Skip to content

What Is ISO 27001:2022 Annex A 7.3?

ISO 27001:2022 Annex A 7.3 outlines the requirement for constructing and executing physical security for offices, chambers and venues.

This control encourages organisations to put appropriate measures in place to safeguard against unauthorised access to rooms, offices and facilities, particularly when dealing with information security. Such measures may include locks, alarms, security guards, or other suitable means to protect against information security issues.

Physical Security for Offices, Rooms and Facilities Explained

Physical security is an essential component of information security. The two must be taken into account together. Information security is the safeguarding of data and systems from unauthorised access, use, disclosure, disruption, alteration or destruction.

Physical security involves taking measures to protect personnel, facilities, equipment and other assets from potential hazards, such as burglary, sabotage, terrorism and other criminal activities, by reducing the associated risks.

Determining if you have an information sensitive location is the initial step in physical security. These could be offices, rooms, or facilities with computers containing delicate data, or those with personnel granted access to delicate information.

Locks and Keys

Secure all doors, windows and cupboards; attach security seals to laptops and mobile devices; install password protection for computers; encrypt sensitive data.

CCTV

Closed-circuit cameras provide an efficient means of surveilling activity on the grounds or in particular regions of a structure.

Intruder Alarms

Motion, heat, or sound can trigger these alarms, which alert you to any intruders or unauthorised people in an area (e.g. a security alarm going off if someone attempts to break into the office).




ISMS.online gives you an 81% Headstart from the moment you log on

ISO 27001 made easy

We’ve done the hard work for you, giving you an 81% Headstart from the moment you log on. All you have to do is fill in the blanks.




What Is the Purpose of ISO 27001:2022 Annex A 7.3?

The goal of ISO 27001:2022 Annex A Control 7.3 is to protect the organisation’s information and other associated assets in offices, rooms, and facilities from unauthorised physical access, damage, and interference.

The primary objective of ISO 27001:2022 Annex A 7.3 is to reduce the risk of unauthorised physical access to offices, rooms, and facilities to an acceptable level by:

  • Preventing unauthorised individuals from entering offices, rooms, and facilities is essential. All personnel must be authorised before they can gain access.
  • Prevent harm or disruption to the organisation’s data and other related assets within workplace areas, rooms and facilities.
  • Ensure information security sensitive areas are discreet so that it is difficult to discern their purpose.
  • Minimising the chance of theft or property loss in offices, rooms, and facilities.
  • Ensure identification of personnel authorised for physical access via a combination of uniforms, electronic door entry systems, and visitor passes.
  • Where feasible, CCTV or other surveillance systems should be implemented to ensure security in vital areas such as doors/exits.

Annex A 7.3 pertains to all structures utilised by the organisation for offices or administrative operations. It also covers rooms in which confidential data is retained or processed, including areas where sensitive conversations occur.

This does not include reception areas or other public parts of an organisation’s premises, unless they are utilised for administrative purposes, such as when a reception area serves as an office.

What Is Involved and How to Meet the Requirements

Annex A 7.3 of ISO 27001:2022 stipulates that rooms and facilities must be safeguarded. To fulfil these requirements, the following security measures should be taken:

  • Locating critical facilities to prevent public access.
  • Ensure buildings are not intrusive and demonstrate minimal indication as to their purpose, with no clear signs either inside or outside the building that show information processing activities are taking place.
  • Set up systems to protect confidential data and activities from being heard or seen from the outside. Electromagnetic shielding may be necessary.
  • Make sure directories, internal phone books and online maps showing the whereabouts of confidential info processing facilities accessible to any unauthorised person.

For further details on reaching the control stipulated in the ISO 27001:2022 standard, consult the document.




climbing

Embed, expand and scale your compliance, without the mess. IO gives you the resilience and confidence to grow securely.




Changes and Differences from ISO 27001:2013

ISO 27001:2022 Annex A 7.3 replaces ISO 27001:2013 Annex A 11.1.3 in the revised 2022 standard.

Annex A 7.3 is not a novel control. It is a modified version of Annex A 11.1.3 in ISO 27001:2013. The most significant distinction between the 2013 and 2022 versions is the Annex A Control Number has been altered. Apart from this adjustment, the context and general meaning remain unchanged, despite the rephrasing.

