What is ISO 27001 Annex A 7.6 – Working in Secure Areas?
ISO 27001 Annex A 7.6 requires organizations to define and apply security measures for people working in secure areas.
A secure area is a physical location where additional security controls are needed because sensitive information, critical systems, important equipment, or high-risk activities are present.
Examples include:
- Server and network rooms
- Data centers
- Security operation centers (SOC)
- Records and archive rooms
- Research and development areas
- Finance or HR restricted areas
- Areas where sensitive customer information is processed
- Rooms containing critical network infrastructure
- Restricted project rooms
- Secure document or media storage areas
The objective is not simply to prevent unauthorized entry. It is also to ensure that authorized people behave securely while working inside the secure area.
Simple Explanation
A.7.2 controls who can enter a secure area. A.7.6 controls how people should work once they are inside.
Why is ISO 27001 Annex A 7.6 Important?
A person may be authorized to enter a secure area but could still create a security risk through inappropriate behavior.
For example, an employee may be authorized to enter a server room but:
- Take photographs of equipment
- Bring an unauthorized device inside
- Connect a personal laptop to the network
- Leave a secure door open
- Allow another person to follow them inside
- Leave confidential documents unattended
- Discuss sensitive information where unauthorized people can hear it
- Remove equipment or records without authorization
- Use removable media without approval
- Allow visitors to move around without supervision
Therefore, physical access authorization alone is not sufficient.
Organizations should define appropriate rules for working in sensitive physical areas.
Simple Principle
Entering a secure area should be controlled, but working inside the area should also be controlled.
What Does ISO 27001 A.7.6 Require?
The organization should establish and apply appropriate procedures and controls for working in secure areas.
The controls should be proportionate to the risks associated with the area.
This means a small SaaS company does not necessarily need military-style security controls.
For example:
| Area | Typical Risk | Possible Controls |
|---|---|---|
| General office | Low | Basic physical security |
| HR/Finance room | Medium | Restricted access, clean desk |
| Network room | High | Restricted access, visitor supervision |
| Data center | Very high | Strong access control, monitoring, authorized personnel only |
| Secure records room | High | Restricted access, document handling rules |
The exact controls should be determined through the organization’s physical security risk assessment.
What is a Secure Area?
A secure area is not necessarily a room with a sign saying “Secure Area.”
An organization should identify areas where additional physical security is required based on factors such as:
- Information sensitivity
- Criticality of equipment
- Business impact
- Confidentiality requirements
- Regulatory requirements
- Customer requirements
- Threat environment
- Number of people requiring access
- Physical location
- Environmental risks
- Possibility of unauthorized observation or access
For example:
A company’s general office may not be considered a secure area.
However, the small network room containing:
- Firewall
- Network switches
- Backup equipment
- Network cables
- Security appliances
may require additional controls.
A.7.6 vs A.7.2 – What is the Difference?
These two controls are closely related.
| Control | Main Question |
|---|---|
| A.7.1 Physical Security Perimeters | Where is the protected boundary? |
| A.7.2 Physical Entry Controls | Who is allowed to enter? |
| A.7.3 Securing Offices, Rooms and Facilities | How is the facility physically protected? |
| A.7.4 Physical Security Monitoring | How do we detect physical security activity? |
| A.7.5 Physical and Environmental Threats | How do we protect against environmental and physical threats? |
| A.7.6 Working in Secure Areas | How should people behave and work inside secure areas? |
Example
An employee may have authorization to enter the server room.
A.7.2 answers:
“Is this employee authorized to enter?”
A.7.6 answers:
“What security rules must the employee follow while working inside?”
Activities Required to Implement A.7.6
1. Identify Secure Areas
Start by identifying areas that require additional protection.
Create a list of relevant locations.
For example:
| Location | Secure Area? | Reason |
|---|---|---|
| Reception | No | Public/general area |
| Open office | No | General working area |
| HR room | Yes | Employee confidential information |
| Finance room | Yes | Financial information |
| Network room | Yes | Critical infrastructure |
| Records room | Yes | Confidential records |
| Meeting room | Depends | Sensitive discussions may occur |
Do not automatically classify every room as secure.
