ISO 27001A.7 — Working in secure areas
A.7.6
Working in secure areas
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Design and use secure areas with appropriate entry controls and rules for working inside them.
Points of focus
- Define secure areas
- Control entry and escort visitors
- Rules for photography and devices
- Log access where proportionate
Implementation notes
If you have no on-prem secure areas beyond an office IDF, document that and inherit CSP physical security. Otherwise enforce badge + visitor rules and keep the closet locked. Assign a named owner in the SoA, tie operating evidence to secure area definition and floor plan, and sample the control during internal audit before Stage 2 fieldwork.
Audit tip: Tour or photo evidence of locked IDF plus badge reports. If fully cloud, show SoA exclusion with CSP inheritance.
Evidence auditors typically request:
- Secure area definition and floor plan
- Badge access configuration
- Visitor escort procedure
- Access logs for restricted rooms
Common gaps
- Server closet propped open
- No visitor escort
- Contractors left alone with network gear
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.7.6 | This control |
| SOC 2 | CC6.4 | Related SOC 2 themes (CC6.4) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.7.6)
Frequently Asked Questions
Usually no; secure areas are spaces with elevated protection for sensitive assets.
Only if risk assessment says so — most startups do not.
A.7.2 is physical entry controls broadly; A.7.6 focuses on behavior inside designated secure areas.
Even without owned data centers, working in secure areas still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with secure area definition and floor plan, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.