Skip to content
compliancebase
ISO 27001A.7 — Securing offices, rooms and facilities

A.7.3

Securing offices, rooms and facilities

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Design and configure physical security for offices, rooms, and facilities to protect information and assets.

Points of focus

  • Sensitive rooms identified
  • Physical protections proportionate to risk
  • Visitor and delivery paths considered
  • Cloud/office shared-responsibility documented

Implementation notes

Inventory spaces that hold sensitive assets (AV closets, badge printers, executive areas). Apply locks, badge readers, and clear desk expectations proportionate to risk. For cloud-native SaaS with tiny offices, document residual controls and provider inheritance honestly in the SoA. Link to A.7.1/A.7.2 perimeters and entry.

Audit tip: If you have an office, show how visitors reach meeting rooms without entering secure areas unescorted.

Evidence auditors typically request:

  • Facility security description
  • Badge zoning diagram or photos
  • Visitor procedure for offices
  • SoA note for cloud-inherited physical controls

Common gaps

  • Network closets unlocked in open offices
  • SoA silent on residual office risk for remote-first companies
  • Delivery drop zones expose devices

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.7.3This control

Primary sources

Frequently Asked Questions

Possibly, with risk-based SoA rationale covering home working (often A.6.7) and cloud facilities.

Treat as facilities with limited control — minimise local sensitive assets and rely on endpoint/crypto controls.

Overlaps CC6.4 themes; reuse facility descriptions carefully across programs.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above