ISO/IEC 27001:2022 Annex A · Control 7.8
Equipment Siting and Protection: A Practical Implementation Guide
Place and protect equipment to reduce physical, environmental and observational risk.
This control concerns appropriate siting and protection of equipment from physical and environmental threats and unauthorized access.
What should the control achieve?
- Equipment placement reflects risk and manufacturer requirements.
- Unauthorized viewing and access are reduced.
- Power, cooling and environmental needs are supported.
- Portable and unattended equipment receive appropriate protection.
Step-by-step implementation
Inventory critical equipment
Identify servers, network devices, endpoints, printers, sensors and communications equipment.
Assess proposed locations
Consider public access, windows, liquids, dust, heat, vibration, theft and maintenance routes.
Apply physical protection
Use locked rooms, racks, anchors, privacy screens and protective enclosures.
Support safe operation
Provide ventilation, power conditioning and clear maintenance space.
Reduce disclosure
Orient screens and printers away from unauthorized observation.
Inspect and maintain
Review moves, damage, blocked ventilation and changed surroundings.
What this could look like in practice
Network switches are moved from an unlocked shared cupboard into a locked ventilated rack. Cables are protected, environmental alerts are enabled and access is limited to infrastructure staff.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Server equipment | Locked racks and controlled room protect critical devices. | Access and inspection |
| Reception screen | Display orientation and privacy filter prevent observation. | Workplace review |
| Portable device | Cable lock or secure storage applies in public areas. | Asset check |
| Printer | Sensitive printing device sits within controlled zone. | Site assessment |
Implementation evidence
- Equipment inventory
- Siting risk assessments
- Floor plans
- Rack and enclosure controls
- Environmental logs
- Manufacturer requirements
- Inspection records
- Move approvals
Useful metrics
- Critical equipment in approved locations
- Siting findings overdue
- Heat or power incidents
- Unsecured portable-equipment events
Common mistakes
- Placing network equipment in shared cupboards.
- Blocking airflow for physical concealment.
- Ignoring public viewing angles.
- Running critical cables through accessible spaces.
- Moving equipment without security review.
Questions an auditor may ask
- How are locations approved?
- What protects critical equipment?
- How are environmental requirements monitored?
- Show a recent equipment move review.
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.