ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 4. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 7.8 Equipment siting and protection

ISO 27001 Annex A 7.8 Equipment siting and protection

What is ISO 27001 Annex A 7.8 – Equipment Siting and Protection?

ISO 27001 Annex A 7.8 focuses on protecting equipment from physical and environmental risks and positioning equipment in a way that reduces the possibility of unauthorized access, damage, interference, or disruption.

Equipment supporting information processing may include:

  • Servers
  • Network switches
  • Routers
  • Firewalls
  • Wireless access points
  • Storage devices
  • Desktop computers
  • Laptops
  • Printers
  • CCTV systems
  • Backup devices
  • UPS systems
  • Security appliances
  • Communication equipment
  • Specialized operational equipment

The organization should consider where equipment is located, what it is exposed to, and how it is physically protected.

Simple Explanation

Put important equipment in an appropriate location and protect it from the physical, environmental, and security risks around it.


Why is A.7.8 Important?

Information security is not only about protecting information logically.

Physical equipment can also be:

  • Stolen
  • Damaged
  • Tampered with
  • Disconnected
  • Overheated
  • Flooded
  • Exposed to dust
  • Damaged by power problems
  • Accidentally switched off
  • Accessed by unauthorized people

For example, a firewall sitting in an unlocked area may be physically accessible to people who should not be able to modify or disconnect it.

Similarly, a network switch installed directly below a leaking air-conditioning unit could be exposed to water damage.

Simple Principle

Critical equipment should be located and protected according to the risks that could affect its security or availability.


What Does ISO 27001 A.7.8 Require?

Organizations should consider the location and physical protection of equipment used for information processing.

Controls should address risks such as:

  • Unauthorized physical access
  • Theft
  • Tampering
  • Physical damage
  • Environmental conditions
  • Water leakage
  • Fire
  • Dust
  • Extreme temperature
  • Humidity
  • Power interruption
  • Electromagnetic interference
  • Physical interference
  • Accidental damage
  • Unauthorized viewing

The controls should be proportionate to the importance and risk of the equipment.

A small startup does not need a dedicated data center simply because it has an ISO 27001 ISMS.


A.7.8 vs A.7.5 – What is the Difference?

These controls are related but focus on different things.

ControlMain Focus
A.7.5 Physical and Environmental ThreatsProtect against physical/environmental threats
A.7.8 Equipment Siting and ProtectionPosition and physically protect equipment against those risks

Example

A company identifies water leakage as a risk.

A.7.5 may require the organization to address water leakage as an environmental threat.

A.7.8 may require network equipment not to be positioned directly underneath a water pipe or air-conditioning drain.


Activities Required to Implement A.7.8

1. Identify Information-Processing Equipment

Create an inventory of relevant equipment.

Examples:

  • Servers
  • Network equipment
  • Security appliances
  • Storage devices
  • Backup systems
  • Workstations
  • Printers
  • Wireless access points
  • UPS
  • Communication equipment

This should connect with A.5.9 – Inventory of Information and Other Associated Assets.


2. Identify Critical Equipment

Not every device requires the same level of protection.

Classify equipment based on:

  • Business criticality
  • Information processed
  • Availability requirements
  • Confidentiality requirements
  • Integrity requirements
  • Replacement difficulty
  • Dependency on other systems
  • Recovery requirements

Example

EquipmentCriticalityProtection
Core firewallHighRestricted network room
Core switchHighRestricted network room
Employee laptopMediumEndpoint controls + physical protection
Office printerMediumControlled location
Spare keyboardLowNormal storage

3. Assess Equipment Location

The organization should consider whether the equipment is positioned appropriately.

Questions include:

  • Is the equipment accessible to unauthorized people?
  • Is it visible from public areas?
  • Is it near water sources?
  • Is it exposed to excessive heat?
  • Is it exposed to dust?
  • Is it vulnerable to physical impact?
  • Is it located near electrical hazards?
  • Is it protected against unauthorized removal?
  • Is it exposed to unstable environmental conditions?
  • Could someone accidentally disconnect it?

4. Protect Equipment Against Unauthorized Access

Critical equipment should be placed in appropriately restricted areas.

