What is ISO 27001 Annex A 7.3 – Securing Offices, Rooms and Facilities?
ISO 27001 Annex A 7.3 focuses on protecting offices, rooms and facilities where information and associated assets are located.
The objective is to prevent unauthorized access, damage, interference, or other physical security risks affecting people, information, systems, and equipment.
This can apply to:
- Corporate offices
- Server rooms
- Network rooms
- Data centers
- HR and finance areas
- Records/storage rooms
- Security operations rooms
- Meeting rooms
- Research and development areas
- Equipment rooms
- Utility areas supporting critical systems
Simple Explanation
A.7.2 controls who can enter. A.7.3 focuses on how the offices, rooms and facilities themselves are secured.
For example, simply restricting access to a server room may not be enough.
The organization should also consider:
- Where the room is located
- Whether doors and walls provide appropriate protection
- Whether visitors can see sensitive information
- Whether equipment is exposed to environmental risks
- Whether emergency exits are secure
- Whether utilities are protected
- Whether sensitive rooms are appropriately separated
Why is A.7.3 Important?
Physical security is not only about preventing someone from walking into an office.
A poorly designed or inadequately protected facility can expose an organization to:
- Unauthorized access
- Theft
- Equipment damage
- Information disclosure
- Tampering
- Eavesdropping
- Fire
- Water damage
- Power-related incidents
- Environmental damage
- Unauthorized photography
- Physical disruption
- Loss of critical infrastructure
For example, a network room located in an unrestricted public area may create a significant risk even if the organization has a good cybersecurity program.
Simple Principle
Protect the room according to what is inside it, what happens there, and what could happen if it is compromised.
What Does A.7.3 Require?
Organizations should design and apply appropriate physical security measures for offices, rooms and facilities.
The controls should consider:
- Information sensitivity
- Criticality of equipment
- Physical location
- Threats to the organization
- Environmental risks
- Access requirements
- Business continuity requirements
- Legal and contractual requirements
The organization should avoid both extremes:
Too Little Protection
Example:
Sensitive customer records are stored in an unlocked room accessible to visitors.
Too Much Protection
Example:
A small startup installs expensive biometric systems for ordinary meeting rooms that contain no sensitive assets.
The objective is risk-based physical protection.
A.7.2 vs A.7.3
These controls are closely related.
| Control | Main Question |
|---|---|
| A.7.1 Physical Security Perimeters | Where does the protected physical boundary exist? |
| A.7.2 Physical Entry Controls | Who is allowed to enter? |
| A.7.3 Securing Offices, Rooms and Facilities | How are the offices, rooms and facilities protected? |
Example
Consider a network room.
A.7.1:
The network room is identified as a restricted physical area.
A.7.2:
Only authorized IT personnel can enter.
A.7.3:
The room is appropriately located, secured, protected from unauthorized observation, and maintained to reduce relevant physical and environmental risks.
Activities Required to Implement A.7.3
1. Identify Offices, Rooms and Facilities Requiring Protection
Start by identifying areas that require physical security based on risk.
Examples:
- Main office
- Network room
- Server room
- Data center
- HR room
- Finance room
- Records storage
- Backup storage
- Security operations area
- Equipment room
Not every room needs the same level of protection.
2. Assess the Risks Associated With Each Area
Consider:
Unauthorized Access
Could unauthorized people enter the area?
Information Exposure
Could sensitive information be seen, copied or photographed?
Equipment Damage
Could critical equipment be damaged or disconnected?
Environmental Threats
Could the area be affected by:
- Fire
- Water
- Heat
- Humidity
- Dust
- Power problems
Operational Disruption
Could an incident prevent the organization from operating?
External Threats
Consider the surrounding environment:
- Public access
- Adjacent businesses
- Construction
- Flooding
- Crime
- Industrial activity
- Shared buildings
3. Define Physical Security Requirements
Different rooms may require different controls.
Example:
| Area | Risk | Possible Controls |
|---|---|---|
| Reception | Visitor access | Reception desk, visitor controls |
| General Office | Unauthorized entry | Door access control |
| HR Room | Confidential information | Restricted access, locked storage |
| Finance Room | Financial records | Restricted access, secure storage |
| Network Room | Critical infrastructure | Restricted access, locked room |
| Server Room | Critical infrastructure | Strong access control, environmental protection |
| Records Room | Sensitive records | Locked room, controlled access |
4. Secure Doors, Walls and Windows
Physical boundaries should be appropriate for the sensitivity of the area.
Consider:
- Strong doors
- Locks
- Access-control mechanisms
- Secure windows
- Appropriate walls/partitions
- Door closers
- Emergency exits
- Ceiling/floor vulnerabilities
- Visibility through windows
For highly sensitive areas, the organization should consider whether someone could bypass the intended physical boundary through:
- Adjacent rooms
- Windows
- False ceilings
- Service corridors
- Unsecured doors
- Shared building spaces
The appropriate level of protection depends on the risk.
