ISO 27002:2022 7.3: Securing offices, rooms and facilities
The organization is to design and implement physical protection for its offices, rooms and facilities. Purpose: keep intruders out of these spaces and protect the information and assets in them from harm or tampering. Guidance: consider locating critical facilities where the public cannot reach them; where relevant, keeping buildings unobtrusive with minimal indication of their purpose and no obvious signs inside or out that information processing takes place; arranging facilities so confidential information and activities cannot be seen or heard from outside, and considering electromagnetic shielding where appropriate; and keeping directories, internal phone lists and online maps that show where confidential processing facilities are located out of the hands of unauthorized people.
This control maps to 44 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 7.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.