ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 4. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 7.12 Cabling security

ISO 27001 Annex A 7.12 Cabling security

What is ISO 27001 Annex A 7.12 – Cabling Security?

ISO 27001 Annex A 7.12 – Cabling Security requires organizations to protect power and telecommunications cabling from interception, interference, damage, and other physical security risks.

Cabling can carry or support:

  • Network traffic
  • Internet connectivity
  • Voice communications
  • Security system signals
  • Access-control systems
  • Power to information-processing equipment
  • Data between network devices
  • Critical communications

Examples include:

  • Ethernet cables
  • Fiber-optic cables
  • Network backbone cables
  • Telephone cables
  • Power cables
  • Data-center cabling
  • Patch cables
  • Structured cabling
  • Communication cables
  • Cables connecting security and access-control systems

Simple explanation: Important cables should be installed, protected, and maintained so that people cannot easily damage, disconnect, intercept, or interfere with the services they support.


Why is Annex A 7.12 Important?

Organizations often focus heavily on cybersecurity controls such as:

  • Firewalls
  • MFA
  • Endpoint protection
  • Encryption
  • Vulnerability management

But physical cabling can also create security and availability risks.

For example:

Unprotected network cable → unauthorized physical access → cable disconnected → network outage

Or:

Accessible communication cable → physical tampering → communication disruption

Or:

Sensitive cable exposed in an uncontrolled area → opportunity for unauthorized interception or manipulation

Cabling problems can affect:

  • Confidentiality
  • Integrity
  • Availability
  • Physical security
  • Network reliability
  • Business continuity

What Does ISO 27001 Annex A 7.12 Require?

The organization should protect power and telecommunications cabling against risks such as:

  • Unauthorized access
  • Physical damage
  • Tampering
  • Accidental disconnection
  • Interference
  • Environmental damage
  • Unauthorized interception
  • Cable cutting
  • Poor installation
  • Uncontrolled access to network infrastructure

The controls should be appropriate to the organization’s risk and environment.

A small startup with a few network switches does not need the same cabling security arrangements as a large data center.


What is Cabling Security?

Cabling security is the protection of cables and associated infrastructure used to support information processing and communication.

It covers both:

Power cabling

Examples:

  • Electrical power cables
  • UPS connections
  • Power distribution cables
  • Power connections to critical equipment

Telecommunications and data cabling

Examples:

  • Ethernet
  • Fiber optic
  • Telephone
  • Network backbone
  • Internet connectivity
  • Communication infrastructure

The objective is not simply to make cables look organized.

The objective is to protect the availability, integrity, and confidentiality of the services carried or supported by those cables.


Common Cabling Risks

RiskExample
Physical damageCable damaged during construction
Accidental disconnectionEmployee disconnects network cable
Unauthorized accessNetwork cables accessible to unauthorized people
TamperingSomeone modifies or interferes with cabling
Cable cuttingCritical communication line is deliberately cut
Environmental damageWater damages cables
Poor installationIncorrect cabling causes instability
Lack of redundancyOne cable failure causes major outage
Unauthorized interceptionSensitive communication infrastructure is physically accessible
Cable confusionIncorrect patching causes network disruption

Activities Required to Implement Annex A 7.12

1. Identify Critical Cabling

First identify cabling that is important to information processing.

Examples:

  • Internet connection
  • Core network connections
  • Server/network room cabling
  • Fiber backbone
  • Security system cabling
  • Access-control cabling
  • Critical power connections
  • Connections to important network devices

You do not necessarily need to document every ordinary power cable individually.

Focus on cables where failure or compromise could create meaningful risk.


2. Identify Where Cables Are Located

Determine where important cables run.

Examples:

  • Server rooms
  • Network rooms
  • Ceilings
  • Raised floors
  • Cable trays
  • Walls
  • Building shafts
  • External pathways
  • Data centers
  • Shared office areas

Understanding the physical route helps identify risks.


3. Protect Network Cables From Unauthorized Access

Where appropriate, cables should be routed through controlled areas.