2. Assess the Risks
For each secure area, identify relevant risks.
Consider:
- Unauthorized observation
- Unauthorized access
- Theft
- Photography
- Recording
- Equipment tampering
- Unauthorized devices
- Removable media
- Information disclosure
- Tailgating
- Visitors
- Contractors
- Maintenance personnel
- Fire and environmental risks
- Accidental damage
- Loss of confidentiality
Example
Network Room
Risk:
Unauthorized person connects a device to the internal network.
Possible control:
Only authorized IT personnel may enter. Visitors must be escorted. Personal devices are not permitted unless specifically authorized.
3. Define Working Rules
The organization should establish clear rules for working inside secure areas.
Depending on the risk, rules may include:
- Only authorized personnel may work inside
- Visitors must be accompanied
- Doors must remain closed
- Do not allow tailgating
- No unauthorized photography
- No unauthorized recording
- No unauthorized removable media
- No unauthorized equipment
- Do not leave sensitive information unattended
- Do not remove equipment without authorization
- Follow clean desk requirements where applicable
- Follow clear screen requirements
- Report suspicious activity
- Report physical security incidents
- Follow emergency procedures
The rules should be practical rather than unnecessarily restrictive.
4. Control Visitors
Visitors, contractors, vendors and maintenance personnel may need temporary access.
The organization should define:
- Who can authorize visitors
- How visitors are identified
- Whether visitor registration is required
- Whether visitors need badges
- Whether visitors must be escorted
- Which areas visitors can access
- Whether photography is permitted
- Whether visitors can bring devices
- How visitor access ends
- How visitor records are retained
Example
A network equipment vendor needs to replace a firewall.
A practical process could be:
Request → Approval → Visitor Registration → Identity Verification → Escort → Work → Verification → Exit → Record
5. Control Equipment and Devices
Secure areas may contain critical equipment.
The organization should consider controls around:
- Laptops
- Mobile phones
- USB drives
- External hard drives
- Cameras
- Recording devices
- Network devices
- Maintenance equipment
- Personal computers
- Diagnostic tools
Not every secure area requires a complete device ban.
Instead, the organization should determine what is appropriate based on risk.
6. Prevent Unauthorized Observation
Sensitive information may be exposed even without someone touching a system.
For example:
An employee working in a restricted area displays customer information on a large monitor.
A visitor can see the screen through a glass door.
Possible controls include:
- Screen positioning
- Privacy screens
- Restricted viewing areas
- Curtains/blinds where appropriate
- Visitor escorting
- Screen locking
- Restricted photography
- Separation of sensitive work areas
7. Control Sensitive Conversations
Secure areas may also be used for confidential discussions.
Examples include:
- Security incident discussions
- Customer information
- Financial information
- Employee matters
- Security architecture
- Product development
- Vulnerability information
- Legal matters
Employees should understand when discussions need additional privacy.
8. Apply Clean Desk and Clear Screen Practices
Where sensitive physical or electronic information is handled, organizations should consider:
Clean Desk
Do not leave confidential:
- Documents
- Reports
- Contracts
- Customer records
- Credentials
- Printed security information
unattended.
Clear Screen
Employees should lock their computers when leaving the workstation.
Sensitive information should not remain visible to unauthorized persons.
These requirements can also support:
- A.5.10 Acceptable Use
- A.5.12 Classification of Information
- A.5.13 Information Labelling
- A.8.1 User Endpoint Devices
9. Control Contractors and Maintenance Personnel
Third-party personnel may need access to secure areas.
Examples:
- IT support
- Network engineers
- CCTV technicians
- Electrical contractors
- HVAC technicians
- Building maintenance
- Data center engineers
- Equipment vendors
Before granting access, consider:
- Business need
- Authorization
- Identification
- NDA/confidentiality requirements
- Escorting
- Temporary access
- Supervision
- Access termination
- Work records
10. Define Emergency Procedures
People working in secure areas should understand what to do during emergencies.
Examples:
- Fire
- Flood
- Power failure
- Security breach
- Unauthorized entry
- Equipment failure
- Natural disaster
Security requirements should not prevent people from safely evacuating.
