ISO/IEC 27001:2022 Annex A · Control 7.6
Working in Secure Areas: A Practical Implementation Guide
Set clear working rules that preserve the protection of restricted physical areas.
This control concerns security measures for personnel and activities performed within secure areas.
What should the control achieve?
- Secure-area activities and behavior are defined.
- Access and work are limited to authorized need.
- Visitors and contractors are supervised.
- Recording, equipment and unattended work are controlled.
Step-by-step implementation
Define secure areas
Document purpose, owner, authorized roles and permitted activities.
Set entry and conduct rules
Address badges, tailgating, photography, phones, conversations and unattended doors.
Control third parties
Preauthorize work, verify identity, escort and inspect completion.
Manage equipment and materials
Approve introduction and removal of devices, tools, media and paper.
Protect lone and emergency work
Set check-in, safety, override and incident rules.
Monitor and review
Inspect logs, violations, changes and user understanding.
What this could look like in practice
A research lab prohibits personal cameras and removable media. Contractors submit work plans, receive temporary access and remain escorted. Equipment leaving the area requires owner authorization and inspection.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Authorized work | Access is limited to trained role holders. | Authorization list |
| Maintenance | Contractor tools and activities are logged and supervised. | Work permit |
| Equipment removal | Owner approves and Security records removal. | Removal form |
| Emergency | Safe egress and emergency responder access are defined. | Exercise result |
Implementation evidence
- Secure-area rules
- Authorized-person list
- Training records
- Visitor and contractor logs
- Work permits
- Equipment movement records
- Incident logs
- Inspection results
Useful metrics
- Secure-area violations
- Temporary access expired
- Unescorted visitor events
- Equipment removals with approval
Common mistakes
- Relying on signs without training.
- Allowing personal recording devices by default.
- Unsupervised maintenance.
- No control over items entering or leaving.
- Security rules that compromise emergency safety.
Questions an auditor may ask
- What behavior is required inside?
- How are contractors supervised?
- How is equipment removal controlled?
- How do emergency rules work?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.