Possible controls include:

  • Cable trays
  • Conduits
  • Locked network rooms
  • Secure risers
  • Restricted ceiling/floor access
  • Protected cable pathways
  • Physical barriers

The objective is to make unauthorized access or interference more difficult.


4. Separate Critical Cabling Where Appropriate

Power and telecommunications cables may need appropriate separation depending on the environment.

For example, separation can reduce:

  • Electrical interference
  • Accidental damage
  • Maintenance problems
  • Physical disruption

The actual requirements depend on the type of facility and infrastructure.


5. Protect Against Physical Damage

Cables should be protected from foreseeable damage caused by:

  • People
  • Furniture
  • Construction
  • Water
  • Heat
  • Sharp objects
  • Vehicles
  • Maintenance activities
  • Equipment movement

For example:

A network cable running across a walkway creates both a safety and availability risk.


6. Protect Cabling in Restricted Areas

Where cables support critical systems, access to the associated cabling infrastructure should be restricted.

For example:

Network room → restricted access → secured racks → controlled patching → documented changes

This works together with:

  • A.7.2 – Physical Entry Controls
  • A.7.3 – Securing Offices, Rooms and Facilities
  • A.7.6 – Working in Secure Areas

7. Protect External Cabling

Some organizations have cables running outside controlled buildings.

Examples:

  • Internet connections
  • Fiber connections between buildings
  • External communication infrastructure
  • Data-center connectivity
  • Campus network connections

Where appropriate, external cabling may require:

  • Protected pathways
  • Conduits
  • Physical access restrictions
  • Tamper protection
  • Monitoring
  • Alternative connectivity

8. Protect Against Unauthorized Interception

Where cables carry particularly sensitive information, the organization should consider the risk of physical interception.

Controls may include:

  • Secure cable routes
  • Restricted physical access
  • Fiber-optic infrastructure where appropriate
  • Encryption of data
  • Protected network infrastructure

Encryption is particularly useful because physical protection and encryption address different risks.

For example:

Physical protection → makes cable access more difficult.

Encryption → reduces the value of intercepted data.


9. Label Cables Appropriately

Cable identification can help prevent accidental disconnection or incorrect patching.

Examples:

  • Cable ID
  • Source
  • Destination
  • Port number
  • Rack information
  • Circuit identification

However, avoid unnecessarily exposing sensitive infrastructure information in publicly accessible areas.

Cable labels should be practical and appropriately controlled.


10. Maintain Cable Documentation

Organizations may maintain:

  • Network diagrams
  • Cable diagrams
  • Rack diagrams
  • Port mappings
  • Cable registers
  • Data-center layouts
  • Critical connectivity documentation

Documentation should be kept accurate enough to support:

  • Troubleshooting
  • Maintenance
  • Incident response
  • Change management
  • Business continuity

11. Control Changes to Critical Cabling

Changes to important cabling should be appropriately authorized.

For example:

Change request → Impact assessment → Approval → Cabling change → Testing → Documentation update

This helps prevent accidental network outages.

This also connects with:

A.8.32 – Change Management


12. Inspect Cabling

Periodic inspections may identify:

  • Damaged cables
  • Loose connections
  • Exposed cables
  • Unauthorized modifications
  • Poor routing
  • Water exposure
  • Overloaded cable pathways
  • Unused cables
  • Unsafe installation

The frequency should depend on risk and the environment.


Startup Example

Imagine a 50-person SaaS startup.

The company has:

  • One network room
  • Firewall
  • Core switch
  • Wi-Fi access points
  • Internet connection
  • CCTV
  • Access-control system
  • Employee workstations
  • Cloud production environment

The company does not operate a data center.

Practical cabling controls

The startup could:

  • Keep the network room locked.
  • Restrict access to IT personnel.
  • Route important cables through appropriate pathways.
  • Keep network cables away from areas where they can easily be damaged.
  • Label important network connections.
  • Maintain a basic network diagram.
  • Document major cabling changes.
  • Protect internet entry points where practical.
  • Inspect cabling periodically.
  • Maintain backup internet connectivity where business risk justifies it.

