Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 7.6

Working in Secure Areas: A Practical Implementation Guide

Set clear working rules that preserve the protection of restricted physical areas.

This control concerns security measures for personnel and activities performed within secure areas.

Practical interpretation: A strong door is ineffective if behavior inside exposes information or allows uncontrolled access. Rules should cover authorization, supervision, recording, equipment and emergencies.

What should the control achieve?

  • Secure-area activities and behavior are defined.
  • Access and work are limited to authorized need.
  • Visitors and contractors are supervised.
  • Recording, equipment and unattended work are controlled.

Step-by-step implementation

1

Define secure areas

Document purpose, owner, authorized roles and permitted activities.

2

Set entry and conduct rules

Address badges, tailgating, photography, phones, conversations and unattended doors.

3

Control third parties

Preauthorize work, verify identity, escort and inspect completion.

4

Manage equipment and materials

Approve introduction and removal of devices, tools, media and paper.

5

Protect lone and emergency work

Set check-in, safety, override and incident rules.

6

Monitor and review

Inspect logs, violations, changes and user understanding.

What this could look like in practice

A research lab prohibits personal cameras and removable media. Contractors submit work plans, receive temporary access and remain escorted. Equipment leaving the area requires owner authorization and inspection.

ActivityPractical implementationEvidence
Authorized workAccess is limited to trained role holders.Authorization list
MaintenanceContractor tools and activities are logged and supervised.Work permit
Equipment removalOwner approves and Security records removal.Removal form
EmergencySafe egress and emergency responder access are defined.Exercise result

Implementation evidence

  • Secure-area rules
  • Authorized-person list
  • Training records
  • Visitor and contractor logs
  • Work permits
  • Equipment movement records
  • Incident logs
  • Inspection results

Useful metrics

  • Secure-area violations
  • Temporary access expired
  • Unescorted visitor events
  • Equipment removals with approval

Common mistakes

  • Relying on signs without training.
  • Allowing personal recording devices by default.
  • Unsupervised maintenance.
  • No control over items entering or leaving.
  • Security rules that compromise emergency safety.

Questions an auditor may ask

  • What behavior is required inside?
  • How are contractors supervised?
  • How is equipment removal controlled?
  • How do emergency rules work?
Implementation test: Observe a normal work period and contractor visit and compare actual behavior with secure-area rules.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.