Possible controls include:

  • Locked network rooms
  • Locked cabinets
  • Server racks
  • Access-controlled rooms
  • Security cages
  • Tamper-evident controls
  • Physical access monitoring
  • Restricted maintenance access

The level of protection should reflect the risk.


5. Protect Equipment Against Physical Damage

Equipment should be positioned to reduce accidental or deliberate damage.

Examples:

  • Keep network equipment away from high-traffic walkways.
  • Secure racks and cabinets.
  • Prevent cables from becoming trip hazards.
  • Protect equipment from accidental impact.
  • Avoid placing equipment where it can easily be knocked over.
  • Secure portable equipment when unattended.

6. Protect Against Water and Environmental Risks

Equipment should not be unnecessarily exposed to:

  • Water pipes
  • Air-conditioning leaks
  • Flooding
  • Roof leakage
  • Humidity
  • Condensation

For example, placing a server rack directly below a water pipe creates an avoidable risk.

Where relevant, organizations may use:

  • Water detection
  • Raised equipment
  • Appropriate drainage
  • Environmental monitoring
  • Suitable room design
  • Preventive maintenance

7. Protect Against Temperature and Humidity

Some equipment may require controlled environmental conditions.

Organizations should consider:

  • Temperature
  • Humidity
  • Cooling
  • Ventilation
  • Airflow
  • Dust

For critical equipment, environmental monitoring may be appropriate.

However, organizations should avoid implementing expensive monitoring where the risk does not justify it.


8. Protect Against Power Problems

Equipment may be affected by:

  • Power failure
  • Voltage fluctuation
  • Electrical surge
  • Unexpected shutdown
  • Poor-quality power supply

Depending on the risk, controls may include:

  • UPS
  • Surge protection
  • Backup power
  • Redundant power supplies
  • Generator
  • Power monitoring

The requirements should reflect equipment criticality.


9. Protect Against Electromagnetic and Other Interference

Where relevant, equipment may need protection from interference that could affect operation.

This is particularly relevant for specialized or sensitive environments.

Organizations should consider whether electromagnetic interference, signal interference or other physical interference represents a realistic risk.

Do not introduce unnecessary controls simply because the control exists in a standard.


10. Protect Cables and Connections

Cables can be damaged, disconnected, or tampered with.

Where appropriate:

  • Protect network cables
  • Protect power cables
  • Separate critical cables
  • Secure connections
  • Avoid exposed cables in public areas
  • Label connections where useful
  • Protect network distribution points

For critical infrastructure, physical cable protection can become particularly important.


11. Consider Equipment Visibility

Equipment may reveal useful information to unauthorized people.

For example:

A publicly visible network rack may expose:

  • Network architecture
  • Equipment models
  • Cable connections
  • Security devices
  • Infrastructure information

Where appropriate, equipment should be located away from public observation.


12. Consider Portable Equipment

A.7.8 also has practical relevance to laptops and other portable equipment.

Organizations should consider:

  • Secure storage
  • Physical locking where appropriate
  • Protection during transport
  • Avoiding unattended equipment
  • Encryption
  • Screen locking
  • Asset identification
  • Reporting loss or theft

This should work together with:

  • A.5.9 Asset Inventory
  • A.6.7 Remote Working
  • A.7.9 Security of Assets Off-Premises
  • A.8.1 User Endpoint Devices

Startup Example – SaaS Company

Consider a 35-person SaaS company.

The company does not operate a data center.

Its infrastructure includes:

  • Cloud-hosted production environment
  • Firewall
  • Network switch
  • Wi-Fi equipment
  • Office laptops
  • Backup devices
  • UPS
  • Small network room

The company identifies the network room as a restricted area.

Risks

  • Unauthorized access
  • Equipment tampering
  • Accidental disconnection
  • Power failure
  • Heat
  • Water leakage
  • Equipment theft

Controls

The company:

  • Places network equipment in a locked room.
  • Restricts physical access.
  • Uses a UPS for critical network equipment.
  • Keeps equipment away from water sources.
  • Maintains appropriate ventilation.
  • Secures network racks.
  • Protects cables.
  • Reviews physical access periodically.
  • Maintains equipment inventory.