This may be sufficient depending on the organization’s risk assessment.


Cabling Security Example

Without adequate controls

Accessible network room

↓

Uncontrolled access

↓

Critical network cable disconnected

↓

Office network unavailable

↓

Employees cannot access cloud services

With appropriate controls

Restricted network room

↓

Controlled physical access

↓

Protected cable pathways

↓

Documented network configuration

↓

Controlled changes

↓

Monitoring and maintenance

↓

Reduced cabling-related risk


Cabling Security Risk Assessment

RiskLikelihoodImpactExample Control
Network cable accidentally disconnectedMediumHighProtected/labelled cabling
Cable damaged during constructionMediumHighProtected pathway
Unauthorized physical accessLow/MediumHighRestricted network room
Water damageLowHighAppropriate routing
Cable tamperingLowHighControlled access
Single cable failureMediumHighRedundant connectivity where justified
Incorrect patchingMediumMedium/HighCable labels + change control
External cable damageLow/MediumHighProtected pathway
Unauthorized interceptionLowHighPhysical protection + encryption

Cabling Inventory / Register

A startup does not necessarily need an inventory of every cable.

A simple register can focus on critical connections.

Cable IDTypeSourceDestinationCriticalityProtectionStatus
CAB-001FiberISP EntryFirewallCriticalProtected pathwayActive
CAB-002EthernetFirewallCore SwitchCriticalLocked network roomActive
CAB-003FiberCore SwitchNetwork RackHighCable trayActive
CAB-004EthernetAccess ControllerDoor SystemHighProtected routeActive

Network / Cabling Diagram

A simple network diagram can help demonstrate understanding of critical connectivity.

Example:

Internet

↓

ISP Fiber Entry

↓

Firewall

↓

Core Switch

↓

Network Switches

↓

Wi-Fi / Endpoints

The diagram should identify important physical connectivity where appropriate.

It can support:

  • Incident response
  • Troubleshooting
  • Change management
  • Business continuity
  • Cabling security

Cabling Change Management

Critical cabling changes should be controlled.

Example

A network switch is being relocated.

Before the change

  • Identify affected cables.
  • Assess business impact.
  • Obtain approval.
  • Schedule maintenance.
  • Prepare rollback plan.

During the change

  • Disconnect according to the approved plan.
  • Install new cabling.
  • Verify connections.
  • Test network connectivity.

After the change

  • Update network diagram.
  • Update cable/port records.
  • Confirm service availability.
  • Close the change record.

Do not let undocumented cabling changes become an undocumented security or availability risk.


Cloud-First Startup Considerations

A cloud-first startup may assume that cabling security is only relevant to data centers.

That is not correct.

The startup may still have:

  • Office network cabling
  • Internet connections
  • Firewall connections
  • Switches
  • Wi-Fi infrastructure
  • CCTV
  • Access-control systems
  • Power connections
  • Network room cabling

At the same time, the organization normally does not directly manage cabling inside its cloud provider’s data centers.

For cloud infrastructure, the organization should instead consider:

  • Cloud provider responsibilities
  • Supplier assurance
  • Availability commitments
  • Network architecture
  • Redundancy
  • Encryption
  • Business continuity

Audit Evidence for Annex A 7.12

An auditor may request evidence such as:

Documentation

  • Cabling Security Policy
  • Physical Security Policy
  • Network Security Policy
  • Network Diagram
  • Cable Diagram
  • Rack Diagram
  • Cable Register
  • Data Center/Network Room Layout
  • Cabling Change Procedure

Operational evidence

  • Physical inspection records
  • Network room inspection checklist
  • Cable maintenance records
  • Cabling change records
  • Network diagrams
  • Port mappings
  • Photographs of secured cable routes
  • Vendor installation records
  • Maintenance contracts

Security evidence

  • Physical access logs
  • Restricted-area access lists
  • Network room access records
  • Change approvals
  • Incident records
  • Risk assessment

The exact evidence should reflect the organization’s actual environment.