For example:
During a fire emergency, employees should follow emergency evacuation procedures rather than attempting to protect equipment.
Safety comes first.
Startup Example – SaaS Company
Consider a 40-person SaaS startup.
The company has:
- General office
- HR/Finance room
- Network room
- Meeting rooms
- Storage area
- Cloud infrastructure hosted by AWS
- Employee laptops
The company identifies the network room as a secure area.
Risks
- Unauthorized access
- Network equipment tampering
- Unauthorized device connection
- Photography of network configuration
- Equipment theft
- Accidental disconnection
Controls
The company implements:
- Restricted physical access
- Authorized IT personnel only
- Visitor escorting
- Access logs
- Door remains closed
- No unauthorized devices
- No unauthorized photography
- Equipment removal requires approval
- Physical inspection
- Security incident reporting
Simple Workflow
Identify Secure Area
↓
Assess Risks
↓
Define Working Rules
↓
Authorize Personnel
↓
Control Visitors
↓
Monitor
↓
Review
↓
Improve
Cloud-First Startup Example
A common question is:
“Our startup uses AWS/Azure/GCP. We don’t have our own data center. Do we still need A.7.6?”
Yes, potentially—but the control should be applied to the physical areas that are actually relevant to your organization.
For example, a startup may not operate a data center, but it may have:
- A network room
- Office equipment
- Restricted HR/Finance areas
- Secure records
- Product development rooms
- Physical backup media
- Confidential project areas
The cloud provider’s data center is generally part of the provider’s responsibility rather than an area the startup directly operates.
The startup should address this through its cloud and supplier security controls, including relevant assurance information from the provider.
Do not create unnecessary physical controls simply to “satisfy ISO.”
Physical Secure Area Register
A simple register can help demonstrate how the organization identifies and manages secure areas.
| Area | Classification | Main Assets | Authorized Personnel | Visitor Requirement | Key Controls |
|---|---|---|---|---|---|
| Network Room | Restricted | Network equipment | IT Team | Escort | Access control, logs |
| HR Room | Restricted | Employee records | HR | Approval | Restricted access |
| Finance Room | Restricted | Financial records | Finance | Approval | Access control |
| Records Room | Restricted | Physical records | Authorized staff | Escort | Locked storage |
| General Office | General | Laptops | Employees | Normal controls | Office security |
Secure Area Working Rules Matrix
| Security Requirement | General Area | Restricted Area | Highly Restricted Area |
|---|---|---|---|
| Authorized access | ✓ | ✓ | ✓ |
| Visitor registration | As applicable | ✓ | ✓ |
| Visitor escort | As applicable | ✓ | ✓ |
| Photography restriction | Risk-based | ✓ | ✓ |
| Personal devices | Normal policy | Risk-based | Restricted if required |
| Removable media | Normal policy | Controlled | Restricted |
| Clean desk | ✓ | ✓ | ✓ |
| Clear screen | ✓ | ✓ | ✓ |
| Activity monitoring | Risk-based | Risk-based | Stronger controls |
| Access review | Periodic | Periodic | More frequent if required |
Audit Evidence for A.7.6
An auditor may ask for evidence that the organization actually manages work inside secure areas.
Useful evidence may include:
Policies and Procedures
- Physical Security Policy
- Secure Area Working Procedure
- Physical Access Control Procedure
- Visitor Management Procedure
- Clean Desk and Clear Screen Policy
- Removable Media Policy
- Physical Security Incident Procedure
Registers and Records
- Secure Area Register
- Physical Access Authorization Register
- Visitor Register
- Contractor Access Records
- Access Review Records
- Key/Card Register
- Physical Security Inspection Checklist
Technical/Operational Evidence
- Door access logs
- CCTV evidence where applicable
- Access control configuration
- Visitor badges
- Physical inspection records
- Security incident records
- Maintenance access records
Third-Party Evidence
Where relevant:
- Data center assurance reports
- Supplier security assessments
- Facility security reports
- SOC reports
- ISO 27001 certificates
- Contractual security requirements
A.7.6 Audit Checklist
An auditor may ask:
Secure Areas
- Have secure areas been identified?
