ISO 27001 Equipment Siting and Protection Explained – Annex A 7.8

Stuart Barker -271

ISO 27001 Annex A 7.8 requires placing hardware safely to prevent physical hazards and stop viewing by unapproved people. Organisations must record device locations and build safety checks into daily office planning.

Key Takeaways

  • Position hardware to block visual access: Place monitors, control units, and printers away from windows or visitor areas to prevent screen viewing and shoulder surfing.
  • Protect hardware from environmental threats: Keep critical equipment safe from water leaks, heat, dust, and direct sunlight by avoiding areas near windows or pipes.
  • Track asset locations continuously: Record the exact physical placement of all equipment in a central asset log to keep location tracking accurate.
  • Embed siting into change workflows: Include physical placement security checks in office change plans before moving hardware to new areas.
  • Limit physical access to critical gear: Place core servers and networking equipment inside locked server rooms or restricted access cabinets.
  • Provide stable power and climate controls: Use uninterrupted power units and air cooling to protect sensitive systems from power cuts and overheating.
  • Secure cables and power lines: Run power cables and network wires through covered floor runs to prevent physical damage or accidental unplugging.
  • Isolate special assets safely: Keep hardware that processes extra sensitive data in isolated physical zones away from common staff areas.

How to Implement ISO 27001 Annex A 7.8

  • Log hardware in a central register: Record all physical equipment in a central asset log with clear, exact physical location details.
  • Assess environmental hazards: Map physical risks like water pipes, high heat, dust, and direct sunlight near work areas.
  • Set screen protection rules: Position displays and control panels away from windows, walkways, and public visitor areas to block view.
  • Control equipment moves: Use central change tasks to review and approve physical hardware moves before staff shift any equipment.
  • Run regular location checks: Inspect work areas monthly and log audit findings to confirm physical safeguards stay active.
  • Secure cables and wiring: Route power cables and data lines through floor channels to prevent accidental disconnects or physical harm.
  • Provide power backup systems: Install stable power supplies to shield sensitive equipment from sudden power losses or voltage spikes.
  • Apply physical access limits: Place core servers and vital network gear inside locked rooms accessible only to approved workers.
  • Train staff on siting rules: Teach employees how simple desk setup choices prevent screen viewing and protect physical hardware.

How to Audit ISO 27001 Annex A 7.8

  • Review equipment siting policies: Inspect written facility rules to check that clear guidance exists for placing hardware safely away from risks and public view.
  • Audit the central asset log: Sample inventory records to confirm physical room, desk, or rack placement details are accurate.
  • Inspect physical screen placement: Walk through work areas to verify display screens, control panels, and printers face away from windows and public walkways.
  • Check environmental hazard safety: Inspect hardware zones to confirm devices stay clear of water pipes, high heat, and direct sunlight.
  • Verify hardware move sign-offs: Sample change log records to confirm staff get manager approval before moving physical equipment between rooms.
  • Inspect restricted room access: Verify main network gear and core servers sit behind locked doors with restricted staff access.
  • Audit power and cooling logs: Inspect service records for backup power systems, surge units, and air cooling in main hardware areas.
  • Check physical cable protection: Inspect cable runs to confirm power lines and network wires pass through covered floor channels to avoid harm.
  • Review site check records: Inspect logs from routine site reviews to confirm teams check screen privacy and physical risks regularly.
  • Check visitor escort rules: Sample visitor sign-in logs to confirm unapproved guests carry continuous staff escort near sensitive gear zones.
  • Verify clean desk rules: Inspect open work areas after hours to confirm workers clear away paper documents and portable media items.
  • Check physical tracking labels: Inspect sample placed hardware to confirm tamper-evident asset tags match central log records.
  • Audit physical access logs: Review keycard entry logs for secure server rooms to check for unapproved access attempts.
  • Verify clear screen timeout rules: Check sample workstations to ensure inactive screens auto-lock quickly to prevent screen viewing.

Audit Evidence Checklist

  • Central asset register: Maintain an up-to-date inventory showing exact room, desk, or rack locations for all company equipment.
  • Equipment room risk checks: Document physical hazard reviews for all hardware rooms, including water, heat, and power risks.
  • Hardware move change logs: Supply task approval records that show a complete trail for all physical equipment moves.
  • Physical site inspection logs: Produce dated check records showing routine reviews of hardware zones and screen placement.
  • Approved office floor plans: Keep version-controlled floor layouts that mark secure hardware zones and restricted access areas.
  • Maintenance service records: Provide service logs showing regular checks on air cooling, fire systems, and backup power units.
  • Environmental control logs: Maintain temp and humidity tracking logs for core server rooms and main technical cabinets.
  • Visitor access logs: Supply sign-in records proving unapproved guests carry supervision inside restricted hardware zones.

What to Teach Employees

  • Position screens away from view: Teach staff to turn monitors and displays away from windows, walkways, and visitor areas to block shoulder surfing.
  • Lock screens when stepping away: Remind workers to lock device screens every time they leave their desk, even for brief moments.
  • Keep hardware away from hazards: Instruct employees to set up devices away from water pipes, heat units, open windows, and direct sunlight.
  • Avoid moving equipment without sign-off: Teach staff to request formal approval before shifting company hardware to new rooms or locations.
  • Protect power cables and wires: Instruct workers to route cables through covered floor runs to prevent physical damage and trips.
  • Keep food and liquids away from tech: Remind staff to keep drinks and food clear of hardware and work desks to avoid spills.
  • Secure sensitive printouts immediately: Teach employees to collect printed paper right away and place shared printers away from public view.
  • Report physical hazards fast: Ensure workers know to flag water leaks, strange noises, high heat, or cable damage right away.
  • Keep secure room doors closed: Train staff never to prop open doors to central hardware rooms or restricted equipment areas.
  • Escort unapproved visitors: Teach staff to challenge or guide unverified guests walking near sensitive hardware or work desks.
  • Follow clear desk rules daily: Instruct workers to clear sensitive paper notes and portable items from desks at the end of every work day.
  • Use privacy filters in open zones: Encourage staff working in high-traffic areas to fit physical screen privacy covers.
  • Verify physical asset labels: Teach workers to ensure asset tracking tags stay attached to all placed hardware during daily work.
  • Report suspicious physical tampering: Train staff to inspect devices for unexpected cables, loose cases, or signs of physical intrusion.

Common Implementation Challenges

  • Exposing screens to public view: Workstation screens face windows, glass walls, or visitor walkways, allowing screen viewing. Angle displays away from public view or fit physical privacy screens.
  • Placing gear near water or heat hazards: Hardware sits near water pipes, radiators, or leaky air units. Move sensitive gear away from liquid lines and heat sources to avoid physical damage.
  • Unapproved hardware moves: Staff move equipment between rooms without updating central asset logs. Require manager sign-off tasks before moving any physical equipment.
  • Outdated asset location logs: Asset registers fail to reflect real physical room or desk locations as office layouts change. Run routine physical spot checks to keep location records accurate.
  • Exposed cabling and trip hazards: Power cables and data wires lie loose across walkways, risking physical wear or accidental unplugging. Route all wires through covered floor channels or cable wraps.
  • Propping open secure room doors: Staff prop open doors to central hardware rooms for air flow or quick entry. Enforce strict door rules and install auto-closing locks on secure zones.
  • Inadequate cooling and ventilation: High hardware density in small equipment rooms leads to system overheating. Install air cooling and temperature tracking devices in core hardware zones.
  • Lack of backup power protection: Sudden power cuts or electrical spikes disrupt active hardware and corrupt data. Protect critical systems with battery backups and surge protectors.
  • Communal printer exposure: Shared printers sit in high-traffic corridors where visitors can view printed paper. Move printers into secure staff zones and require user codes for paper release.
  • Unescorted visitors in tech areas: External contractors walk past active screens and hardware without staff supervision. Mandate visitor logs and continuous staff escorts in sensitive areas.
  • Ignoring sunlight and dust threats: Hardware placed near open windows suffers from direct sunlight heat or heavy dust buildup. Position devices in shaded, clean zones with regular cleaning schedules.
  • Missing physical asset labels: Devices lack visible tracking tags, making location audits hard to verify. Attach tamper-evident physical tracking tags to all placed equipment.
  • Shared office spatial limits: Shared spaces limit control over physical walls, doors, and window layout. Use physical lock cables, privacy screen covers, and locked cabinets to secure gear.
  • Overlooking clear desk rules: Workers leave active displays unlocked and paper files scattered on desks overnight. Enforce automatic screen lock timeouts and end-of-day clean desk checks.
  • Unsecured physical key management: Physical keys to secure equipment rooms sit in open drawers. Store keycards and room keys inside secure key safes with logged access.
  • Unprotected physical maintenance ports: Open network sockets and hardware ports in public areas allow unapproved access. Lock down or cover unused physical ports on placed equipment.

How to Measure Effectiveness (KPIs)

  • Asset location tracking accuracy: Track the percentage of physical hardware items whose recorded location matches real room placement during spot checks.
  • Screen privacy compliance rate: Measure the proportion of workstations angled away from windows and walkways or fitted with privacy filters.
  • Environmental hazard exposure rate: Track the number of placed devices located near water pipes, radiators, or direct sunlight risks.
  • Hardware move approval rate: Measure the percentage of physical equipment moves backed by formal manager sign-off before relocation.
  • Unauthorised physical access events: Track the total count of security incidents or unescorted visitor events in restricted hardware zones.
  • Environmental incident count: Monitor the number of equipment issues caused by water leaks, power cuts, dust, or high room heat.
  • Backup power system test pass rate: Measure the percentage of routine battery backup and surge protector tests completed successfully.
  • Physical cabling safety rate: Track the proportion of equipment areas where power lines and data wires run through covered floor channels.
  • Clear screen timeout rate: Measure the percentage of workstations configured to lock screens automatically after brief inactive periods.
  • Siting audit finding count: Monitor the number of physical security gaps flagged during routine site checks and facility reviews.
  • Unattended print job count: Track the number of sensitive documents left on shared printers during random clean desk audits.
  • Physical tracking label pass rate: Measure the percentage of placed hardware items carrying intact, visible asset tracking labels.
  • Temperature and humidity log compliance: Track the percentage of core equipment rooms maintaining safe climate levels within agreed limits.
  • Physical key management audit score: Measure compliance for logging physical key and access card issuance for secure hardware zones.

ISO 27001 Control A 7.8 connects to several other ISO 27001 areas:

ISO 27001 Equipment Siting and Protection Explained – Annex A 7.8 - ISO 27001.com
ISO 27001 Equipment Siting and Protection Explained – Annex A 7.8
ISO 27001 Annex A 7.8