ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 4. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 7.4 Physical security monitoring

ISO 27001 Annex A 7.4 Physical security monitoring

What is ISO 27001 Annex A 7.4 – Physical Security Monitoring?

ISO 27001 Annex A 7.4 focuses on monitoring physical premises and areas where information and other associated assets are located.

The objective is to detect and respond to:

  • Unauthorized physical entry
  • Suspicious physical activity
  • Security breaches
  • Attempts to bypass physical controls
  • Physical security incidents
  • Other events that could threaten information and associated assets

Physical security monitoring can include:

  • CCTV
  • Security guards
  • Door access logs
  • Alarm systems
  • Intrusion detection
  • Security patrols
  • Visitor monitoring
  • Environmental monitoring where relevant
  • Monitoring of restricted areas

Simple Explanation

A.7.2 controls who can enter. A.7.4 helps the organization detect what is happening physically and identify potential security events.

A locked door provides a preventive control.

Monitoring provides a way to detect whether something suspicious or unauthorized is happening.


Why is A.7.4 Important?

Physical security controls can fail.

Examples:

  • Someone follows an employee through a secure door.
  • An access card is stolen.
  • A restricted door is forced open.
  • An unauthorized person enters behind a visitor.
  • Someone tampers with network equipment.
  • A camera detects suspicious activity.
  • A physical security alarm is triggered.

Without appropriate monitoring, an organization may not know that a physical security control has been bypassed.

Physical security monitoring can help with:

  • Early detection
  • Investigation
  • Incident response
  • Evidence collection
  • Deterrence
  • Access-control verification
  • Protection of critical assets

Simple Principle

If a physical area is important enough to protect, consider how you will know when that protection is being bypassed or a security event is occurring.


What Does A.7.4 Require?

Organizations should use appropriate monitoring mechanisms for their physical security environment.

The level of monitoring should be based on:

  • Risk
  • Sensitivity of information
  • Criticality of equipment
  • Location
  • Threat environment
  • Regulatory requirements
  • Contractual requirements
  • Business needs

This does not mean that every organization must install CCTV throughout its premises.

For some organizations, appropriate monitoring may include:

  • Door access logs
  • Reception controls
  • Security guards
  • Visitor registers
  • Periodic inspections
  • Building security systems
  • Alarm notifications

For a high-security facility, more extensive monitoring may be appropriate.


A.7.2 vs A.7.3 vs A.7.4

These controls work together.

ControlMain Question
A.7.1 Physical Security PerimetersWhere is the protected boundary?
A.7.2 Physical Entry ControlsWho is allowed to enter?
A.7.3 Securing Offices, Rooms and FacilitiesHow is the physical environment protected?
A.7.4 Physical Security MonitoringHow do we detect and monitor physical security events?

Example: Network Room

A.7.1

The network room is classified as a restricted physical area.

A.7.2

Only authorized IT personnel can enter.

A.7.3

The room is physically secured and appropriate environmental protections are applied.

A.7.4

Entry activity and relevant physical security events are monitored and investigated when necessary.


Activities Required to Implement A.7.4

1. Identify Areas Requiring Monitoring

Start with the organization’s physical security risk assessment.

Potential areas include:

  • Office entrances
  • Reception
  • Restricted rooms
  • Network rooms
  • Server rooms
  • Data centers
  • Equipment storage
  • Records rooms
  • Loading areas
  • Critical infrastructure areas

Not every location requires the same monitoring level.


2. Determine What Needs to Be Monitored

Monitoring should have a defined purpose.

Examples:

Unauthorized Entry

Monitor access to restricted areas.

Suspicious Activity

Identify unusual activity around sensitive areas.

Access-Control Events

Monitor:

  • Failed access attempts
  • Forced doors
  • Unusual access
  • After-hours access

Physical Security Equipment

Monitor relevant:

  • Alarms
  • Cameras
  • Access-control systems
  • Intrusion detection systems

3. Select Appropriate Monitoring Controls

Possible controls include:

Monitoring MethodExample Use
CCTVOffice entrances/restricted areas
Access logsRestricted rooms
Security guardBuilding entrance
Visitor registerVisitor tracking
Door alarmsCritical areas
Intrusion detectionHigh-risk facilities
Security patrolsLarge facilities
Periodic inspectionSmall offices
Environmental monitoringServer/equipment rooms

The appropriate combination depends on risk.


4. Monitor Access-Control Events

Where electronic physical access systems exist, organizations may review relevant events such as:

  • Successful access
  • Failed access
  • Access outside normal hours
  • Repeated failed attempts
  • Access-card use after employment termination
  • Unusual access patterns

For example:

A former employee’s card is used to attempt entry.

This should trigger appropriate investigation.


5. Monitor Restricted Areas

Highly sensitive areas may require additional monitoring.