5. Protect Sensitive Areas From Public Visibility
Physical security also includes visual exposure.
For example:
A meeting room may have access control, but confidential information displayed on a large screen could still be visible through a glass wall.
Potential controls include:
- Blinds
- Privacy film
- Screen positioning
- Restricted meeting-room use
- Clear-screen practices
- Controlled photography
- Visitor restrictions
This connects with A.7.7 Clear Desk and Clear Screen.
6. Secure Critical Equipment Areas
Where critical information-processing equipment is located, consider additional controls.
Examples:
- Network racks
- Servers
- Firewalls
- Switches
- Storage systems
- Backup systems
- UPS systems
- Telecommunications equipment
Potential controls include:
- Locked rooms
- Locked cabinets/racks
- Restricted access
- Appropriate environmental controls
- Cable protection
- Monitoring
- Equipment labeling
7. Protect Supporting Facilities
Physical security should also consider facilities that support information processing.
Examples:
- Electrical rooms
- UPS rooms
- Generator areas
- HVAC systems
- Network connection points
- Telecommunications rooms
- Fire protection systems
- Water supply
- Building management systems
A cybersecurity incident does not always begin with a computer.
For example:
A power failure affecting a critical network room can become an information-security availability incident.
8. Consider Fire and Environmental Risks
The organization should consider appropriate protection against environmental threats.
Depending on the facility, this may include:
- Fire detection
- Fire suppression
- Smoke detection
- Temperature monitoring
- Humidity monitoring
- Water-leak detection
- Flood protection
- Appropriate ventilation
- Air conditioning
- Dust control
The controls should be appropriate to the equipment and risk.
A small office laptop area does not necessarily require the same environmental controls as a dedicated data center.
9. Protect Emergency Exits
Emergency exits must support life safety requirements while also considering security.
Organizations should ensure that:
- Emergency exits are not unnecessarily blocked
- Doors operate as required during emergencies
- Exit arrangements are understood
- Security controls do not create unsafe evacuation conditions
Physical security should never be implemented in a way that creates an unacceptable safety risk.
10. Secure Sensitive Rooms During Visits and Maintenance
Maintenance personnel, vendors and contractors may need temporary access.
Examples:
- HVAC maintenance
- Electrical work
- Network installation
- Equipment repair
- Cleaning
- Building maintenance
The organization should determine whether:
- Access needs approval
- The person needs an escort
- Work needs supervision
- Equipment needs protection
- Access needs to be logged
- Sensitive information needs to be removed or covered
11. Consider Shared Buildings and Coworking Spaces
Many startups operate from:
- Coworking spaces
- Serviced offices
- Shared commercial buildings
- Incubators
- Managed offices
In these environments, some physical controls may be provided by the facility operator.
The organization should understand:
Which controls are provided by the facility and which remain the organization’s responsibility?
For example:
| Control | Facility Provider | Startup |
|---|---|---|
| Building entrance | ✓ | |
| Security guards | ✓ | |
| Common-area CCTV | ✓ | |
| Employee access cards | Shared | ✓ |
| Visitor management | Shared | ✓ |
| Laptop protection | ✓ | |
| Confidential documents | ✓ | |
| Screen protection | ✓ | |
| Restricted internal rooms | Shared | ✓ |
This should be documented where relevant.
Startup Example
Consider a 35-person SaaS company.
The office contains:
- Reception
- Open workspace
- HR/Finance room
- Meeting rooms
- Network room
- Storage area
The company applies different controls.
General Workspace
Employees use controlled office access.
HR/Finance
Restricted access is applied because confidential employee and financial information is processed there.
Network Room
The room is locked and access is limited to authorized IT personnel.
Meeting Rooms
Employees are instructed not to leave confidential information visible after meetings.
Visitors
Visitors remain in designated areas unless access to another area is approved.
Equipment
Network equipment is kept in a secured room/rack rather than in an open workspace.
Environmental Risks
The company assesses power, heat, fire and water risks for its critical equipment.
This provides a proportionate physical-security model without requiring a large enterprise security infrastructure.