- Is there a documented secure-area register?
- Has the organization assessed the risks associated with those areas?
Working Rules
- Are security rules defined for working inside secure areas?
- Are employees aware of these rules?
- Are the rules appropriate to the sensitivity of the area?
Access
- Is access restricted to authorized personnel?
- Are temporary personnel controlled?
- Are visitors supervised where required?
Information Protection
- Are confidential documents protected?
- Are clear desk and clear screen requirements implemented where appropriate?
- Are photography and recording controls considered?
Devices
- Are unauthorized devices restricted?
- Are removable media controlled where necessary?
Contractors
- Are maintenance personnel and contractors controlled?
- Is temporary access removed after the work is completed?
Monitoring and Review
- Are physical security events monitored where appropriate?
- Are secure-area controls periodically reviewed?
- Are security incidents recorded and addressed?
Common Mistakes in Implementing A.7.6
1. Assuming Access Control Is Enough
An organization may have door access cards but no rules for what people can do inside.
Better approach:
Control both entry and behavior.
2. Treating Every Area as Highly Secure
Making every room a “secure area” can create unnecessary complexity.
Better approach:
Use a risk-based classification.
3. Ignoring Visitors
A visitor may enter a secure area with an employee and then move around without supervision.
Better approach:
Define visitor authorization, escorting and access limitations.
4. Ignoring Contractors
IT vendors and maintenance personnel may have legitimate access but can still create risks.
Better approach:
Use temporary authorization and supervision appropriate to the risk.
5. Allowing Photography Without Considering Risk
Mobile phones can easily capture:
- Screens
- Network diagrams
- Equipment
- Documents
- Security configurations
Better approach:
Determine whether photography/recording needs restrictions in particular secure areas.
6. No Evidence of Actual Operation
Having a “Secure Area Policy” alone does not demonstrate effective implementation.
Better approach:
Maintain operational evidence such as:
- Access records
- Visitor records
- Inspections
- Training
- Access reviews
- Incident records
7. Copying Data Center Controls Into a Small Startup
A cloud-native startup may have no physical data center.
Requiring expensive controls that address risks the organization does not actually have may add unnecessary complexity.
Better approach:
Apply A.7.6 according to the organization’s actual physical environment and risk.
Practical Startup Implementation Model
A startup can implement A.7.6 using the following model:
1. Identify
Identify areas requiring additional physical protection.
2. Assess
Assess the information, equipment and activities located there.
3. Classify
Classify the area according to risk.
4. Define
Define rules for people working in the area.
5. Authorize
Identify who can enter and work there.
6. Control
Control visitors, contractors, devices and information handling.
7. Monitor
Monitor physical activity where appropriate.
8. Review
Periodically review access and working practices.
9. Improve
Update controls when risks, facilities or business requirements change.
Simple Model
Identify → Assess → Classify → Define → Authorize → Control → Monitor → Review → Improve
Policy vs. Process vs. Evidence
One of the easiest ways to understand A.7.6 is to separate these three elements.
| Element | Example |
|---|---|
| Policy | People working in secure areas must follow defined physical security requirements. |
| Process | Secure area access, visitor escorting and working rules are applied according to area classification. |
| Evidence | Access logs, visitor records, inspections, approvals and training records. |
For an audit-ready organization:
Policy says what should happen. Process explains how it happens. Evidence demonstrates that it actually happened.
Relationship With Other ISO 27001 Controls
A.7.6 works together with several other controls.
