ISO 27001A.7 — Securing offices, rooms and facilities
A.7.3
Securing offices, rooms and facilities
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Design and configure physical security for offices, rooms, and facilities to protect information and assets.
Points of focus
- Sensitive rooms identified
- Physical protections proportionate to risk
- Visitor and delivery paths considered
- Cloud/office shared-responsibility documented
Implementation notes
Inventory spaces that hold sensitive assets (AV closets, badge printers, executive areas). Apply locks, badge readers, and clear desk expectations proportionate to risk. For cloud-native SaaS with tiny offices, document residual controls and provider inheritance honestly in the SoA. Link to A.7.1/A.7.2 perimeters and entry.
Audit tip: If you have an office, show how visitors reach meeting rooms without entering secure areas unescorted.
Evidence auditors typically request:
- Facility security description
- Badge zoning diagram or photos
- Visitor procedure for offices
- SoA note for cloud-inherited physical controls
Common gaps
- Network closets unlocked in open offices
- SoA silent on residual office risk for remote-first companies
- Delivery drop zones expose devices
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.7.3 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.7.3)
Frequently Asked Questions
Possibly, with risk-based SoA rationale covering home working (often A.6.7) and cloud facilities.
Treat as facilities with limited control — minimise local sensitive assets and rely on endpoint/crypto controls.
Overlaps CC6.4 themes; reuse facility descriptions carefully across programs.