Security Monitoring Procedure
- CCTV Policy, where applicable
- Visitor Management Procedure
- Physical Security Incident Procedure
Monitoring Records
- Door access logs
- CCTV records, where appropriate
- Visitor registers
- Security guard logs
- Alarm records
- Physical inspection records
System Evidence
- Access-control reports
- Camera system configuration
- Alarm configuration
- Monitoring dashboards
- Alert records
Operational Evidence
- Physical security alerts
- Investigation records
- Physical security incidents
- Corrective actions
- Periodic monitoring reviews
- Monitoring-system testing
Third-Party Evidence
Where monitoring is provided by a building or facility provider:
- Facility security documentation
- Service agreements
- Security procedures
- Relevant certifications or assurance reports
- Supplier assessments
Audit Checklist for A.7.4
An auditor may ask:
Monitoring Scope
- Which physical areas are monitored?
- Why were those areas selected?
- Is the monitoring based on a risk assessment?
Monitoring Methods
- Do you use CCTV?
- Do you use access logs?
- Are alarms used?
- How are visitors monitored?
Alerts
- What happens when a physical security alert occurs?
- Who reviews alerts?
- How are unauthorized entry attempts handled?
Records
- What monitoring records are maintained?
- Who can access them?
- How long are they retained?
- How are records protected?
System Reliability
- How do you know your monitoring controls are working?
- Are cameras or access-control systems periodically tested?
- What happens when a monitoring system fails?
Incidents
- Can you provide an example of a physical security event?
- How was it investigated?
- Was evidence preserved?
Common Mistakes
1. Assuming CCTV Is Mandatory
ISO 27001 does not mean every organization must install CCTV.
The organization should select controls based on risk.
2. Installing Cameras but Never Reviewing Them
A camera that records continuously may have limited value if nobody can access or review footage when a security event occurs.
3. No Alert or Escalation Process
Monitoring without a response process creates a gap.
The organization should define:
What is monitored → What is an alert → Who receives it → What happens next
4. Ignoring Access Logs
Physical access systems can generate useful evidence.
Organizations should determine whether relevant access events need monitoring or periodic review.
5. Keeping Monitoring Data Forever
CCTV and access records may contain personal information.
Retention should have a defined purpose and comply with applicable requirements.
6. Giving Too Many People Access to CCTV
Surveillance records can be sensitive.
Access should be restricted to authorized personnel.
7. Forgetting Monitoring-System Failures
A broken camera or disabled alarm can create a security gap.
Monitoring controls themselves should be maintained and tested where appropriate.
8. No Evidence of Actual Operation
Having a CCTV policy is not enough.
An auditor may want evidence that:
- Monitoring is implemented
- Relevant logs exist
- Alerts are handled
- Systems are maintained
- Security events are investigated
Privacy Considerations for CCTV and Monitoring
Physical monitoring may involve personal information.
For example:
- CCTV footage
- Visitor records
- Access-card records
- Security logs
Organizations should consider applicable privacy and data-protection requirements when implementing monitoring.
Depending on the jurisdiction and circumstances, this may involve:
- Clearly defined purpose
- Appropriate notice
- Limited access
- Appropriate retention
- Protection against unauthorized disclosure
- Secure deletion
- Handling of data-subject rights where applicable
The objective should be:
Monitor what is necessary for security without collecting or retaining unnecessary personal information.
Practical Startup Implementation Model
A startup can implement A.7.4 using this lifecycle:
Identify → Assess → Select → Monitor → Alert → Investigate → Record → Review → Improve
Identify
Identify physical areas and assets requiring monitoring.
Assess
Evaluate the physical security risks.
Select
Choose appropriate monitoring mechanisms.
Monitor
Operate the controls.
Alert
Identify suspicious or unauthorized activity.
Investigate
Assess and investigate relevant events.
Record
Maintain appropriate evidence.
Review
Periodically review monitoring effectiveness.
Improve
Address weaknesses and lessons learned.
Policy vs. Process vs. Evidence
| Element | Example |
|---|---|
| Policy | Physical Security Monitoring Policy |
| Process | Physical Security Event Monitoring Process |
| Procedure | CCTV Review Procedure |
| Control | Access logging |
| System | CCTV/access-control system |
| Record | Door access log |
| Event | Failed access attempt |
| Evidence | Investigation record |
| Review | Periodic monitoring review |
Important Distinction
Monitoring is not the same as recording.
