ISO/IEC 27001:2022 Annex A · Control 7.3
Securing Offices, Rooms and Facilities: A Practical Implementation Guide
Protect working areas and facilities according to the information, equipment and activities they contain.
This control concerns designing and applying physical security for offices, rooms and facilities.
What should the control achieve?
- Locations are risk assessed and appropriately designed.
- Sensitive rooms receive additional protection.
- Layouts reduce unauthorized observation and access.
- Security remains effective during normal and exceptional use.
Step-by-step implementation
Classify spaces
Identify public, general work, confidential meeting, storage, network and critical-equipment areas.
Assess location risk
Consider neighborhood, shared tenancy, ground-floor exposure, utilities and emergency response.
Apply room controls
Use locks, access control, window protection, acoustic privacy and secure storage.
Design discreetly
Avoid unnecessary signs and external visibility of sensitive activities.
Set operating rules
Control unattended rooms, meetings, deliveries, cleaning and after-hours use.
Inspect changes
Review moves, renovations, new tenants and altered use.
What this could look like in practice
A legal office positions client meeting rooms away from open workspaces, uses acoustic protection and privacy film, and keeps file rooms badge-controlled. Cleaners access offices only during supervised windows.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Confidential room | Acoustic privacy and controlled entry protect discussions. | Room assessment |
| File room | Restricted badge profile and locked cabinets are used. | Access log |
| Shared facility | Landlord and tenant responsibilities are documented. | Facility agreement |
| Renovation | Security review precedes layout change. | Design approval |
Implementation evidence
- Facility risk assessments
- Floor and zone plans
- Room-control standards
- Access lists
- Shared-premises agreement
- Inspection checklists
- Renovation reviews
- Maintenance records
Useful metrics
- Sensitive rooms meeting baseline
- Facility findings overdue
- Unauthorized room access
- Security reviews before moves
Common mistakes
- Advertising critical room locations.
- Using meeting rooms with poor acoustic privacy.
- Allowing unrestricted cleaning access.
- Storing sensitive records in general areas.
- Ignoring temporary construction openings.
Questions an auditor may ask
- How are rooms classified?
- Which controls protect sensitive work?
- How are shared facilities governed?
- Show a security review of a move or renovation.
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.