ISO/IEC 27001:2022 Annex A · Control 7.12
Cabling Security: A Practical Implementation Guide
Protect power and data cabling from interception, interference, damage and unauthorized connection.
This control concerns protecting cables carrying power, data or supporting information services.
What should the control achieve?
- Critical cable routes and endpoints are known.
- Data and power paths receive suitable physical protection.
- Unauthorized connection and tampering are detectable.
- Changes and maintenance are controlled.
Step-by-step implementation
Map important cabling
Document risers, trays, entry points, patch rooms, external links and critical circuits.
Assess route threats
Consider public areas, shared tenants, construction, water, fire and electromagnetic sources.
Protect routes
Use conduits, locked rooms, protected trays, separation and diverse paths where justified.
Secure termination points
Lock cabinets, control patching and label without exposing unnecessary sensitive purpose.
Control work
Authorize installers, supervise access and verify changes.
Inspect and test
Check damage, unknown connections, cabinet access and path changes.
What this could look like in practice
A multi-tenant office routes network backbones through locked risers and keeps patch panels in controlled rooms. Critical links use diverse routes, and all patch changes require tickets and port documentation.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Backbone route | Locked riser and conduit protect shared-building path. | Route diagram |
| Patch panel | Restricted access and port records control connections. | Patch log |
| Power/data separation | Installation standard reduces interference and hazards. | Inspection record |
| Construction | Temporary work is supervised and circuits retested. | Work permit |
Implementation evidence
- Cable diagrams
- Installation standards
- Restricted-room access
- Patch records
- Contractor authorization
- Inspection results
- Link tests
- Change tickets
Useful metrics
- Unknown connections
- Cable findings overdue
- Critical links with diverse routes
- Unauthorized cabinet access
Common mistakes
- Leaving patch rooms unlocked.
- Using labels that reveal critical functions.
- Routing redundant links together.
- Ignoring shared risers and external handoff points.
- Allowing undocumented temporary cabling.
Questions an auditor may ask
- Where are critical cable routes?
- How are patch changes controlled?
- How is shared-building exposure managed?
- Show inspection after construction.
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.