The 2022 Annex A Control features an attributes table and statement of purpose, which are absent from the 2013 version.

Who Is in Charge of This Process?

The first person to consult when arranging offices, rooms, and facilities is usually the manager or director in charge of the building and its contents.

The security manager oversees security in all areas, including offices and facilities. He/She keeps tabs on all personnel with access to these areas and ensures their use is appropriate.

In certain instances, multiple people may be responsible for security. For example, where an individual has access to sensitive information that could be detrimental to the business or to other staff members’ private lives, it is essential to have several individuals involved in their security.

The HR department are responsible for employee insurance policies and benefits, while IT manage computer systems and networks. Both departments are involved in managing physical safety, as well as cyber security issues such as phishing scams and unauthorised access attempts.

Table of All ISO 27001:2022 Annex A Controls

In the table below you’ll find more information on each individual ISO 27001:2022 Annex A Control.

ISO 27001:2022 Organisational Controls
Annex A Control Type ISO/IEC 27001:2022 Annex A Identifier ISO/IEC 27001:2013 Annex A Identifier Annex A Name
Organisational Controls Annex A 5.1 Annex A 5.1.1
Annex A 5.1.2
Policies for Information Security
Organisational Controls Annex A 5.2 Annex A 6.1.1 Information Security Roles and Responsibilities
Organisational Controls Annex A 5.3 Annex A 6.1.2 Segregation of Duties
Organisational Controls Annex A 5.4 Annex A 7.2.1 Management Responsibilities
Organisational Controls Annex A 5.5 Annex A 6.1.3 Contact With Authorities
Organisational Controls Annex A 5.6 Annex A 6.1.4 Contact With Special Interest Groups
Organisational Controls Annex A 5.7 NEW Threat Intelligence
Organisational Controls Annex A 5.8 Annex A 6.1.5
Annex A 14.1.1
Information Security in Project Management
Organisational Controls Annex A 5.9 Annex A 8.1.1
Annex A 8.1.2
Inventory of Information and Other Associated Assets
Organisational Controls Annex A 5.10 Annex A 8.1.3
Annex A 8.2.3
Acceptable Use of Information and Other Associated Assets
Organisational Controls Annex A 5.11 Annex A 8.1.4 Return of Assets
Organisational Controls Annex A 5.12 Annex A 8.2.1 Classification of Information
Organisational Controls Annex A 5.13 Annex A 8.2.2 Labelling of Information
Organisational Controls Annex A 5.14 Annex A 13.2.1
Annex A 13.2.2
Annex A 13.2.3
Information Transfer
Organisational Controls Annex A 5.15 Annex A 9.1.1
Annex A 9.1.2
Access Control
Organisational Controls Annex A 5.16 Annex A 9.2.1 Identity Management
Organisational Controls Annex A 5.17 Annex A 9.2.4
Annex A 9.3.1
Annex A 9.4.3
Authentication Information
Organisational Controls Annex A 5.18 Annex A 9.2.2
Annex A 9.2.5
Annex A 9.2.6
Access Rights
Organisational Controls Annex A 5.19 Annex A 15.1.1 Information Security in Supplier Relationships
Organisational Controls Annex A 5.20 Annex A 15.1.2 Addressing Information Security Within Supplier Agreements
Organisational Controls Annex A 5.21 Annex A 15.1.3 Managing Information Security in the ICT Supply Chain
Organisational Controls Annex A 5.22 Annex A 15.2.1
Annex A 15.2.2
Monitoring, Review and Change Management of Supplier Services
Organisational Controls Annex A 5.23 NEW Information Security for Use of Cloud Services
Organisational Controls Annex A 5.24 Annex A 16.1.1 Information Security Incident Management Planning and Preparation
Organisational Controls Annex A 5.25 Annex A 16.1.4 Assessment and Decision on Information Security Events
Organisational Controls Annex A 5.26 Annex A 16.1.5 Response to Information Security Incidents