Physical Security Area Register
A simple register can help demonstrate implementation.
| Area | Purpose | Security Level | Key Assets | Main Risks | Controls |
|---|---|---|---|---|---|
| Reception | Visitor management | Public | Visitor records | Unauthorized entry | Reception |
| General Office | Employee workspace | General | Laptops | Theft | Controlled entry |
| HR Room | HR operations | Restricted | Employee records | Disclosure | Locked access |
| Finance Room | Finance operations | Restricted | Financial records | Disclosure | Restricted access |
| Network Room | IT infrastructure | Highly Restricted | Network equipment | Tampering | Locked room |
| Storage Room | Asset storage | Restricted | Equipment | Theft | Locked access |
Physical Room Risk Assessment
A practical assessment can look like this:
| Area | Threat | Impact | Existing Control | Additional Action |
|---|---|---|---|---|
| Network Room | Unauthorized entry | High | Locked door | Access review |
| HR Room | Unauthorized viewing | High | Restricted access | Privacy film |
| Storage | Equipment theft | Medium | Locked room | Asset register |
| Meeting Room | Information exposure | Medium | Controlled access | Clear-screen reminders |
| Server Room | Heat/fire | High | HVAC/fire system | Periodic inspection |
The assessment should be proportional to the organization’s size and risk.
What About Cloud-Only Startups?
A cloud-first startup may not operate its own server room.
That does not mean A.7.3 is irrelevant.
The startup may still have:
- Office space
- Laptops
- Network equipment
- Physical records
- Employee work areas
- Meeting rooms
- Backup devices
- Home-working environments
For cloud infrastructure, the physical facility may be operated by a cloud provider.
The organization should understand the provider’s responsibilities through appropriate supplier assurance.
For example:
- Cloud provider certifications
- SOC reports
- Contractual commitments
- Supplier assessments
- Security documentation
The startup should avoid claiming that it physically controls a cloud data center when it does not.
Audit Evidence for A.7.3
An auditor may request:
Policies
- Physical Security Policy
- Physical Facility Security Procedure
- Office Security Procedure
- Secure Area Procedure
Registers
- Physical Security Area Register
- Restricted Area Register
- Physical Asset Register
- Facility Risk Assessment
Operational Evidence
- Physical security inspections
- Maintenance records
- Environmental monitoring
- Fire-system inspection records
- Access-control records
- Visitor records
- Security incident records
Facility Evidence
Where applicable:
- Office photographs
- Floor plans
- Restricted-area identification
- Door/access-control arrangements
- CCTV arrangements
- Fire protection records
- HVAC records
- UPS maintenance records
Third-Party Evidence
For leased/shared facilities:
- Facility security documentation
- Building security procedures
- Supplier assessments
- Contractual requirements
- Relevant certifications/reports
Audit Checklist for A.7.3
An auditor may ask:
Facilities
- Have you identified the offices and facilities requiring protection?
- Which areas are considered restricted?
- What information or equipment is located there?
Physical Protection
- How are sensitive rooms protected?
- Are doors, windows and other physical boundaries appropriate?
- Are critical equipment areas separately secured?
Environmental Protection
- How do you protect critical equipment from fire?
- How are temperature and environmental risks managed?
- How do you address water leakage or flooding?
Visitors and Contractors
- How are visitors controlled?
- Can contractors enter restricted rooms?
- Are maintenance activities supervised where necessary?
Shared Facilities
- Do you use a coworking or serviced office?
- Which physical controls are provided by the facility?
- What responsibilities remain with your organization?
Evidence
- Can you show your physical security area register?
- Can you show a recent physical security inspection?
- Can you show evidence of environmental or facility maintenance?
Common Mistakes
1. Treating Physical Security as Only Door Locks
Physical security includes much more than controlling entry.
Organizations should also consider:
- Walls
- Windows
- Equipment
- Environmental risks
- Utilities
- Visibility
- Visitors
- Maintenance activities
2. Ignoring Environmental Risks
A secured server room can still be vulnerable to:
- Fire
- Heat
- Water
- Humidity
- Power failure
3. Putting Critical Equipment in Open Areas
Network equipment should not be left exposed simply because the office itself is access-controlled.
4. Ignoring Glass Walls and Windows
A person may not need to enter a room to see sensitive information.
Visual exposure can also be a security risk.
5. Giving Contractors Unrestricted Access
A maintenance contractor may need access to a facility, but that does not automatically mean they need unrestricted access to sensitive rooms.
6. Assuming the Building Owner Handles Everything
In a leased or coworking environment, responsibilities should be understood rather than assumed.
7. Overengineering Physical Security
ISO 27001 does not mean every organization needs:
- Biometrics
- Security guards
- Mantraps
- Military-grade doors
- Complex surveillance
The controls should correspond to risk.
Practical Startup Implementation Model
A startup can implement A.7.3 using this lifecycle:
Identify → Assess → Classify → Protect → Monitor → Maintain → Review → Improve
Identify
Identify offices, rooms and facilities that require protection.
Assess
Determine physical, environmental and operational risks.
Classify
Assign appropriate security levels.
Protect
Implement appropriate physical and environmental controls.
Monitor
Monitor relevant conditions and security events.
Maintain
Keep doors, locks, equipment, HVAC, fire systems and other relevant controls functional.
