ISO/IEC 27001:2022 Annex A · Control 7.4
Physical Security Monitoring: A Practical Implementation Guide
Detect, assess and respond to unauthorized physical access and suspicious activity.
This control concerns continuously monitoring premises for unauthorized physical access.
What should the control achieve?
- Monitoring addresses defined physical threats.
- Sensors and cameras cover relevant areas.
- Alerts reach trained responders.
- Recordings and logs are protected and retained appropriately.
Step-by-step implementation
Define monitoring objectives
Identify intrusion, tailgating, theft, tampering and after-hours activity to detect.
Design coverage
Use CCTV, door alarms, motion detection, guards and access-log correlation based on risk.
Address privacy and law
Document purpose, notices, access, retention and prohibited monitoring areas.
Configure alert response
Set thresholds, contacts, verification, escalation and emergency coordination.
Protect monitoring systems
Restrict administration, synchronize time and prevent evidence tampering.
Test and review
Verify image quality, blind spots, sensor function and responder performance.
What this could look like in practice
A warehouse combines door contacts, motion sensors, CCTV and guard response. Alarms create a ticket, the guard verifies the area and Security preserves relevant footage. Cameras avoid private areas and recordings expire automatically.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Door alarm | Forced opening alerts on-duty security. | Alarm record |
| CCTV | Coverage supports entrances and asset zones. | Camera test |
| Access anomaly | After-hours badge use is correlated with video. | Investigation record |
| Evidence request | Authorized export is hashed and logged. | Custody record |
Implementation evidence
- Monitoring risk assessment
- Coverage map
- Privacy assessment
- System configuration
- Alert procedures
- Test records
- Access logs
- Retention and evidence exports
Useful metrics
- Monitoring devices operational
- Alerts acknowledged within target
- Blind spots unresolved
- Unauthorized access detected
Common mistakes
- Recording without active alert response.
- Placing cameras in inappropriate areas.
- Keeping footage indefinitely.
- Failing to synchronize access and video time.
- Allowing installers unrestricted ongoing access.
Questions an auditor may ask
- Which threats does monitoring address?
- Who receives and verifies alerts?
- How are recordings protected?
- Show a recent functional test.
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.