Organisational Controls Annex A 5.27 Annex A 16.1.6 Learning From Information Security Incidents
Organisational Controls Annex A 5.28 Annex A 16.1.7 Collection of Evidence
Organisational Controls Annex A 5.29 Annex A 17.1.1
Annex A 17.1.2
Annex A 17.1.3
Information Security During Disruption
Organisational Controls Annex A 5.30 NEW ICT Readiness for Business Continuity
Organisational Controls Annex A 5.31 Annex A 18.1.1
Annex A 18.1.5
Legal, Statutory, Regulatory and Contractual Requirements
Organisational Controls Annex A 5.32 Annex A 18.1.2 Intellectual Property Rights
Organisational Controls Annex A 5.33 Annex A 18.1.3 Protection of Records
Organisational Controls Annex A 5.34 Annex A 18.1.4 Privacy and Protection of PII
Organisational Controls Annex A 5.35 Annex A 18.2.1 Independent Review of Information Security
Organisational Controls Annex A 5.36 Annex A 18.2.2
Annex A 18.2.3
Compliance With Policies, Rules and Standards for Information Security
Organisational Controls Annex A 5.37 Annex A 12.1.1 Documented Operating Procedures
ISO 27001:2022 People Controls
Annex A Control Type ISO/IEC 27001:2022 Annex A Identifier ISO/IEC 27001:2013 Annex A Identifier Annex A Name
People Controls Annex A 6.1 Annex A 7.1.1 Screening
People Controls Annex A 6.2 Annex A 7.1.2 Terms and Conditions of Employment
People Controls Annex A 6.3 Annex A 7.2.2 Information Security Awareness, Education and Training
People Controls Annex A 6.4 Annex A 7.2.3 Disciplinary Process
People Controls Annex A 6.5 Annex A 7.3.1 Responsibilities After Termination or Change of Employment
People Controls Annex A 6.6 Annex A 13.2.4 Confidentiality or Non-Disclosure Agreements
People Controls Annex A 6.7 Annex A 6.2.2 Remote Working
People Controls Annex A 6.8 Annex A 16.1.2
Annex A 16.1.3
Information Security Event Reporting
ISO 27001:2022 Physical Controls
Annex A Control Type ISO/IEC 27001:2022 Annex A Identifier ISO/IEC 27001:2013 Annex A Identifier Annex A Name
Physical Controls Annex A 7.1 Annex A 11.1.1 Physical Security Perimeters
Physical Controls Annex A 7.2 Annex A 11.1.2
Annex A 11.1.6
Physical Entry
Physical Controls Annex A 7.3 Annex A 11.1.3 Securing Offices, Rooms and Facilities
Physical Controls Annex A 7.4 NEW Physical Security Monitoring
Physical Controls Annex A 7.5 Annex A 11.1.4 Protecting Against Physical and Environmental Threats
Physical Controls Annex A 7.6 Annex A 11.1.5 Working In Secure Areas
Physical Controls Annex A 7.7 Annex A 11.2.9 Clear Desk and Clear Screen
Physical Controls Annex A 7.8 Annex A 11.2.1 Equipment Siting and Protection
Physical Controls Annex A 7.9 Annex A 11.2.6 Security of Assets Off-Premises
Physical Controls Annex A 7.10 Annex A 8.3.1
Annex A 8.3.2
Annex A 8.3.3
Annex A 11.2.5
Storage Media
Physical Controls Annex A 7.11 Annex A 11.2.2 Supporting Utilities
Physical Controls Annex A 7.12 Annex A 11.2.3 Cabling Security
Physical Controls Annex A 7.13 Annex A 11.2.4 Equipment Maintenance
Physical Controls Annex A 7.14 Annex A 11.2.7 Secure Disposal or Re-Use of Equipment
ISO 27001:2022 Technological Controls
Annex A Control Type ISO/IEC 27001:2022 Annex A Identifier ISO/IEC 27001:2013 Annex A Identifier Annex A Name
Technological Controls Annex A 8.1 Annex A 6.2.1
Annex A 11.2.8
User Endpoint Devices
Technological Controls Annex A 8.2 Annex A 9.2.3 Privileged Access Rights
Technological Controls Annex A 8.3 Annex A 9.4.1 Information Access Restriction
Technological Controls Annex A 8.4 Annex A 9.4.5 Access to Source Code
Technological Controls Annex A 8.5 Annex A 9.4.2 Secure Authentication
Technological Controls Annex A 8.6 Annex A 12.1.3 Capacity Management
Technological Controls Annex A 8.7 Annex A 12.2.1 Protection Against Malware
Technological Controls Annex A 8.8 Annex A 12.6.1
