ISO 27002:2022
Physical controls – ISO 27002:2022

ISO 27002:2022 7.3: Securing offices, rooms and facilities

The organization is to design and implement physical protection for its offices, rooms and facilities. Purpose: keep intruders out of these spaces and protect the information and assets in them from harm or tampering. Guidance: consider locating critical facilities where the public cannot reach them; where relevant, keeping buildings unobtrusive with minimal indication of their purpose and no obvious signs inside or out that information processing takes place; arranging facilities so confidential information and activities cannot be seen or heard from outside, and considering electromagnetic shielding where appropriate; and keeping directories, internal phone lists and online maps that show where confidential processing facilities are located out of the hands of unauthorized people.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 44 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CMMC 2.0 · 4 controls

FedRAMP High · 4 controls

  • PE-13 Fire Protection
  • PE-2 Physical Access Authorizations
  • PE-3 Physical Access Control
  • PE-6 Monitoring Physical Access

FedRAMP Moderate · 4 controls

  • PE-13 Fire Protection
  • PE-2 Physical Access Authorizations
  • PE-3 Physical Access Control
  • PE-6 Monitoring Physical Access

NIST SP 800-53 Rev 5 · 4 controls

PCI DSS 4.0 · 4 controls

  • 9.2.1 9.2.1 Facility entry controls for CDE systems
  • 9.2.1.1 9.2.1.1 Monitoring of entry to sensitive areas
  • 9.3.1 9.3.1 Personnel physical access procedures for the CDE
  • 9.3.2 9.3.2 Visitor access procedures for the CDE
  • A.7.3 A.7.3 Design of controls and countermeasures (PPS design)
  • B.1.5 B.1.5 Crime prevention through environmental design (CPTED)
  • B.7.2.1 B.7.2.1 Security considerations for the command centre

HIPAA Security Rule · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

  • ISM-1053 Zoned rooms for classified infrastructure
  • ISM-1974 Securing non-classified server rooms

C5 (Germany) · 2 controls

  • C5-PS-01 Physical Security and Environmental Control Requirements
  • C5-PS-04 Physical site access control
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
  • NIST-CSF-PR.IR-02 The organization's technology assets are protected from environmental threats
  • ANSSI-HYG-26 Control and Protect Access to Server Rooms and Technical Areas

CIS Controls v8 · 1 control

  • CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work

ISO 27001:2022 · 1 control

  • 7.3 Securing offices, rooms and facilities

ISO 27701:2019 · 1 control

  • 8.2.7.C.01 8.2.7.C.01 Site Security Plan for each server and communications room

SOC 2 · 1 control

  • SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Physical controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 7.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 44 it maps to, and the evidence behind each claim, over MCP and REST.