Simple Flow

Identify Equipment

↓

Assess Criticality

↓

Assess Location

↓

Identify Physical Risks

↓

Apply Protection

↓

Monitor/Maintain

↓

Review


Cloud-First Startup Example

A startup may ask:

“Our production systems are hosted in AWS. What equipment do we need to protect?”

The organization should distinguish between:

Equipment it operates

Examples:

  • Employee laptops
  • Office network equipment
  • Firewall
  • Wi-Fi equipment
  • Local backup devices
  • Printers

and:

Infrastructure operated by the cloud provider

Examples:

  • Cloud servers
  • Physical storage infrastructure
  • Data center power
  • Data center cooling
  • Physical data center security

For cloud infrastructure, the organization should understand the provider’s responsibilities and obtain appropriate assurance.

This can include reviewing:

  • SOC reports
  • ISO certifications
  • Security documentation
  • Supplier assessments
  • Contractual commitments

The organization should not claim direct physical control over a cloud provider’s data center if it does not have that control.


Equipment Siting Assessment

A simple assessment can be maintained.

EquipmentLocationCriticalityKey RiskProtection
FirewallNetwork RoomHighUnauthorized accessLocked room
Core SwitchNetwork RoomHighTamperingRestricted access
UPSNetwork RoomHighPower failureUPS maintenance
Wi-Fi APOffice ceilingMediumTamperingControlled physical access
LaptopEmployee workspaceMediumTheftEndpoint + physical security
PrinterOfficeMediumInformation exposureControlled location

Equipment Protection Risk Assessment

RiskImpactExisting ControlAdditional Action
Unauthorized accessHighLocked roomPeriodic access review
Water leakageHighEquipment locationInspection
Power failureHighUPSUPS testing
OverheatingMediumAir conditioningMaintenance
TheftHighRestricted roomAsset tracking
Accidental damageMediumRack/cabinetPhysical inspection
Cable disconnectionMediumProtected cablingReview

Equipment Maintenance

Physical protection is not only about where equipment is placed.

Equipment should also be appropriately maintained.

Depending on the environment, this may include:

  • Preventive maintenance
  • UPS testing
  • HVAC maintenance
  • Cleaning
  • Firmware/hardware maintenance
  • Cable inspection
  • Rack inspection
  • Environmental monitoring
  • Replacement of defective components

Maintenance activities should be performed by authorized personnel.


Third-Party Equipment

Organizations may have equipment belonging to:

  • Customers
  • Suppliers
  • Contractors
  • Managed service providers
  • Telecom providers
  • Security providers

The organization should determine who is responsible for protecting such equipment.

For example:

A telecom provider installs network equipment in the company’s office.

The company should clarify:

  • Physical location
  • Access responsibility
  • Maintenance responsibility
  • Security requirements
  • Incident reporting
  • Equipment removal
  • Supplier obligations

This can connect with A.5.19–A.5.22 supplier security controls.


Audit Evidence for A.7.8

An auditor may ask for evidence showing that equipment is appropriately located and protected.

Policies and Procedures

  • Physical Security Policy
  • Equipment Protection Procedure
  • Asset Management Policy
  • Physical Security Procedure
  • Environmental Protection Procedure

Registers

  • Asset Register
  • Equipment Inventory
  • Network Equipment Register
  • Physical Location Register
  • Critical Equipment Register

Operational Evidence

  • Physical security inspections
  • Equipment maintenance records
  • UPS maintenance/testing
  • HVAC maintenance
  • Environmental monitoring
  • Access logs
  • Physical access reviews
  • Incident records

Technical/Physical Evidence

Where appropriate:

  • Photographs of equipment locations
  • Rack/cabinet controls
  • Access-control records
  • UPS configuration
  • Environmental monitoring
  • Cable protection
  • Equipment labels

Photographs should be handled appropriately because they may themselves reveal sensitive infrastructure information.


Audit Checklist

An ISO 27001 auditor may ask:

Equipment Identification

  • Have relevant information-processing assets been identified?
  • Is equipment included in the asset inventory?
  • Have critical equipment items been identified?

Location

  • Is equipment located appropriately?
  • Is critical equipment protected from unauthorized access?
  • Is equipment protected from accidental damage?