Audit Checklist – ISO 27001 Annex A 7.12

QuestionYes/NoEvidence
Have critical power and telecommunications cables been identified?
Has the organization assessed cabling-related risks?
Are critical cables protected against physical damage?
Is access to important cabling appropriately restricted?
Are network rooms appropriately secured?
Are important cables routed through protected pathways where necessary?
Are cables protected from environmental threats?
Are external cables protected where required?
Is sensitive cabling protected against unauthorized interception where necessary?
Are important cables appropriately labelled?
Are critical connections documented?
Are cabling changes controlled?
Are network/cabling diagrams maintained?
Are important cabling arrangements periodically inspected?
Are single points of failure identified?
Are third-party cabling dependencies considered?
Are cabling incidents recorded and reviewed?

Common Mistakes

1. Thinking cabling security only applies to data centers

Small offices can also have critical cabling.

A single cable connecting the firewall to the core switch may be essential to the entire organization’s network.


2. Leaving the network room unlocked

Physical access to network infrastructure can allow:

  • Cable disconnection
  • Unauthorized patching
  • Device tampering
  • Network disruption

3. Poor cable routing

Cables running across:

  • Walkways
  • Open areas
  • Water-prone locations
  • Construction areas

can be easily damaged.


4. No documentation

Organizations sometimes have a network that “everyone knows.”

Then the IT administrator leaves.

Suddenly nobody knows:

  • Which cable goes where
  • Which port is critical
  • Where the ISP enters
  • Which switch serves which area

Basic documentation reduces this risk.


5. No change management

Uncontrolled cabling changes can cause unnecessary outages.


6. No consideration of external cabling

An organization may secure its network room but ignore the cable connecting the building to the ISP.

External connectivity should be considered where relevant.


7. Overengineering the control

A small startup does not necessarily need expensive specialized cable-security infrastructure.

The objective is risk-based protection, not maximum physical security.


8. Confusing cable organization with cable security

Neat cables are useful.

But cable management alone does not demonstrate security.

The organization should consider:

Access + Protection + Routing + Documentation + Change Control + Monitoring


Practical Startup Implementation Model

A startup can implement Annex A 7.12 using this model:

1. Identify

Identify critical power and telecommunications cabling.

2. Map

Understand where important cables run.

3. Assess

Assess physical, environmental and security risks.

4. Protect

Use appropriate pathways, conduits, restricted areas and physical controls.

5. Label

Identify important connections appropriately.

6. Document

Maintain basic network and cabling documentation.

7. Control Changes

Authorize and document significant cabling changes.

8. Inspect

Periodically inspect critical cabling.

9. Maintain

Repair or replace damaged infrastructure.

10. Improve

Review incidents, outages and changes to identify improvements.

Startup formula: Identify → Map → Assess → Protect → Document → Control Changes → Inspect → Maintain


Policy vs. Process vs. Evidence

LayerExample
PolicyPhysical and Cabling Security Policy
ProcessCabling Installation and Change Procedure
Risk AssessmentCabling Security Risk Assessment
Technical/Physical ControlCable tray, conduit, locked network room
DocumentationNetwork/Cabling Diagram
RecordCabling inspection record
Change EvidenceApproved cabling change
Incident EvidenceCable failure/disconnection report

The objective is not to produce a complicated cabling manual.

The organization should be able to demonstrate that important cabling risks are understood and appropriately controlled.


