Skip to content
compliancebase
ISO 27001A.7 — Physical security monitoring

A.7.4

Physical security monitoring

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Monitor sensitive areas continuously for unauthorized physical access as needed by risk.

Points of focus

  • Monitoring needs based on risk
  • Detection of unauthorized entry
  • Response to physical alarms
  • Privacy-aware retention of monitoring data

Implementation notes

Apply monitoring only where risk justifies it — many SaaS offices need badge logs more than full CCTV. Define who responds to alarms and how evidence is preserved (A.5.28). Respect workplace privacy laws for camera use. For cloud data centres, rely on provider assurance and document inheritance. Pair with A.7.1–A.7.3 physical design.

Audit tip: Show coverage of a sensitive area and a test or real alarm response record.

Evidence auditors typically request:

  • Physical monitoring procedure
  • Camera/alarm coverage description
  • Alarm response tickets
  • Retention settings for CCTV/access logs

Common gaps

  • Cameras installed but never reviewed or tested
  • No response path for after-hours alerts
  • Monitoring PII retained indefinitely

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.7.4This control

Primary sources

Frequently Asked Questions

No. Risk may be satisfied with badge logs and alarms. Justify the choice in the SoA.

Often limited office monitoring plus strong endpoint controls; document the rationale.

Keep long enough for investigations; avoid indefinite retention of biometric/video PII.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above