Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 7.4

Physical Security Monitoring: A Practical Implementation Guide

Detect, assess and respond to unauthorized physical access and suspicious activity.

This control concerns continuously monitoring premises for unauthorized physical access.

Practical interpretation: Cameras alone do not provide monitoring. Detection coverage, lawful operation, alert handling, evidence quality, retention and response must form an end-to-end process.

What should the control achieve?

  • Monitoring addresses defined physical threats.
  • Sensors and cameras cover relevant areas.
  • Alerts reach trained responders.
  • Recordings and logs are protected and retained appropriately.

Step-by-step implementation

1

Define monitoring objectives

Identify intrusion, tailgating, theft, tampering and after-hours activity to detect.

2

Design coverage

Use CCTV, door alarms, motion detection, guards and access-log correlation based on risk.

3

Address privacy and law

Document purpose, notices, access, retention and prohibited monitoring areas.

4

Configure alert response

Set thresholds, contacts, verification, escalation and emergency coordination.

5

Protect monitoring systems

Restrict administration, synchronize time and prevent evidence tampering.

6

Test and review

Verify image quality, blind spots, sensor function and responder performance.

What this could look like in practice

A warehouse combines door contacts, motion sensors, CCTV and guard response. Alarms create a ticket, the guard verifies the area and Security preserves relevant footage. Cameras avoid private areas and recordings expire automatically.

ActivityPractical implementationEvidence
Door alarmForced opening alerts on-duty security.Alarm record
CCTVCoverage supports entrances and asset zones.Camera test
Access anomalyAfter-hours badge use is correlated with video.Investigation record
Evidence requestAuthorized export is hashed and logged.Custody record

Implementation evidence

  • Monitoring risk assessment
  • Coverage map
  • Privacy assessment
  • System configuration
  • Alert procedures
  • Test records
  • Access logs
  • Retention and evidence exports

Useful metrics

  • Monitoring devices operational
  • Alerts acknowledged within target
  • Blind spots unresolved
  • Unauthorized access detected

Common mistakes

  • Recording without active alert response.
  • Placing cameras in inappropriate areas.
  • Keeping footage indefinitely.
  • Failing to synchronize access and video time.
  • Allowing installers unrestricted ongoing access.

Questions an auditor may ask

  • Which threats does monitoring address?
  • Who receives and verifies alerts?
  • How are recordings protected?
  • Show a recent functional test.
Implementation test: Trigger representative alarms and confirm detection, notification, verification, response, evidence and closure.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.