| Control | Relationship |
|---|---|
| A.5.10 Acceptable Use | Defines acceptable use of information and assets |
| A.5.11 Return of Assets | Controls return of physical assets |
| A.5.12 Classification | Helps determine the sensitivity of information |
| A.5.15 Access Control | Establishes broader access-control principles |
| A.5.18 Access Rights | Controls authorization and review of access |
| A.6.3 Awareness and Training | Educates personnel about secure working |
| A.6.5 Termination/Change | Removes or changes physical access |
| A.6.7 Remote Working | Addresses secure working outside controlled premises |
| A.6.8 Event Reporting | Provides a mechanism to report physical security events |
| A.7.1 Perimeters | Defines physical security boundaries |
| A.7.2 Entry Controls | Controls who can enter |
| A.7.3 Offices, Rooms and Facilities | Protects the physical environment |
| A.7.4 Physical Monitoring | Detects physical security activity |
| A.7.5 Physical/Environmental Threats | Protects against physical and environmental threats |
| A.7.7 Clear Desk/Clear Screen | Protects information from visual or physical exposure |
| A.7.8 Equipment Siting and Protection | Protects equipment physically |
| A.7.9 Security of Assets Off-Premises | Protects assets outside organizational premises |
A.7.6 and A.7.7 – What is the Difference?
These controls can sometimes be confused.
A.7.6 – Working in Secure Areas
Focuses on:
How people work inside areas requiring additional physical security.
Examples:
- Visitor control
- Secure-area working rules
- Device restrictions
- Supervision
- Photography restrictions
- Secure working practices
A.7.7 – Clear Desk and Clear Screen
Focuses specifically on:
Preventing sensitive information from being left exposed on desks or screens.
The two controls can therefore complement each other.
Useful Resources and Draft Documents
Organizations implementing A.7.6 may create or maintain the following documents:
- Physical Security Policy
[Insert Draft Document Link] - Secure Area Working Procedure
[Insert Draft Document Link] - Secure Area Register
[Insert Draft Document Link] - Physical Security Risk Assessment
[Insert Draft Document Link] - Physical Access Authorization Form
[Insert Draft Document Link] - Visitor Management Procedure
[Insert Draft Document Link] - Visitor Register
[Insert Draft Document Link] - Contractor Access Procedure
[Insert Draft Document Link] - Secure Area Inspection Checklist
[Insert Draft Document Link] - Physical Security Incident Report
[Insert Draft Document Link] - Physical Access Review Checklist
[Insert Draft Document Link] - Clean Desk and Clear Screen Policy
[Insert Draft Document Link]
Questions an Auditor May Ask
An ISO 27001 auditor may ask:
“Which areas do you consider secure areas?”
Show the Secure Area Register and explain the risk assessment behind the classification.
“Who can work in these areas?”
Show the physical access authorization records.
“What rules apply when someone works there?”
Show the Secure Area Working Procedure or relevant physical security policy.
“What happens when a contractor needs access?”
Explain the authorization, identification, escorting and temporary access process.
“Can visitors enter the secure area?”
Explain the visitor process and provide visitor records where applicable.
“How do you prevent unauthorized photography or recording?”
Explain the controls applied to sensitive areas based on risk.
“How do you know employees understand these requirements?”
Show security awareness/training records and relevant communications.
“What happens if someone violates the secure-area rules?”
Show the incident reporting and disciplinary/escalation process where applicable.
Startup-Focused Quick Summary
For most startups, A.7.6 does not mean creating an expensive high-security facility.
A practical approach is:
Step 1
Identify physical areas that contain sensitive information or critical equipment.
Step 2
Assess the risks.
Step 3
Classify the areas.
Step 4
Define simple working rules.
Step 5
Restrict access to authorized people.
Step 6
Control visitors and contractors.
Step 7
Control sensitive information, devices and photography where required.
Step 8
Train employees.
Step 9
Maintain evidence.
Step 10
Review the controls periodically.
Startup-Focused Final Takeaway
ISO 27001 Annex A 7.6 is not about making every office a high-security facility.
It is about recognizing that some physical locations require stronger working practices because of the information, systems or assets located there.
A startup should therefore ask:
Which physical areas actually create additional information-security risk?
Then:
Who needs to work there?
What could go wrong?
What rules should people follow?
How will visitors and contractors be controlled?
What evidence proves that the rules are actually being followed?
A practical implementation sequence is:
Identify Secure Areas → Assess Risk → Classify → Define Working Rules → Authorize → Control → Monitor → Review → Improve
The goal is not to create unnecessary physical restrictions.
The goal is to make sure that people working in sensitive physical areas understand the risks and follow appropriate security practices.