A system may generate a log or video recording, but the organization should determine how relevant security events are detected, assessed and handled.
Relationship With Other ISO 27001 Controls
A.7.4 connects with:
- A.5.7 – Threat intelligence
- A.5.15 – Access control
- A.5.16 – Identity management
- A.5.18 – Access rights
- A.5.24 – Information security incident management planning and preparation
- A.5.25 – Assessment and decision on information security events
- A.5.26 – Response to information security incidents
- A.5.27 – Learning from information security incidents
- A.5.28 – Collection of evidence
- A.6.8 – Information security event reporting
- A.7.1 – Physical security perimeters
- A.7.2 – Physical entry controls
- A.7.3 – Securing offices, rooms and facilities
- A.7.5 – Protecting against physical and environmental threats
- A.7.6 – Working in secure areas
- A.7.7 – Clear desk and clear screen
- A.7.9 – Security of assets off-premises
Simple Relationship
A.7.2
Controls physical entry.
↓
A.7.3
Protects the physical environment.
↓
A.7.4
Monitors relevant physical security activity.
↓
A.5.25
Assesses security events.
↓
A.5.26
Responds to confirmed incidents.
Useful Resources and Draft Documents
Organizations implementing A.7.4 may consider creating:
- Physical Security Monitoring Policy
[Insert Draft Document Link] - Physical Security Monitoring Procedure
[Insert Draft Document Link] - CCTV Policy
[Insert Draft Document Link] - CCTV Monitoring and Review Procedure
[Insert Draft Document Link] - Physical Security Monitoring Register
[Insert Draft Document Link] - Physical Security Event Report
[Insert Draft Document Link] - Physical Security Incident Report
[Insert Draft Document Link] - Physical Access Log Review Checklist
[Insert Draft Document Link] - Physical Security Inspection Checklist
[Insert Draft Document Link] - CCTV Access Authorization Register
[Insert Draft Document Link] - Physical Monitoring System Testing Checklist
[Insert Draft Document Link] - Physical Security Monitoring Risk Assessment
[Insert Draft Document Link]
Questions an Auditor May Ask Management
“What physical areas do you monitor and why?”
The answer should be linked to the organization’s physical security risk assessment.
“Do you use CCTV?”
If yes, explain its purpose and controls. If no, explain the alternative monitoring mechanisms and risk-based rationale.
“How do you detect unauthorized physical entry?”
The organization should explain access controls, logs, reception, guards, alarms or other relevant mechanisms.
“What happens when a physical security alert occurs?”
There should be a defined assessment and escalation process.
“Who can access CCTV or physical security records?”
Access should be restricted to authorized personnel.
“How long do you retain physical monitoring records?”
The organization should have a defined retention approach appropriate to legal, privacy, contractual and operational requirements.
“How do you know your monitoring system is working?”
The organization should be able to demonstrate testing, maintenance or monitoring of the relevant controls.
Startup-Focused Quick Summary
For most startups, A.7.4 can be implemented without building a sophisticated security operations center.
Start with:
1. Identify
Determine which physical areas require monitoring.
2. Assess
Understand the risks and potential consequences.
3. Select
Choose appropriate controls such as:
- Access logs
- Visitor records
- CCTV where justified
- Building security
- Alarms
- Periodic inspections
4. Monitor
Operate the controls consistently.
5. Respond
Define what happens when suspicious activity is detected.
6. Protect Records
Restrict access to CCTV, logs and other monitoring information.
7. Review
Check whether monitoring remains effective.
8. Improve
Address incidents, failures and audit findings.
Simple Startup Principle
Don’t install monitoring technology just to show an auditor. Implement monitoring that helps you actually detect and respond to physical security risks.
Startup-Focused Final Takeaway
A.7.4 is about ensuring that physical security controls are not simply installed and forgotten.
The practical lifecycle is:
Identify risks → Select monitoring → Operate monitoring → Detect events → Assess → Respond → Preserve evidence → Review → Improve
For a startup, the key question is not:
“Do we have CCTV?”
It is:
“Can we detect relevant physical security events, determine what happened, and take appropriate action?”
A well-designed A.7.4 implementation should therefore connect physical monitoring, access control, incident management, evidence and privacy into one practical process.
