Skip to content
compliancebase
ISO 27001A.7 — Cabling security

A.7.12

Cabling security

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Protect power and telecommunications cabling carrying information or supporting information services from interception, interference, or damage.

Points of focus

  • Secure cable routes in offices
  • Lock patch panels
  • Avoid public exposed drops
  • Document colo/CSP inheritance

Implementation notes

Keep patch panels in locked closets. Label cables. For cloud, inherit provider cabling controls. Do not run production admin networks through publicly accessible outlets. Assign a named owner in the SoA, tie operating evidence to cabling/idf standard, and sample the control during internal audit before Stage 2 fieldwork.

Audit tip: Show IDF lock and access list, or SoA exclusion with CSP evidence.

Evidence auditors typically request:

  • Cabling/IDF standard
  • Photos of locked patch panels
  • Visitor restrictions near IDF
  • CSP inheritance note

Common gaps

  • Patch panel in open hallway
  • Customer demo room with live production drops

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.7.12This control
SOC 2CC6.6Related SOC 2 themes (CC6.6) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Backhaul and controller placement matter; endpoint Wi-Fi security is more A.8.20–A.8.22.

Proportionate to risk — startups usually need locked IDFs, not SCIF-level conduit.

Avoid unmanaged switches; prefer structured cabling to managed access switches.

Even without owned data centers, cabling security still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with cabling/idf standard, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above