Examples:

  • Server room
  • Network room
  • Data center
  • Security operations center
  • Backup media storage
  • Sensitive records room

Possible controls include:

  • CCTV
  • Door access logging
  • Alarm systems
  • Security patrols
  • Access alerts

Again, monitoring should be proportionate to risk.


6. Monitor Visitors

Visitor monitoring can help establish:

  • Who entered
  • Who they were visiting
  • When they entered
  • When they left
  • Whether they entered restricted areas

A visitor should not normally be able to move through sensitive areas without appropriate authorization.


7. Establish Alert and Escalation Procedures

Monitoring is useful only if someone knows what to do when something suspicious occurs.

Example:

Physical security alert → Initial review → Assess event → Escalate if required → Investigate → Respond → Record → Learn

Examples of escalation triggers:

  • Forced door
  • Unauthorized entry
  • Lost access card used
  • Suspicious activity
  • Physical tampering
  • Theft
  • Damage to equipment

This connects A.7.4 with the organization’s incident-management process.


8. Protect Monitoring Records

Monitoring information can itself be sensitive.

Examples:

  • CCTV recordings
  • Access logs
  • Visitor records
  • Security guard logs
  • Alarm records

The organization should consider:

  • Who can access records
  • How records are protected
  • Retention requirements
  • Privacy requirements
  • Secure deletion
  • Investigation requirements

Access should be limited to authorized personnel.


9. Define Retention Requirements

The organization should determine how long monitoring records need to be retained.

The appropriate period may depend on:

  • Legal requirements
  • Privacy requirements
  • Contractual requirements
  • Investigation needs
  • Business requirements
  • Storage limitations

The organization should avoid retaining personal surveillance data indefinitely without a defined purpose.


10. Test and Review Monitoring Controls

Monitoring systems can fail.

Examples:

  • Camera stops recording
  • Door sensor fails
  • Access logs stop updating
  • Alarm is disabled
  • Storage becomes full
  • Camera angle changes
  • Monitoring personnel stop reviewing alerts

Therefore, organizations should periodically verify that important monitoring mechanisms are functioning.


CCTV and ISO 27001

CCTV is one possible physical-security monitoring control.

It is not automatically mandatory for every ISO 27001-certified organization.

Whether CCTV is appropriate depends on factors such as:

  • Physical risk
  • Premises type
  • Asset sensitivity
  • Location
  • Threat environment
  • Customer requirements
  • Legal/privacy requirements

For example:

Small 10-Person Office

Potentially sufficient:

  • Building security
  • Controlled office entrance
  • Visitor process
  • Access cards
  • Periodic inspection

Data Center

Potentially appropriate:

  • CCTV
  • Access logs
  • Security personnel
  • Intrusion detection
  • Alarm monitoring
  • Restricted access

The controls should be justified through risk assessment.


Startup Example

Consider a 50-person SaaS startup operating from an office.

The organization has:

  • Main entrance
  • Reception
  • Employee workspace
  • HR/Finance room
  • Network room
  • Storage room

The startup implements:

Main Entrance

Building security and access control monitor entry.

Reception

Visitors are registered and linked to an employee host.

Network Room

Access is restricted and physical entry is logged.

Office

Appropriate security monitoring is provided through building controls and access management.

Security Events

A forced-door alert or suspicious physical activity is reported to the responsible security/facilities contact.

Investigation

If a physical security incident occurs, relevant access logs and available CCTV footage can be reviewed.

This provides a practical monitoring model without creating an unnecessarily complex surveillance environment.


Physical Security Monitoring Matrix

AreaAsset/RiskMonitoring MethodFrequencyResponsible Person
Main EntranceUnauthorized entryAccess system/building securityContinuousFacilities
ReceptionVisitor riskVisitor registerPer visitReception
HR RoomConfidential recordsAccess logsAs applicableHR/Facilities
Network RoomEquipment tamperingAccess logs/CCTV where appropriateContinuous/periodic reviewIT
Storage RoomEquipment theftRestricted access/inspectionPeriodicFacilities
Data CenterCritical infrastructureCCTV/access/alarmContinuousData Center Provider

Physical Security Monitoring Register

A simple register can document the monitoring controls.

AreaMonitoring ControlPurposeOwnerRecord GeneratedReview
Network RoomAccess logsDetect unauthorized entryITAccess logMonthly
Main EntranceCCTVDetect suspicious activityFacilitiesVideoAs required
ReceptionVisitor RegisterTrack visitorsReceptionVisitor recordPer visit
Storage RoomPeriodic inspectionDetect unauthorized accessFacilitiesInspection recordMonthly

Physical Security Event Workflow

A useful workflow is:

Detection

↓

Initial Assessment

↓

Security Event?