Relationship With Other ISO 27001 Controls

ControlRelationship
A.5.9 Inventory of Information and Other Associated AssetsHelps identify network equipment and associated infrastructure
A.5.15 Access ControlRestricts access to areas and systems connected through critical cabling
A.5.18 Access RightsSupports authorization for physical/network infrastructure access
A.5.19 Supplier RelationshipsRelevant when cabling is installed or maintained by suppliers
A.5.20 Supplier AgreementsSecurity requirements can apply to external infrastructure providers
A.5.22 Monitoring, Review and Change Management of Supplier ServicesRelevant to third-party network/cabling services
A.5.30 ICT Readiness for Business ContinuityCabling failure can affect ICT availability
A.7.2 Physical Entry ControlsControls who can access areas containing cabling
A.7.3 Securing Offices, Rooms and FacilitiesProtects network rooms and facilities
A.7.5 Physical and Environmental ThreatsProtects cabling from physical/environmental events
A.7.8 Equipment Siting and ProtectionProtects network equipment and related infrastructure
A.7.11 Supporting UtilitiesAddresses power and other supporting utilities
A.8.14 Redundancy of Information Processing FacilitiesAddresses redundancy where cabling failure could affect critical processing
A.8.20 Network SecurityProtects logical/network communications
A.8.21 Security of Network ServicesAddresses security requirements for network services
A.8.32 Change ManagementControls important infrastructure changes

A.7.11 vs A.7.12

These controls are closely connected.

ControlMain Focus
A.7.11 Supporting UtilitiesProtecting utilities required for information-processing facilities
A.7.12 Cabling SecurityProtecting power and telecommunications cabling from physical and security risks

Example

A network room requires electricity.

  • A.7.11 → protects the supporting power supply.
  • A.7.12 → protects the power and communication cabling that connects the equipment.

A.7.12 vs A.8.20 Network Security

These controls address different layers.

A.7.12

Focuses on the physical infrastructure carrying or supporting communications.

A.8.20

Focuses on logical/network security.

For example:

Secure cable route → A.7.12

Firewall and network segmentation → A.8.20

Both may be necessary for a complete network-security approach.


Useful Resources

Organizations can create the following supporting documents:

  1. Cabling Security Policy
    [Insert Draft Document Link]
  2. Cabling Security Procedure
    [Insert Draft Document Link]
  3. Cabling Security Risk Assessment
    [Insert Draft Document Link]
  4. Critical Cabling Register
    [Insert Draft Document Link]
  5. Network Infrastructure Diagram
    [Insert Draft Document Link]
  6. Cabling Inspection Checklist
    [Insert Draft Document Link]
  7. Network Room Inspection Checklist
    [Insert Draft Document Link]
  8. Cabling Change Request Form
    [Insert Draft Document Link]
  9. Cabling Maintenance Record
    [Insert Draft Document Link]
  10. Cabling Security Audit Checklist
    [Insert Draft Document Link]

Questions an Auditor May Ask

1. Which cables are critical to your business?

Be prepared to identify major network, telecommunications and power connections.

2. How are critical cables physically protected?

Explain routing, restricted areas, conduits, cable trays or other controls.

3. Who can access your network cabling?

Explain physical access restrictions.

4. How do you prevent accidental disconnection?

Explain cable routing, labelling and access controls.

5. How do you prevent unauthorized tampering?

Explain restricted access and physical protection.

6. How do you know which cable connects to which system?

Show your network or cabling documentation.

7. How are cabling changes controlled?

Show change requests, approvals and updated diagrams.

8. What happens if a critical cable fails?

Explain your incident and business-continuity response.

9. Do you have any cabling single points of failure?

Show the relevant risk assessment.

10. How do you protect cables managed by third parties?

Explain supplier controls, contractual requirements and assurance activities.


Startup-Focused Final Takeaway

ISO 27001 Annex A 7.12 is about recognizing that physical cabling is part of the organization’s information-processing infrastructure.

A firewall can be perfectly configured, a cloud platform can be secure, and employees can use MFA—but a physically damaged or disconnected critical cable can still cause a major outage.

A practical startup should therefore:

Identify critical cables → understand their routes → restrict access → protect them from damage → document important connections → control changes → inspect and maintain them.

The simple rule

If a cable can interrupt or compromise an important information service, it deserves appropriate protection.

For most startups, Annex A 7.12 does not require complicated data-center infrastructure.

It requires the organization to understand its physical connectivity and apply controls that are appropriate to the risk, business impact, and environment.

Identify → Map → Assess → Protect → Document → Control → Inspect → Improve

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *