ISO 27001A.7 — Physical security monitoring
A.7.4
Physical security monitoring
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Monitor sensitive areas continuously for unauthorized physical access as needed by risk.
Points of focus
- Monitoring needs based on risk
- Detection of unauthorized entry
- Response to physical alarms
- Privacy-aware retention of monitoring data
Implementation notes
Apply monitoring only where risk justifies it — many SaaS offices need badge logs more than full CCTV. Define who responds to alarms and how evidence is preserved (A.5.28). Respect workplace privacy laws for camera use. For cloud data centres, rely on provider assurance and document inheritance. Pair with A.7.1–A.7.3 physical design.
Audit tip: Show coverage of a sensitive area and a test or real alarm response record.
Evidence auditors typically request:
- Physical monitoring procedure
- Camera/alarm coverage description
- Alarm response tickets
- Retention settings for CCTV/access logs
Common gaps
- Cameras installed but never reviewed or tested
- No response path for after-hours alerts
- Monitoring PII retained indefinitely
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.7.4 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.7.4)
Frequently Asked Questions
No. Risk may be satisfied with badge logs and alarms. Justify the choice in the SoA.
Often limited office monitoring plus strong endpoint controls; document the rationale.
Keep long enough for investigations; avoid indefinite retention of biometric/video PII.