Review
Periodically reassess physical security.
Improve
Address weaknesses, incidents and audit findings.
Policy vs. Process vs. Evidence
| Element | Example |
|---|---|
| Policy | Physical Security Policy |
| Process | Physical Facility Security Process |
| Procedure | Secure Room Procedure |
| Register | Physical Security Area Register |
| Risk Assessment | Facility Security Risk Assessment |
| Control | Locked network room |
| Evidence | Access logs, inspection records |
| Review | Periodic physical security inspection |
Remember
A control is not the same as evidence of a control.
A locked room is a control.
A documented inspection showing that the room was checked is evidence that the control is being monitored.
Relationship With Other ISO 27001 Controls
A.7.3 connects closely with several other controls:
- A.5.9 – Inventory of information and other associated assets
- A.5.11 – Return of assets
- A.5.15 – Access control
- A.5.18 – Access rights
- A.5.19 – Information security in supplier relationships
- A.5.23 – Information security for use of cloud services
- A.6.5 – Responsibilities after termination or change of employment
- A.6.7 – Remote working
- A.7.1 – Physical security perimeters
- A.7.2 – Physical entry controls
- A.7.4 – Physical security monitoring
- A.7.5 – Protecting against physical and environmental threats
- A.7.6 – Working in secure areas
- A.7.7 – Clear desk and clear screen
- A.7.8 – Equipment siting and protection
- A.7.9 – Security of assets off-premises
How They Work Together
A.7.1
Defines the physical security boundary.
↓
A.7.2
Controls who enters.
↓
A.7.3
Secures the offices, rooms and facilities.
↓
A.7.4
Monitors physical security where appropriate.
↓
A.7.5
Addresses physical and environmental threats.
This creates a connected physical-security framework rather than isolated controls.
Useful Resources and Draft Documents
Organizations implementing A.7.3 may consider creating:
- Physical Security Policy
[Insert Draft Document Link] - Physical Facility Security Procedure
[Insert Draft Document Link] - Physical Security Area Register
[Insert Draft Document Link] - Physical Facility Risk Assessment
[Insert Draft Document Link] - Restricted Area Register
[Insert Draft Document Link] - Physical Security Inspection Checklist
[Insert Draft Document Link] - Server Room Security Checklist
[Insert Draft Document Link] - Network Room Security Checklist
[Insert Draft Document Link] - Facility Maintenance Checklist
[Insert Draft Document Link] - Physical Security Incident Report
[Insert Draft Document Link] - Environmental Risk Assessment
[Insert Draft Document Link] - Coworking / Shared Facility Security Assessment
[Insert Draft Document Link]
Questions an Auditor May Ask Management
“Which areas of your office are considered physically sensitive?”
The organization should be able to identify them and explain why.
“Why is the network room restricted?”
The answer should connect the restriction to the criticality of the equipment and potential security impact.
“How do you protect sensitive information from being viewed by unauthorized people?”
The organization should explain room access, screen positioning, privacy controls and relevant procedures.
“How do you address fire, water and environmental risks?”
The answer should reflect the actual facility and risk assessment.
“What happens when maintenance personnel need access?”
The organization should have a defined process for authorization and supervision where appropriate.
“You work from a coworking facility. Who controls physical security?”
The organization should be able to explain the division of responsibility between itself and the facility provider.
Startup-Focused Quick Summary
A startup does not need to build a complex physical-security infrastructure to address A.7.3.
Start with:
1. Identify
Which rooms and facilities contain sensitive information or critical assets?
2. Assess
What could happen if the area were accessed, damaged or disrupted?
3. Classify
Which areas are public, general, restricted or highly restricted?
4. Protect
Use appropriate locks, access controls, secure storage and environmental safeguards.
5. Control Visitors
Prevent unnecessary access to sensitive areas.
6. Protect Equipment
Secure critical equipment rather than leaving it exposed.
7. Maintain
Make sure physical and environmental controls continue to work.
8. Review
Periodically inspect the facility and address weaknesses.
Simple Startup Principle
Secure the physical environment according to the value and risk of what it protects—not according to how expensive the security technology looks.
Startup-Focused Final Takeaway
A.7.3 is about making sure that offices, rooms and facilities are physically appropriate for the information and assets they contain.
A practical implementation is:
Identify sensitive areas → Assess risks → Classify areas → Apply appropriate protection → Control visitors and maintenance → Protect equipment → Manage environmental risks → Inspect → Improve
The key question is not:
“Does the company have locks?”
The better question is:
“Are our offices, rooms and facilities appropriately protected against the physical risks that could affect our information, people, equipment and business operations?”
For a startup, the best approach is usually simple, risk-based and evidence-driven rather than expensive or overly complicated.
