Skip to content
compliancebase
ISO 27001A.7 — Working in secure areas

A.7.6

Working in secure areas

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Design and use secure areas with appropriate entry controls and rules for working inside them.

Points of focus

  • Define secure areas
  • Control entry and escort visitors
  • Rules for photography and devices
  • Log access where proportionate

Implementation notes

If you have no on-prem secure areas beyond an office IDF, document that and inherit CSP physical security. Otherwise enforce badge + visitor rules and keep the closet locked. Assign a named owner in the SoA, tie operating evidence to secure area definition and floor plan, and sample the control during internal audit before Stage 2 fieldwork.

Audit tip: Tour or photo evidence of locked IDF plus badge reports. If fully cloud, show SoA exclusion with CSP inheritance.

Evidence auditors typically request:

  • Secure area definition and floor plan
  • Badge access configuration
  • Visitor escort procedure
  • Access logs for restricted rooms

Common gaps

  • Server closet propped open
  • No visitor escort
  • Contractors left alone with network gear

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.7.6This control
SOC 2CC6.4Related SOC 2 themes (CC6.4) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Usually no; secure areas are spaces with elevated protection for sensitive assets.

Only if risk assessment says so — most startups do not.

A.7.2 is physical entry controls broadly; A.7.6 focuses on behavior inside designated secure areas.

Even without owned data centers, working in secure areas still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with secure area definition and floor plan, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above