Environmental Protection

  • Is equipment protected from water?
  • Is temperature appropriately managed?
  • Is humidity considered where relevant?
  • Is equipment protected from dust and other environmental risks?

Power

  • Are critical systems protected from power interruption?
  • Are UPS systems used where appropriate?
  • Are UPS systems maintained and tested?

Physical Protection

  • Are server/network rooms secured?
  • Are racks and cabinets protected?
  • Are cables protected?
  • Is equipment protected from unauthorized tampering?

Maintenance

  • Is equipment appropriately maintained?
  • Is maintenance performed by authorized personnel?
  • Are maintenance records retained where necessary?

Third Parties

  • Are supplier-owned devices appropriately protected?
  • Are physical responsibilities defined?

Common Mistakes in Implementing A.7.8

1. Thinking A.7.8 Only Applies to Servers

Equipment includes much more than servers.

It can include:

  • Network equipment
  • Laptops
  • Printers
  • Backup devices
  • Security appliances
  • Communication equipment

The organization should determine what is relevant based on its ISMS scope and risk assessment.


2. Putting Critical Equipment in an Open Office

A firewall or network switch should not normally be placed somewhere anyone can access it without restriction if doing so creates a meaningful risk.

Better approach:

Use an appropriately secured location.


3. Ignoring Water Risk

Organizations may carefully protect equipment from hackers while placing it directly below an air-conditioning drain.

Better approach:

Include physical and environmental risks in the equipment-location assessment.


4. Ignoring Power Problems

Unexpected power loss can cause:

  • Service interruption
  • Equipment shutdown
  • Data corruption
  • Hardware damage

Better approach:

Assess power requirements and implement appropriate protection.


5. No Maintenance Records

A company may have an UPS but cannot demonstrate that it works.

Better approach:

Maintain appropriate inspection, testing and maintenance records.


6. Poor Cable Management

Exposed or poorly managed cables can create:

  • Trip hazards
  • Accidental disconnection
  • Equipment outages
  • Tampering opportunities

Better approach:

Protect and manage critical cabling appropriately.


7. Overengineering

Not every laptop needs a physical security cage.

Not every office needs a data-center-grade environmental monitoring system.

Better approach:

Apply controls according to risk and equipment criticality.


Practical Startup Implementation Model

A startup can implement A.7.8 using nine practical steps.

1. Identify

Identify relevant information-processing equipment.

2. Classify

Determine equipment criticality.

3. Assess

Identify physical and environmental risks.

4. Locate

Select appropriate physical locations.

5. Protect

Implement physical and environmental controls.

6. Maintain

Perform appropriate maintenance and testing.

7. Monitor

Monitor relevant conditions and physical security events.

8. Review

Review equipment locations and protection periodically.

9. Improve

Update controls when equipment, office layout or risks change.

Simple Model

Identify → Classify → Assess → Locate → Protect → Maintain → Monitor → Review → Improve


Policy vs. Process vs. Evidence

ElementExample
PolicyCritical information-processing equipment must be located and protected according to identified risks.
ProcessEquipment location is assessed during deployment and periodically reviewed.
Technical/Physical ControlLocked room, rack, UPS, environmental controls, cable protection.
EvidenceAsset register, physical inspection, maintenance records, access logs and risk assessment.

Remember:

Having a locked network room is a control. Demonstrating why the network room is required, who can access it, how it is maintained and how it is reviewed provides stronger audit evidence.


Relationship With Other ISO 27001 Controls

A.7.8 works together with several other controls.

ControlRelationship
A.5.9 Inventory of AssetsIdentifies equipment requiring protection
A.5.10 Acceptable UseDefines appropriate use of equipment
A.5.11 Return of AssetsAddresses return of equipment
A.5.15 Access ControlSupports restriction of physical/logical access
A.5.18 Access RightsSupports authorization
A.6.5 Termination/ChangeHelps ensure equipment and access are managed during changes
A.6.7 Remote WorkingAddresses equipment used remotely
A.7.1 Physical Security PerimetersEstablishes protected physical boundaries
A.7.2 Physical Entry ControlsControls physical access
A.7.3 Offices, Rooms and FacilitiesProtects physical facilities
A.7.4 Physical Security MonitoringSupports detection of physical security events
A.7.5 Physical/Environmental ThreatsAddresses threats affecting equipment
A.7.6 Working in Secure AreasControls activities inside secure areas
A.7.7 Clear Desk/Clear ScreenPrevents information exposure around equipment/workspaces
A.7.9 Security of Assets Off-PremisesProtects equipment outside organizational premises
A.8.1 User Endpoint DevicesProtects user endpoint equipment
A.8.14 RedundancySupports availability of critical systems where applicable

A.7.8 vs A.7.9 – What is the Difference?