↓

Yes → Investigate / Escalate

↓

Incident?

↓

Activate Incident Response

↓

Collect Evidence

↓

Resolve

↓

Lessons Learned

This connects A.7.4 with:

  • A.5.24 Incident Management Planning and Preparation
  • A.5.25 Assessment and Decision on Information Security Events
  • A.5.26 Response to Information Security Incidents
  • A.5.27 Learning from Information Security Incidents
  • A.5.28 Collection of Evidence

Audit Evidence for A.7.4

An auditor may request:

Policies and Procedures

  • Physical Security Policy
  • Physical Security Monitoring Procedure
  • CCTV Policy, where applicable
  • Visitor Management Procedure
  • Physical Security Incident Procedure

Monitoring Records

  • Door access logs
  • CCTV records, where appropriate
  • Visitor registers
  • Security guard logs
  • Alarm records
  • Physical inspection records

System Evidence

  • Access-control reports
  • Camera system configuration
  • Alarm configuration
  • Monitoring dashboards
  • Alert records

Operational Evidence

  • Physical security alerts
  • Investigation records
  • Physical security incidents
  • Corrective actions
  • Periodic monitoring reviews
  • Monitoring-system testing

Third-Party Evidence

Where monitoring is provided by a building or facility provider:

  • Facility security documentation
  • Service agreements
  • Security procedures
  • Relevant certifications or assurance reports
  • Supplier assessments

Audit Checklist for A.7.4

An auditor may ask:

Monitoring Scope

  • Which physical areas are monitored?
  • Why were those areas selected?
  • Is the monitoring based on a risk assessment?

Monitoring Methods

  • Do you use CCTV?
  • Do you use access logs?
  • Are alarms used?
  • How are visitors monitored?

Alerts

  • What happens when a physical security alert occurs?
  • Who reviews alerts?
  • How are unauthorized entry attempts handled?

Records

  • What monitoring records are maintained?
  • Who can access them?
  • How long are they retained?
  • How are records protected?

System Reliability

  • How do you know your monitoring controls are working?
  • Are cameras or access-control systems periodically tested?
  • What happens when a monitoring system fails?

Incidents

  • Can you provide an example of a physical security event?
  • How was it investigated?
  • Was evidence preserved?

Common Mistakes

1. Assuming CCTV Is Mandatory

ISO 27001 does not mean every organization must install CCTV.

The organization should select controls based on risk.


2. Installing Cameras but Never Reviewing Them

A camera that records continuously may have limited value if nobody can access or review footage when a security event occurs.


3. No Alert or Escalation Process

Monitoring without a response process creates a gap.

The organization should define:

What is monitored → What is an alert → Who receives it → What happens next


4. Ignoring Access Logs

Physical access systems can generate useful evidence.

Organizations should determine whether relevant access events need monitoring or periodic review.


5. Keeping Monitoring Data Forever

CCTV and access records may contain personal information.

Retention should have a defined purpose and comply with applicable requirements.


6. Giving Too Many People Access to CCTV

Surveillance records can be sensitive.

Access should be restricted to authorized personnel.


7. Forgetting Monitoring-System Failures

A broken camera or disabled alarm can create a security gap.

Monitoring controls themselves should be maintained and tested where appropriate.


8. No Evidence of Actual Operation

Having a CCTV policy is not enough.

An auditor may want evidence that:

  • Monitoring is implemented
  • Relevant logs exist
  • Alerts are handled
  • Systems are maintained
  • Security events are investigated

Privacy Considerations for CCTV and Monitoring

Physical monitoring may involve personal information.

For example:

  • CCTV footage
  • Visitor records
  • Access-card records
  • Security logs

Organizations should consider applicable privacy and data-protection requirements when implementing monitoring.

Depending on the jurisdiction and circumstances, this may involve:

  • Clearly defined purpose
  • Appropriate notice
  • Limited access
  • Appropriate retention
  • Protection against unauthorized disclosure
  • Secure deletion
  • Handling of data-subject rights where applicable

The objective should be:

Monitor what is necessary for security without collecting or retaining unnecessary personal information.


Practical Startup Implementation Model

A startup can implement A.7.4 using this lifecycle:

Identify → Assess → Select → Monitor → Alert → Investigate → Record → Review → Improve

Identify

Identify physical areas and assets requiring monitoring.

Assess

Evaluate the physical security risks.

Select

Choose appropriate monitoring mechanisms.

Monitor

Operate the controls.

Alert

Identify suspicious or unauthorized activity.

Investigate

Assess and investigate relevant events.

Record

Maintain appropriate evidence.

Review

Periodically review monitoring effectiveness.

Improve

Address weaknesses and lessons learned.