Annex A 18.2.3
Management of Technical Vulnerabilities
Technological Controls Annex A 8.9 NEW Configuration Management
Technological Controls Annex A 8.10 NEW Information Deletion
Technological Controls Annex A 8.11 NEW Data Masking
Technological Controls Annex A 8.12 NEW Data Leakage Prevention
Technological Controls Annex A 8.13 Annex A 12.3.1 Information Backup
Technological Controls Annex A 8.14 Annex A 17.2.1 Redundancy of Information Processing Facilities
Technological Controls Annex A 8.15 Annex A 12.4.1
Annex A 12.4.2
Annex A 12.4.3
Logging
Technological Controls Annex A 8.16 NEW Monitoring Activities
Technological Controls Annex A 8.17 Annex A 12.4.4 Clock Synchronization
Technological Controls Annex A 8.18 Annex A 9.4.4 Use of Privileged Utility ProgramsAccess Rights
Technological Controls Annex A 8.19 Annex A 12.5.1
Annex A 12.6.2
Installation of Software on Operational Systems
Technological Controls Annex A 8.20 Annex A 13.1.1 Networks Security
Technological Controls Annex A 8.21 Annex A 13.1.2 Security of Network Services
Technological Controls Annex A 8.22 Annex A 13.1.3 Segregation of Networks
Technological Controls Annex A 8.23 NEW Web filtering
Technological Controls Annex A 8.24 Annex A 10.1.1
Annex A 10.1.2
Use of Cryptography
Technological Controls Annex A 8.25 Annex A 14.2.1 Secure Development Life Cycle
Technological Controls Annex A 8.26 Annex A 14.1.2
Annex A 14.1.3
Application Security Requirements
Technological Controls Annex A 8.27 Annex A 14.2.5 Secure System Architecture and Engineering PrinciplesLearning From Information Security Incidents
Technological Controls Annex A 8.28 NEW Secure Coding
Technological Controls Annex A 8.29 Annex A 14.2.8
Annex A 14.2.9
Security Testing in Development and Acceptance
Technological Controls Annex A 8.30 Annex A 14.2.7 Outsourced Development
Technological Controls Annex A 8.31 Annex A 12.1.4
Annex A 14.2.6
Separation of Development, Test and Production Environments
Technological Controls Annex A 8.32 Annex A 12.1.2
Annex A 14.2.2
Annex A 14.2.3
Annex A 14.2.4
Change Management
Technological Controls Annex A 8.33 Annex A 14.3.1 Test Information
Technological Controls Annex A 8.34 Annex A 12.7.1 Protection of Information Systems During Audit Testing

What Do These Changes Mean for You?

No significant modifications are necessary to conform to the most up-to-date version of ISO 27001:2022.

Evaluate your existing information security solution to make sure it meets the renewed standard. If you’ve modified anything since 2013 when the last edition was issued, consider reviewing those changes to decide if they’re still applicable or need to be revised.




[case_study_slider ids=”88859,101932,92016″ autoplay=”true” autoplay_speed=”5000″]


How ISMS.Online Help

Our platform is perfect for beginners in information security or those who want to quickly gain an understanding of ISO 27001:2022 without needing to invest time in studying from the beginning or reviewing long documents.

ISMS.online is kitted out with all the tools needed to meet compliance, including personalised document templates, checklists and policies.

Contact us now to schedule a demonstration.


Mike Jennings

Mike is the Integrated Management System (IMS) Manager here at ISMS.online. In addition to his day-to-day responsibilities of ensuring that the IMS security incident management, threat intelligence, corrective actions, risk assessments and audits are managed effectively and kept up to date, Mike is a certified lead auditor for ISO 27001 and continues to enhance his other skills in information security and privacy management standards and frameworks including Cyber Essentials, ISO 27001 and many more.

ISO 27001:2022 Annex A Controls

Organisational Controls