Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 7.8

Equipment Siting and Protection: A Practical Implementation Guide

Place and protect equipment to reduce physical, environmental and observational risk.

This control concerns appropriate siting and protection of equipment from physical and environmental threats and unauthorized access.

Practical interpretation: Equipment location affects theft, damage, observation, ventilation, maintenance and cable exposure. Protection should follow criticality and operating conditions.

What should the control achieve?

  • Equipment placement reflects risk and manufacturer requirements.
  • Unauthorized viewing and access are reduced.
  • Power, cooling and environmental needs are supported.
  • Portable and unattended equipment receive appropriate protection.

Step-by-step implementation

1

Inventory critical equipment

Identify servers, network devices, endpoints, printers, sensors and communications equipment.

2

Assess proposed locations

Consider public access, windows, liquids, dust, heat, vibration, theft and maintenance routes.

3

Apply physical protection

Use locked rooms, racks, anchors, privacy screens and protective enclosures.

4

Support safe operation

Provide ventilation, power conditioning and clear maintenance space.

5

Reduce disclosure

Orient screens and printers away from unauthorized observation.

6

Inspect and maintain

Review moves, damage, blocked ventilation and changed surroundings.

What this could look like in practice

Network switches are moved from an unlocked shared cupboard into a locked ventilated rack. Cables are protected, environmental alerts are enabled and access is limited to infrastructure staff.

ActivityPractical implementationEvidence
Server equipmentLocked racks and controlled room protect critical devices.Access and inspection
Reception screenDisplay orientation and privacy filter prevent observation.Workplace review
Portable deviceCable lock or secure storage applies in public areas.Asset check
PrinterSensitive printing device sits within controlled zone.Site assessment

Implementation evidence

  • Equipment inventory
  • Siting risk assessments
  • Floor plans
  • Rack and enclosure controls
  • Environmental logs
  • Manufacturer requirements
  • Inspection records
  • Move approvals

Useful metrics

  • Critical equipment in approved locations
  • Siting findings overdue
  • Heat or power incidents
  • Unsecured portable-equipment events

Common mistakes

  • Placing network equipment in shared cupboards.
  • Blocking airflow for physical concealment.
  • Ignoring public viewing angles.
  • Running critical cables through accessible spaces.
  • Moving equipment without security review.

Questions an auditor may ask

  • How are locations approved?
  • What protects critical equipment?
  • How are environmental requirements monitored?
  • Show a recent equipment move review.
Implementation test: Inspect critical and publicly accessible equipment and identify risks from access, observation, heat, liquids, power and maintenance.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.