Skip to content
compliancebase
ISO 27001A.7 — Equipment siting and protection

A.7.8

Equipment siting and protection

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Site and protect equipment to reduce risks from environmental threats and unauthorized access.

Points of focus

  • Locate equipment away from public access
  • Protect against water/heat where relevant
  • Cable and rack hygiene
  • Document cloud inheritance

Implementation notes

Keep networking gear in locked spaces. Avoid storing production backups on desktops. For cloud, rely on provider siting controls and document that in the SoA. Assign a named owner in the SoA, tie operating evidence to equipment placement standard, and sample the control during internal audit before Stage 2 fieldwork.

Audit tip: Show where in-scope physical equipment lives and how it is protected, or the CSP report you inherit.

Evidence auditors typically request:

  • Equipment placement standard
  • Photos or diagrams of IDF/rack
  • Environmental monitoring if used
  • CSP data center inheritance note

Common gaps

  • Router under reception desk
  • Servers in unlocked closet
  • Ignoring landlord water-risk for on-prem UPS

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.7.8This control
SOC 2CC6.4Related SOC 2 themes (CC6.4) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Endpoints are primarily A.8.1; A.7.8 targets facility-sited equipment.

No for typical SaaS offices.

Apply cage locks, remote hands procedures, and provider SLAs.

Even without owned data centers, equipment siting and protection still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with equipment placement standard, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above