In this guide you will learn how to implement ISO 27001 Annex A 7.12 and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 7.12 Cabling Security is an ISO 27001 control that looks to make sure you protect any cables that you use from being damaged, interfered with or people using them to intercept your communications.
Table of contents
Purpose & Definition
The purpose of ISO 27001 Cabling Security is to prevent loss, damage, theft or compromise of information and other associated assets and interruption to the organisations operations related to power and communications cabling.
The ISO 27001 standard defines ISO 27001 Annex A 7.12 as:
Cables carrying power, data or supporting information services should be protected from interception,
ISO 27001:2022 Annex A 7.12 Cabling Security
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 7.12 Training Video
In this free training video you will learn How to implement ISO 27001 Cabling Security (Annex A 7.12) and Pass Your Audit
Implementation Guide
Cabling security is only really relevant if you have cables. Which goes without saying. As a physical control this relates to information processing utilities such as data centres and server rooms but we can consider it in the context of office as well.
This control is really looking at availability and confidentiality and the ability to stop people breaking your cables or hacking them to get your data.
To some extent this control is outside of your gift to control but there are some considerations that you can put in place and evidence.
The standard is a little overkill and for most small organisations elements of this will not apply.
The advice here is, if you have a server room or information processing facility or offices, to bring in professional third parties to advise and implement. This is not something you will undertake yourself and there are many laws that govern this that are outside your capability.
The guidance in the standard talks about things like putting power and communications lines underground which clearly will have been done for you unless you are building some facility from scratch. You are at the mercy really of the premises you occupy and the service providers you use.
One part of guidance to consider technical sweeps and inspections of cables looking for devices that are not yours or suspicious is well founded as is controlling access to cable rooms and patch management cabinets.
How to implement ISO 27001 Annex A 7.12
Implementing ISO 27001 Annex A 7.12 requires a strategic approach to physical infrastructure to ensure that power and telecommunications lines are resilient against interception, interference, and environmental damage.
1. Formalise Cable Routing and Infrastructure Mapping
Design and document the physical paths of all data and power lines to ensure they bypass high-risk zones and public access areas.
- Identify cable entry points and map the route through the building to the primary server room.
- Avoid routing cables through shared public spaces or areas with high physical traffic.
- Ensure that cabling is not placed near environmental hazards such as water pipes or heat sources.
- Cross-reference the routes with the site floor plan to identify potential interception points.
2. Enclose Cabling in Protective Conduits
Provision physical barriers such as armoured conduits or locked trunking for all exposed or vulnerable cable segments to prevent physical tapping.
- Use rigid metal conduits for cables that must pass through public or semi-secure areas.
- Install locked cable trays in ceiling voids and under-floor voids to prevent unauthorised access.
- Specify the use of tamper-evident seals on junction boxes to identify potential interference.
- Ensure all conduits are securely fastened to the building structure to prevent removal or displacement.
3. Implement Physical Segregation of Power and Data
Separate power lines from telecommunications cabling to mitigate the risk of signal corruption and eavesdropping caused by electromagnetic interference.
- Maintain a minimum distance between high-voltage power lines and data cables according to industry standards.
- Utilise shielded twisted pair (STP) or fibre optic cabling in areas with high electromagnetic activity.
- Provision separate cable trays or dedicated conduits for power and data to ensure isolation.
- Verify that power and data lines only cross at right angles to minimise signal induction.
4. Secure Distribution Points and Patch Panels
Restrict access to junction boxes, patch panels, and telecommunications rooms to prevent unauthorised physical reconfiguration of the network.
- Install patch panels within locked cabinets or dedicated secure rooms.
- Apply biometric or card-based access control to all telecommunications rooms.
- Maintain a log of all personnel who access distribution points for maintenance or repair.
- Ensure that unused ports on patch panels are physically blocked or logically disabled via the network switch.
5. Standardise Cable Labelling and Documentation
Label all cable endpoints and intermediate distribution frames to facilitate rapid asset identification and ensure accurate configuration management.
- Implement a standardised labelling scheme that identifies the source, destination, and service type.
- Update the Asset Register and network topology diagrams whenever a cabling change is made.
- Perform regular physical audits to ensure that the physical infrastructure matches the digital documentation.
- Use colour-coded cabling to distinguish between different network segments such as production, management, and guest networks.
How to comply
To comply with ISO 27001 Annex A 7.12 Cabling Security you are going to
- Get the help of a professional third party to put in place controls around cabling where required.
- Have policies and procedures in place
- Assess your cables and perform a risk assessment
- Implement controls proportionate to the risk posed
- Test the controls that you have to make sure they are working
Top 3 mistakes and how to avoid them
The top 3 mistakes people make for ISO 27001 Annex A 7.12 Cabling Security are
- You have no cables: If everything is in the cloud then this control is potentially irrelevant to you.
- One or more members of your team haven’t done what they should have done: Prior to the audit check that all members of the team have done what they should have. Can you explain your cable set up? Have you checked it? Have you looked for rogue devices? Check!
- Your document and version control is wrong: Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
ISO 27001 Annex A 7.12 FAQ
Securing cables for ISO 27001 compliance involves a combination of physical shielding, strategic routing, and restricted access to junction points.
Conduits and Trunking: Enclose cables in robust, locked conduits or armoured trunking.
Segregation: Physically separate power and data cables to prevent electromagnetic interference (EMI).
Access Control: Secure all patch panels, telecommunications rooms, and cable entry points with locks or biometrics.
Underground Routing: Use buried conduits for external cabling to prevent easy access for interception.
Yes, cable labelling is a best practice for Annex A 7.12 as it supports the integrity and availability of the network by preventing accidental disconnection and aiding rapid incident response.
Labels should identify the source, destination, and service type.
Standardised schemes reduce the risk of maintenance errors.
Clear labelling helps auditors verify that critical redundant lines are physically separated.
EMI poses a significant security risk by causing data corruption, service latency, or complete signal loss, which directly impacts the ‘Availability’ pillar of the CIA triad.
Power cables can “leak” noise into data lines if they are running too close.
High-voltage equipment can disrupt unscreened twisted pair (UTP) cabling.
Shielded cabling or fibre optics should be used in high-interference environments.
Yes, although fibre optic cables are immune to electromagnetic interference, they must still be protected under Annex A 7.12 from physical damage and specialised tapping methods.
Fibre is susceptible to physical breaks and signal degradation if bent too tightly.
Specialised “optical taps” can intercept data without breaking the link, necessitating physical protection of the line.
Fibre entry points to the building are critical assets that require enhanced physical monitoring.
Auditors look for verifiable evidence that cabling is protected from unauthorised access and environmental threats throughout its entire route.
Visible use of protective trunking or conduit in public areas.
Evidence of cable segregation in trays and server racks.
Locked and managed telecommunications rooms and patch cabinets.
Regular inspection logs or maintenance records for physical infrastructure.
Related ISO 27001 Controls
Controls and Attribute Values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Availability | Protect | Physical Security | Protection |
| Integrity |
Stuart Barker
I am the ISO 27001 Ninja.
I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.
If you want to pass your audit the first time, book a call.