Policy vs. Process vs. Evidence

ElementExample
PolicyPhysical Security Monitoring Policy
ProcessPhysical Security Event Monitoring Process
ProcedureCCTV Review Procedure
ControlAccess logging
SystemCCTV/access-control system
RecordDoor access log
EventFailed access attempt
EvidenceInvestigation record
ReviewPeriodic monitoring review

Important Distinction

Monitoring is not the same as recording.

A system may generate a log or video recording, but the organization should determine how relevant security events are detected, assessed and handled.


Relationship With Other ISO 27001 Controls

A.7.4 connects with:

  • A.5.7 – Threat intelligence
  • A.5.15 – Access control
  • A.5.16 – Identity management
  • A.5.18 – Access rights
  • A.5.24 – Information security incident management planning and preparation
  • A.5.25 – Assessment and decision on information security events
  • A.5.26 – Response to information security incidents
  • A.5.27 – Learning from information security incidents
  • A.5.28 – Collection of evidence
  • A.6.8 – Information security event reporting
  • A.7.1 – Physical security perimeters
  • A.7.2 – Physical entry controls
  • A.7.3 – Securing offices, rooms and facilities
  • A.7.5 – Protecting against physical and environmental threats
  • A.7.6 – Working in secure areas
  • A.7.7 – Clear desk and clear screen
  • A.7.9 – Security of assets off-premises

Simple Relationship

A.7.2

Controls physical entry.

↓

A.7.3

Protects the physical environment.

↓

A.7.4

Monitors relevant physical security activity.

↓

A.5.25

Assesses security events.

↓

A.5.26

Responds to confirmed incidents.


Useful Resources and Draft Documents

Organizations implementing A.7.4 may consider creating:

  1. Physical Security Monitoring Policy
    [Insert Draft Document Link]
  2. Physical Security Monitoring Procedure
    [Insert Draft Document Link]
  3. CCTV Policy
    [Insert Draft Document Link]
  4. CCTV Monitoring and Review Procedure
    [Insert Draft Document Link]
  5. Physical Security Monitoring Register
    [Insert Draft Document Link]
  6. Physical Security Event Report
    [Insert Draft Document Link]
  7. Physical Security Incident Report
    [Insert Draft Document Link]
  8. Physical Access Log Review Checklist
    [Insert Draft Document Link]
  9. Physical Security Inspection Checklist
    [Insert Draft Document Link]
  10. CCTV Access Authorization Register
    [Insert Draft Document Link]
  11. Physical Monitoring System Testing Checklist
    [Insert Draft Document Link]
  12. Physical Security Monitoring Risk Assessment
    [Insert Draft Document Link]

Questions an Auditor May Ask Management

“What physical areas do you monitor and why?”

The answer should be linked to the organization’s physical security risk assessment.

“Do you use CCTV?”

If yes, explain its purpose and controls. If no, explain the alternative monitoring mechanisms and risk-based rationale.

“How do you detect unauthorized physical entry?”

The organization should explain access controls, logs, reception, guards, alarms or other relevant mechanisms.

“What happens when a physical security alert occurs?”

There should be a defined assessment and escalation process.

“Who can access CCTV or physical security records?”

Access should be restricted to authorized personnel.

“How long do you retain physical monitoring records?”

The organization should have a defined retention approach appropriate to legal, privacy, contractual and operational requirements.

“How do you know your monitoring system is working?”

The organization should be able to demonstrate testing, maintenance or monitoring of the relevant controls.


Startup-Focused Quick Summary

For most startups, A.7.4 can be implemented without building a sophisticated security operations center.

Start with:

1. Identify

Determine which physical areas require monitoring.

2. Assess

Understand the risks and potential consequences.

3. Select

Choose appropriate controls such as:

  • Access logs
  • Visitor records
  • CCTV where justified
  • Building security
  • Alarms
  • Periodic inspections

4. Monitor

Operate the controls consistently.

5. Respond

Define what happens when suspicious activity is detected.

6. Protect Records

Restrict access to CCTV, logs and other monitoring information.

7. Review

Check whether monitoring remains effective.

8. Improve

Address incidents, failures and audit findings.

Simple Startup Principle

Don’t install monitoring technology just to show an auditor. Implement monitoring that helps you actually detect and respond to physical security risks.


Startup-Focused Final Takeaway

A.7.4 is about ensuring that physical security controls are not simply installed and forgotten.

The practical lifecycle is:

Identify risks → Select monitoring → Operate monitoring → Detect events → Assess → Respond → Preserve evidence → Review → Improve

For a startup, the key question is not:

“Do we have CCTV?”

It is:

“Can we detect relevant physical security events, determine what happened, and take appropriate action?”

A well-designed A.7.4 implementation should therefore connect physical monitoring, access control, incident management, evidence and privacy into one practical process.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *