Table of contents
ISO/IEC 27001:2022 Annex A 7.8
ISO 27001 Annex A 7.8 requires placing hardware safely to prevent physical hazards and stop viewing by unapproved people. Organisations must record device locations and build safety checks into daily office planning.
Key Takeaways
- Position hardware to block visual access: Place monitors, control units, and printers away from windows or visitor areas to prevent screen viewing and shoulder surfing.
- Protect hardware from environmental threats: Keep critical equipment safe from water leaks, heat, dust, and direct sunlight by avoiding areas near windows or pipes.
- Track asset locations continuously: Record the exact physical placement of all equipment in a central asset log to keep location tracking accurate.
- Embed siting into change workflows: Include physical placement security checks in office change plans before moving hardware to new areas.
- Limit physical access to critical gear: Place core servers and networking equipment inside locked server rooms or restricted access cabinets.
- Provide stable power and climate controls: Use uninterrupted power units and air cooling to protect sensitive systems from power cuts and overheating.
- Secure cables and power lines: Run power cables and network wires through covered floor runs to prevent physical damage or accidental unplugging.
- Isolate special assets safely: Keep hardware that processes extra sensitive data in isolated physical zones away from common staff areas.
How to Implement ISO 27001 Annex A 7.8
- Log hardware in a central register: Record all physical equipment in a central asset log with clear, exact physical location details.
- Assess environmental hazards: Map physical risks like water pipes, high heat, dust, and direct sunlight near work areas.
- Set screen protection rules: Position displays and control panels away from windows, walkways, and public visitor areas to block view.
- Control equipment moves: Use central change tasks to review and approve physical hardware moves before staff shift any equipment.
- Run regular location checks: Inspect work areas monthly and log audit findings to confirm physical safeguards stay active.
- Secure cables and wiring: Route power cables and data lines through floor channels to prevent accidental disconnects or physical harm.
- Provide power backup systems: Install stable power supplies to shield sensitive equipment from sudden power losses or voltage spikes.
- Apply physical access limits: Place core servers and vital network gear inside locked rooms accessible only to approved workers.
- Train staff on siting rules: Teach employees how simple desk setup choices prevent screen viewing and protect physical hardware.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 7.8
- Review equipment siting policies: Inspect written facility rules to check that clear guidance exists for placing hardware safely away from risks and public view.
- Audit the central asset log: Sample inventory records to confirm physical room, desk, or rack placement details are accurate.
- Inspect physical screen placement: Walk through work areas to verify display screens, control panels, and printers face away from windows and public walkways.
- Check environmental hazard safety: Inspect hardware zones to confirm devices stay clear of water pipes, high heat, and direct sunlight.
- Verify hardware move sign-offs: Sample change log records to confirm staff get manager approval before moving physical equipment between rooms.
- Inspect restricted room access: Verify main network gear and core servers sit behind locked doors with restricted staff access.
- Audit power and cooling logs: Inspect service records for backup power systems, surge units, and air cooling in main hardware areas.
- Check physical cable protection: Inspect cable runs to confirm power lines and network wires pass through covered floor channels to avoid harm.
- Review site check records: Inspect logs from routine site reviews to confirm teams check screen privacy and physical risks regularly.
- Check visitor escort rules: Sample visitor sign-in logs to confirm unapproved guests carry continuous staff escort near sensitive gear zones.
- Verify clean desk rules: Inspect open work areas after hours to confirm workers clear away paper documents and portable media items.
- Check physical tracking labels: Inspect sample placed hardware to confirm tamper-evident asset tags match central log records.
- Audit physical access logs: Review keycard entry logs for secure server rooms to check for unapproved access attempts.
- Verify clear screen timeout rules: Check sample workstations to ensure inactive screens auto-lock quickly to prevent screen viewing.
Audit Evidence Checklist
- Central asset register: Maintain an up-to-date inventory showing exact room, desk, or rack locations for all company equipment.
- Equipment room risk checks: Document physical hazard reviews for all hardware rooms, including water, heat, and power risks.
- Hardware move change logs: Supply task approval records that show a complete trail for all physical equipment moves.
- Physical site inspection logs: Produce dated check records showing routine reviews of hardware zones and screen placement.
- Approved office floor plans: Keep version-controlled floor layouts that mark secure hardware zones and restricted access areas.
- Maintenance service records: Provide service logs showing regular checks on air cooling, fire systems, and backup power units.
- Environmental control logs: Maintain temp and humidity tracking logs for core server rooms and main technical cabinets.
- Visitor access logs: Supply sign-in records proving unapproved guests carry supervision inside restricted hardware zones.
What to Teach Employees
- Position screens away from view: Teach staff to turn monitors and displays away from windows, walkways, and visitor areas to block shoulder surfing.
- Lock screens when stepping away: Remind workers to lock device screens every time they leave their desk, even for brief moments.
- Keep hardware away from hazards: Instruct employees to set up devices away from water pipes, heat units, open windows, and direct sunlight.
- Avoid moving equipment without sign-off: Teach staff to request formal approval before shifting company hardware to new rooms or locations.
- Protect power cables and wires: Instruct workers to route cables through covered floor runs to prevent physical damage and trips.
- Keep food and liquids away from tech: Remind staff to keep drinks and food clear of hardware and work desks to avoid spills.
- Secure sensitive printouts immediately: Teach employees to collect printed paper right away and place shared printers away from public view.
- Report physical hazards fast: Ensure workers know to flag water leaks, strange noises, high heat, or cable damage right away.
- Keep secure room doors closed: Train staff never to prop open doors to central hardware rooms or restricted equipment areas.
- Escort unapproved visitors: Teach staff to challenge or guide unverified guests walking near sensitive hardware or work desks.
- Follow clear desk rules daily: Instruct workers to clear sensitive paper notes and portable items from desks at the end of every work day.
- Use privacy filters in open zones: Encourage staff working in high-traffic areas to fit physical screen privacy covers.
- Verify physical asset labels: Teach workers to ensure asset tracking tags stay attached to all placed hardware during daily work.
- Report suspicious physical tampering: Train staff to inspect devices for unexpected cables, loose cases, or signs of physical intrusion.
Common Implementation Challenges
- Exposing screens to public view: Workstation screens face windows, glass walls, or visitor walkways, allowing screen viewing. Angle displays away from public view or fit physical privacy screens.
- Placing gear near water or heat hazards: Hardware sits near water pipes, radiators, or leaky air units. Move sensitive gear away from liquid lines and heat sources to avoid physical damage.
- Unapproved hardware moves: Staff move equipment between rooms without updating central asset logs. Require manager sign-off tasks before moving any physical equipment.
- Outdated asset location logs: Asset registers fail to reflect real physical room or desk locations as office layouts change. Run routine physical spot checks to keep location records accurate.
- Exposed cabling and trip hazards: Power cables and data wires lie loose across walkways, risking physical wear or accidental unplugging. Route all wires through covered floor channels or cable wraps.
- Propping open secure room doors: Staff prop open doors to central hardware rooms for air flow or quick entry. Enforce strict door rules and install auto-closing locks on secure zones.
- Inadequate cooling and ventilation: High hardware density in small equipment rooms leads to system overheating. Install air cooling and temperature tracking devices in core hardware zones.
- Lack of backup power protection: Sudden power cuts or electrical spikes disrupt active hardware and corrupt data. Protect critical systems with battery backups and surge protectors.
- Communal printer exposure: Shared printers sit in high-traffic corridors where visitors can view printed paper. Move printers into secure staff zones and require user codes for paper release.
- Unescorted visitors in tech areas: External contractors walk past active screens and hardware without staff supervision. Mandate visitor logs and continuous staff escorts in sensitive areas.
- Ignoring sunlight and dust threats: Hardware placed near open windows suffers from direct sunlight heat or heavy dust buildup. Position devices in shaded, clean zones with regular cleaning schedules.
- Missing physical asset labels: Devices lack visible tracking tags, making location audits hard to verify. Attach tamper-evident physical tracking tags to all placed equipment.
- Shared office spatial limits: Shared spaces limit control over physical walls, doors, and window layout. Use physical lock cables, privacy screen covers, and locked cabinets to secure gear.
- Overlooking clear desk rules: Workers leave active displays unlocked and paper files scattered on desks overnight. Enforce automatic screen lock timeouts and end-of-day clean desk checks.
- Unsecured physical key management: Physical keys to secure equipment rooms sit in open drawers. Store keycards and room keys inside secure key safes with logged access.
- Unprotected physical maintenance ports: Open network sockets and hardware ports in public areas allow unapproved access. Lock down or cover unused physical ports on placed equipment.
How to Measure Effectiveness (KPIs)
- Asset location tracking accuracy: Track the percentage of physical hardware items whose recorded location matches real room placement during spot checks.
- Screen privacy compliance rate: Measure the proportion of workstations angled away from windows and walkways or fitted with privacy filters.
- Environmental hazard exposure rate: Track the number of placed devices located near water pipes, radiators, or direct sunlight risks.
- Hardware move approval rate: Measure the percentage of physical equipment moves backed by formal manager sign-off before relocation.
- Unauthorised physical access events: Track the total count of security incidents or unescorted visitor events in restricted hardware zones.
- Environmental incident count: Monitor the number of equipment issues caused by water leaks, power cuts, dust, or high room heat.
- Backup power system test pass rate: Measure the percentage of routine battery backup and surge protector tests completed successfully.
- Physical cabling safety rate: Track the proportion of equipment areas where power lines and data wires run through covered floor channels.
- Clear screen timeout rate: Measure the percentage of workstations configured to lock screens automatically after brief inactive periods.
- Siting audit finding count: Monitor the number of physical security gaps flagged during routine site checks and facility reviews.
- Unattended print job count: Track the number of sensitive documents left on shared printers during random clean desk audits.
- Physical tracking label pass rate: Measure the percentage of placed hardware items carrying intact, visible asset tracking labels.
- Temperature and humidity log compliance: Track the percentage of core equipment rooms maintaining safe climate levels within agreed limits.
- Physical key management audit score: Measure compliance for logging physical key and access card issuance for secure hardware zones.
Related ISO 27001 Controls
ISO 27001 Control A 7.8 connects to several other ISO 27001 areas:
- ISO 27001 Annex A 7.5: Protecting against environmental threats.
- ISO 27001 Annex A 7.1: Physical security perimeters.
- ISO 27001 Clause 8.1: Operational planning and control.
