ISO 27001 Annex A 7.8 requires placing hardware safely to prevent physical hazards and stop viewing by unapproved people. Organisations must record device locations and build safety checks into daily office planning.
Table of contents
Key Takeaways
- Position hardware to block visual access: Place monitors, control units, and printers away from windows or visitor areas to prevent screen viewing and shoulder surfing.
- Protect hardware from environmental threats: Keep critical equipment safe from water leaks, heat, dust, and direct sunlight by avoiding areas near windows or pipes.
- Track asset locations continuously: Record the exact physical placement of all equipment in a central asset log to keep location tracking accurate.
- Embed siting into change workflows: Include physical placement security checks in office change plans before moving hardware to new areas.
- Limit physical access to critical gear: Place core servers and networking equipment inside locked server rooms or restricted access cabinets.
- Provide stable power and climate controls: Use uninterrupted power units and air cooling to protect sensitive systems from power cuts and overheating.
- Secure cables and power lines: Run power cables and network wires through covered floor runs to prevent physical damage or accidental unplugging.
- Isolate special assets safely: Keep hardware that processes extra sensitive data in isolated physical zones away from common staff areas.
How to Implement ISO 27001 Annex A 7.8
- Log hardware in a central register: Record all physical equipment in a central asset log with clear, exact physical location details.
- Assess environmental hazards: Map physical risks like water pipes, high heat, dust, and direct sunlight near work areas.
- Set screen protection rules: Position displays and control panels away from windows, walkways, and public visitor areas to block view.
- Control equipment moves: Use central change tasks to review and approve physical hardware moves before staff shift any equipment.
- Run regular location checks: Inspect work areas monthly and log audit findings to confirm physical safeguards stay active.
- Secure cables and wiring: Route power cables and data lines through floor channels to prevent accidental disconnects or physical harm.
- Provide power backup systems: Install stable power supplies to shield sensitive equipment from sudden power losses or voltage spikes.
- Apply physical access limits: Place core servers and vital network gear inside locked rooms accessible only to approved workers.
- Train staff on siting rules: Teach employees how simple desk setup choices prevent screen viewing and protect physical hardware.
How to Audit ISO 27001 Annex A 7.8
- Review equipment siting policies: Inspect written facility rules to check that clear guidance exists for placing hardware safely away from risks and public view.
- Audit the central asset log: Sample inventory records to confirm physical room, desk, or rack placement details are accurate.
- Inspect physical screen placement: Walk through work areas to verify display screens, control panels, and printers face away from windows and public walkways.
- Check environmental hazard safety: Inspect hardware zones to confirm devices stay clear of water pipes, high heat, and direct sunlight.
- Verify hardware move sign-offs: Sample change log records to confirm staff get manager approval before moving physical equipment between rooms.
- Inspect restricted room access: Verify main network gear and core servers sit behind locked doors with restricted staff access.
- Audit power and cooling logs: Inspect service records for backup power systems, surge units, and air cooling in main hardware areas.
- Check physical cable protection: Inspect cable runs to confirm power lines and network wires pass through covered floor channels to avoid harm.
- Review site check records: Inspect logs from routine site reviews to confirm teams check screen privacy and physical risks regularly.
- Check visitor escort rules: Sample visitor sign-in logs to confirm unapproved guests carry continuous staff escort near sensitive gear zones.
- Verify clean desk rules: Inspect open work areas after hours to confirm workers clear away paper documents and portable media items.
- Check physical tracking labels: Inspect sample placed hardware to confirm tamper-evident asset tags match central log records.
- Audit physical access logs: Review keycard entry logs for secure server rooms to check for unapproved access attempts.
- Verify clear screen timeout rules: Check sample workstations to ensure inactive screens auto-lock quickly to prevent screen viewing.
Audit Evidence Checklist
- Central asset register: Maintain an up-to-date inventory showing exact room, desk, or rack locations for all company equipment.
- Equipment room risk checks: Document physical hazard reviews for all hardware rooms, including water, heat, and power risks.
- Hardware move change logs: Supply task approval records that show a complete trail for all physical equipment moves.
- Physical site inspection logs: Produce dated check records showing routine reviews of hardware zones and screen placement.
- Approved office floor plans: Keep version-controlled floor layouts that mark secure hardware zones and restricted access areas.
- Maintenance service records: Provide service logs showing regular checks on air cooling, fire systems, and backup power units.
- Environmental control logs: Maintain temp and humidity tracking logs for core server rooms and main technical cabinets.
- Visitor access logs: Supply sign-in records proving unapproved guests carry supervision inside restricted hardware zones.
What to Teach Employees
- Position screens away from view: Teach staff to turn monitors and displays away from windows, walkways, and visitor areas to block shoulder surfing.
- Lock screens when stepping away: Remind workers to lock device screens every time they leave their desk, even for brief moments.
- Keep hardware away from hazards: Instruct employees to set up devices away from water pipes, heat units, open windows, and direct sunlight.
- Avoid moving equipment without sign-off: Teach staff to request formal approval before shifting company hardware to new rooms or locations.
- Protect power cables and wires: Instruct workers to route cables through covered floor runs to prevent physical damage and trips.
- Keep food and liquids away from tech: Remind staff to keep drinks and food clear of hardware and work desks to avoid spills.
- Secure sensitive printouts immediately: Teach employees to collect printed paper right away and place shared printers away from public view.
- Report physical hazards fast: Ensure workers know to flag water leaks, strange noises, high heat, or cable damage right away.
- Keep secure room doors closed: Train staff never to prop open doors to central hardware rooms or restricted equipment areas.
- Escort unapproved visitors: Teach staff to challenge or guide unverified guests walking near sensitive hardware or work desks.
- Follow clear desk rules daily: Instruct workers to clear sensitive paper notes and portable items from desks at the end of every work day.
- Use privacy filters in open zones: Encourage staff working in high-traffic areas to fit physical screen privacy covers.
- Verify physical asset labels: Teach workers to ensure asset tracking tags stay attached to all placed hardware during daily work.
- Report suspicious physical tampering: Train staff to inspect devices for unexpected cables, loose cases, or signs of physical intrusion.
Common Implementation Challenges
- Exposing screens to public view: Workstation screens face windows, glass walls, or visitor walkways, allowing screen viewing. Angle displays away from public view or fit physical privacy screens.
- Placing gear near water or heat hazards: Hardware sits near water pipes, radiators, or leaky air units. Move sensitive gear away from liquid lines and heat sources to avoid physical damage.
- Unapproved hardware moves: Staff move equipment between rooms without updating central asset logs. Require manager sign-off tasks before moving any physical equipment.
- Outdated asset location logs: Asset registers fail to reflect real physical room or desk locations as office layouts change. Run routine physical spot checks to keep location records accurate.
- Exposed cabling and trip hazards: Power cables and data wires lie loose across walkways, risking physical wear or accidental unplugging. Route all wires through covered floor channels or cable wraps.
- Propping open secure room doors: Staff prop open doors to central hardware rooms for air flow or quick entry. Enforce strict door rules and install auto-closing locks on secure zones.
- Inadequate cooling and ventilation: High hardware density in small equipment rooms leads to system overheating. Install air cooling and temperature tracking devices in core hardware zones.
- Lack of backup power protection: Sudden power cuts or electrical spikes disrupt active hardware and corrupt data. Protect critical systems with battery backups and surge protectors.
- Communal printer exposure: Shared printers sit in high-traffic corridors where visitors can view printed paper. Move printers into secure staff zones and require user codes for paper release.
- Unescorted visitors in tech areas: External contractors walk past active screens and hardware without staff supervision. Mandate visitor logs and continuous staff escorts in sensitive areas.
- Ignoring sunlight and dust threats: Hardware placed near open windows suffers from direct sunlight heat or heavy dust buildup. Position devices in shaded, clean zones with regular cleaning schedules.
- Missing physical asset labels: Devices lack visible tracking tags, making location audits hard to verify. Attach tamper-evident physical tracking tags to all placed equipment.
- Shared office spatial limits: Shared spaces limit control over physical walls, doors, and window layout. Use physical lock cables, privacy screen covers, and locked cabinets to secure gear.
- Overlooking clear desk rules: Workers leave active displays unlocked and paper files scattered on desks overnight. Enforce automatic screen lock timeouts and end-of-day clean desk checks.
- Unsecured physical key management: Physical keys to secure equipment rooms sit in open drawers. Store keycards and room keys inside secure key safes with logged access.
- Unprotected physical maintenance ports: Open network sockets and hardware ports in public areas allow unapproved access. Lock down or cover unused physical ports on placed equipment.
How to Measure Effectiveness (KPIs)
- Asset location tracking accuracy: Track the percentage of physical hardware items whose recorded location matches real room placement during spot checks.
- Screen privacy compliance rate: Measure the proportion of workstations angled away from windows and walkways or fitted with privacy filters.
- Environmental hazard exposure rate: Track the number of placed devices located near water pipes, radiators, or direct sunlight risks.
- Hardware move approval rate: Measure the percentage of physical equipment moves backed by formal manager sign-off before relocation.
- Unauthorised physical access events: Track the total count of security incidents or unescorted visitor events in restricted hardware zones.
- Environmental incident count: Monitor the number of equipment issues caused by water leaks, power cuts, dust, or high room heat.
- Backup power system test pass rate: Measure the percentage of routine battery backup and surge protector tests completed successfully.
- Physical cabling safety rate: Track the proportion of equipment areas where power lines and data wires run through covered floor channels.
- Clear screen timeout rate: Measure the percentage of workstations configured to lock screens automatically after brief inactive periods.
- Siting audit finding count: Monitor the number of physical security gaps flagged during routine site checks and facility reviews.
- Unattended print job count: Track the number of sensitive documents left on shared printers during random clean desk audits.
- Physical tracking label pass rate: Measure the percentage of placed hardware items carrying intact, visible asset tracking labels.
- Temperature and humidity log compliance: Track the percentage of core equipment rooms maintaining safe climate levels within agreed limits.
- Physical key management audit score: Measure compliance for logging physical key and access card issuance for secure hardware zones.
Related ISO 27001 Controls
ISO 27001 Control A 7.8 connects to several other ISO 27001 areas:
- ISO 27001 Annex A 7.5: Protecting against environmental threats.
- ISO 27001 Annex A 7.1: Physical security perimeters.
- ISO 27001 Clause 8.1: Operational planning and control.