A.7.8 – Equipment Siting and Protection

Focus:

Where equipment is located and how it is physically protected.

Example:

A firewall is installed in a locked network room with appropriate environmental protection.

A.7.9 – Security of Assets Off-Premises

Focus:

How assets are protected when they are outside organizational premises.

Example:

An employee takes a company laptop to a customer site or works from home.

The two controls therefore address different physical environments.


Useful Resources and Draft Documents

Organizations implementing A.7.8 may create:

  1. Equipment Siting and Protection Policy
    [Insert Draft Document Link]
  2. Asset Management Policy
    [Insert Draft Document Link]
  3. Asset Register
    [Insert Draft Document Link]
  4. Critical Equipment Register
    [Insert Draft Document Link]
  5. Equipment Location Register
    [Insert Draft Document Link]
  6. Physical Equipment Risk Assessment
    [Insert Draft Document Link]
  7. Physical Security Inspection Checklist
    [Insert Draft Document Link]
  8. Equipment Maintenance Procedure
    [Insert Draft Document Link]
  9. UPS Maintenance Checklist
    [Insert Draft Document Link]
  10. Environmental Monitoring Register
    [Insert Draft Document Link]
  11. Network Room Access Register
    [Insert Draft Document Link]
  12. Equipment Relocation/Installation Checklist
    [Insert Draft Document Link]

Questions an Auditor May Ask

“How do you determine where critical equipment should be located?”

Show the equipment risk assessment and explain the factors considered.

“How is your network equipment protected?”

Demonstrate the physical location, access controls and environmental protections.

“How do you protect equipment against water?”

Explain the location assessment, physical controls and inspection/maintenance process.

“How do you protect critical equipment from power failure?”

Show UPS or other applicable controls and maintenance/testing evidence.

“Who can access the network room?”

Show the authorized access list and physical access records.

“How do you know the equipment is being maintained?”

Show maintenance records, inspection records and relevant service reports.

“What happens if equipment needs to be moved?”

Explain the authorization and risk assessment process.

“What about cloud infrastructure?”

Explain the shared-responsibility model and provide relevant cloud-provider assurance and supplier-management evidence.


Startup-Focused Quick Summary

For a typical cloud-first startup, A.7.8 can be relatively simple.

Identify

List important physical equipment.

Assess

Determine what could happen if the equipment is stolen, damaged, disconnected or exposed to environmental problems.

Protect

Use appropriate controls such as:

  • Locked rooms
  • Secure cabinets
  • UPS
  • Appropriate ventilation
  • Water-risk protection
  • Cable protection
  • Physical access control

Maintain

Keep critical equipment and supporting facilities maintained.

Review

Reassess when:

  • Office location changes
  • New equipment is installed
  • Infrastructure changes
  • Business requirements change
  • New physical risks appear

Startup-Focused Final Takeaway

ISO 27001 Annex A 7.8 is about making sure that the physical location and protection of equipment do not become a security or availability weakness.

A company can have excellent logical security and still experience an outage because:

  • A network switch was accidentally disconnected
  • A firewall was physically tampered with
  • A server overheated
  • Water damaged equipment
  • A power failure shut down critical infrastructure
  • A laptop was stolen
  • Critical cables were damaged

The practical approach is not to protect every device with the same level of control.

Instead:

Identify what matters, understand the physical risks, and protect equipment proportionately.

For a startup, the implementation sequence is:

Identify Equipment → Classify Criticality → Assess Location → Protect → Maintain → Monitor → Review → Improve

The objective is simple:

Put critical equipment in the right place, protect it from the right risks, and maintain evidence that the protection is working.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *