ISO 27001 Annex A 7.6 Working in Secure Areas Explained

Stuart And Fay High Table

ISO 27001 Working in Secure Areas

ISO 27001 Annex A 7.6 Working In Secure Areas is an ISO 27001 control that requires an organisation to put measures in place for security when working in secure areas.

Key Takeaways

ISO 27001 Annex A 7.6 requires organizations to design and implement security measures specifically for personnel working within secure areas (e.g., server rooms, high-security zones, or sensitive processing facilities). While other controls focus on getting into the building, this control focuses on what happens once you are inside. The goal is to prevent unauthorized interference, damage, or data leakage by those authorized to be in the space.

Purpose

ISO 27001 Annex A 7.6 is a preventive control that ensures you protect information and other associated assets in secure areas from damage and unauthorised interference by personnel working in these areas.

Definition

The ISO 27001 standard defines ISO 27001 Annex A 7.6 as:

Security measures for working in secure areas should be designed and implemented.

ISO27001:2022 Annex A 7.6 Working In Secure Areas

Explanation

The focus for this ISO 27001 Control are your secure areas. As one of the ISO 27001 controls this is about stopping people who work in these secure areas from causing damage and unauthorised interference.

Requirement

  • Need-to-Know Access: Personnel should only work in secure areas if it is strictly necessary for their role. Access should be restricted to the specific times required to perform the task.
  • Prohibiting Recording Devices: You must consider banning or restricting the use of cameras, mobile phones, and recording equipment within secure zones to prevent the photographing of sensitive data or hardware configurations.
  • Supervision & Lone Working: Where practicable, work in high-security areas should be supervised. If lone working is necessary, additional security or safety monitoring should be implemented.
  • Clear Desk & Screen: Just because an area is “secure” doesn’t mean information can be left exposed. Personnel must follow clean desk and clear screen practices within the zone.
  • Safety First: Security measures must never compromise human safety. Emergency exits must be clearly marked, and fail-safe mechanisms (like doors that “fail open” during a fire alarm) must be in place.

Audit Focus

  1. Policy Awareness: They will interview staff to see if they know the specific rules for the secure area (e.g., “Are you allowed to take photos in here?”).
  2. Visual Evidence: They will look for signage at the entrance of secure zones outlining prohibited items and behavior.
  3. The “Tailgating” Test: They may observe entry points to see if authorized personnel are letting others in without following proper badge-in or escort procedures.

FREE Training Video

Guidance

You are going to have to

  • Implement a need to know approach to the existence, operation and working processes of secure areas
  • Where practicable ensure that work in secure areas is supervised
  • Put in a process of locking and inspecting vacant secure areas
  • Consider preventing the use of cameras, phones, recording equipment unless you authorise it
  • Train people in emergency procedures
  • Communicate emergency procedures
  • Follow all health and safety laws as well as all laws and regulations

The implementation of working in secure areas is in the context of the physical security perimeter where you can find guidance in the Ultimate guide to ISO 27001 Annex A 7.1 Physical Security Perimeter.

Health and Safety

Your number one priority is to meet the requirements of law and regulation. Be sure to engage with a legal professional to understand what you can and cannot do and to check that you are not breaking any laws. The most significant laws are those around health and safety as the protection of human life and wellbeing is always our number priority. There are common things that should be considered such as entry point doors that fail open. Whilst we want to protect buildings and information our absolute priority is to protect people.

How to implement it

Implementing ISO 27001 Annex A 7.6 requires a combination of physical barriers and strict behavioural protocols to ensure that sensitive information remains protected while personnel are active within secure zones. This technical guide outlines the action-result workflow for managing conduct, supervision, and recording restrictions in high-security environments.

1. Formalise Secure Area Operating Procedures

Develop and approve a formal set of rules that govern how personnel must behave when inside a secure zone to ensure consistency and auditability.

  • Define the specific boundaries of the secure area and the activities permitted within it.
  • Establish a “Need to Know” criteria for anyone requesting access to the zone.
  • Document the process for opening and closing the area, including alarm deactivation and activation.
  • Distribute these procedures as part of the mandatory security induction for all staff.

2. Restrict and Manage Recording Equipment

Provision physical and technical barriers to prevent the unauthorised capture of sensitive data via cameras, mobile phones, or other recording devices.

  • Install secure lockers outside the perimeter for the storage of personal mobile devices.
  • Implement a “No Photography” policy enforced by prominent signage at all entry points.
  • Utilise MDM (Mobile Device Management) profiles to logically disable camera functions on corporate devices used within the zone.
  • Conduct random spot checks to ensure compliance with device restrictions.

3. Enforce Continuous Supervision for Unvetted Personnel

Establish a strict “shadowing” protocol to ensure that visitors, contractors, and unvetted staff are never left alone with sensitive assets.

  • Assign a designated “Host” for every visitor who has been background-vetted by the organisation.
  • Mandate that visitors are kept within the visual line of sight of the host at all times.
  • Ensure all third-party maintenance work is supervised by a staff member with appropriate technical knowledge.
  • Revoke access immediately if a visitor is found unattended in a restricted zone.

4. Implement Visual Privacy and Clean Area Controls

Apply physical safeguards to prevent accidental visual eavesdropping and ensure that sensitive data is not left exposed when the area is vacant.

  • Position monitors away from windows and entry doors to prevent “shoulder surfing” from outside the zone.
  • Enforce a strict “Clean Desk” policy for secure areas, requiring all sensitive documents to be locked away when not in use.
  • Utilise privacy screen filters on all workstations within the secure area.
  • Ensure that whiteboards are cleared of all sensitive diagrams or data immediately after meetings.

5. Maintain a Formal Register of Entrants

Document every entry and exit to create a verifiable audit trail of who was present in the secure area and for what duration.

  • Utilise a physical or digital Register of Entrants (ROE) to log name, organisation, purpose, and time.
  • Cross-reference the ROE with electronic badge logs to identify any discrepancies.
  • Retain access logs for at least twelve months to support forensic investigations or audit requests.
  • Review the ROE monthly to identify unusual patterns of access that may indicate a security threat.

Secure Area Rules Checklist

RuleDescriptionWhy?
No Unaccompanied GuestsVisitors must be escorted at all times.Prevents unauthorized access/theft.
No PhotographyCameras/Phones are banned (or covered).Prevents data leakage via photos.
Wear IDBadges must be visible.rapid identification of intruders.
Need to KnowOnly enter if you have work to do here.Minimizes foot traffic/risk.
Lock on ExitNever prop the door open.Maintains the physical perimeter.

ISO 27001 Physical Security Policy

To communicate to people what you do and what is expected you are going to write, sign off, implement and communicate your topic specific Physical and Environmental Security Policy.

ISO 27001 Physical and Environmental Security Policy - ISO 27001 Annex A 7.6 Template
ISO 27001 Physical and Environmental Security Policy Template

How to pass the audit

To pass the audit of ISO 27001 Annex A 7.6 you are going to

  • Define your physical protection requirements
  • Consult with a legal professional to ensure you are meeting legal and regulatory requirements
  • Consult with appropriate professionals who specialise in the identified protection requirements
  • Implement your physical threat protection
  • Write, sign off, implement and communicate your topic specific Physical and Environmental Security Policy
  • Write, sign off, implement and communicate your secure working procedures
  • Implement a process of internal audit that checks that the appropriate controls are in place and effective and where they are not follow the continual improvement process to address the risks

What the auditor will check

The audit is going to check a number of areas. Lets go through them

1. That you have defined secure working areas

Not every business or organisation requires secure areas but if you do the audit will check that you have defined what they are, done a risk assessment and put in place the appropriate controls and processes.

2. The you have implemented controls

They have been doing this a long time and done many audits so they know what to look for. They will test the controls and see what happens where they can. They will want to see evidence that the controls have been reviewed and tested and are working as intended.

3. Documentation

They are going to look at audit trails and all your documentation. They will look at appropriate maintenance, reviews, logs of monitors and reports, incidents and how you managed them.

Top 3 mistakes and how to avoid them

The top 3 mistakes people make for ISO 27001 Annex A 7.6 are

1. Your fire extinguishers are not up to date

This one feels a bit random but as they walk around they will check fire extinguishers and look for evidence that they are operational and maintained. An example would be a fire extinguisher that works on pressure and the pressure gauge is at zero or in the red. Also that there is no evidence of them being maintained.

2. One or more members of your team haven’t done what they should have done

Prior to the audit check that all members of the team have done what they should have. Have control reviews taken place? Who gets informed about about the alarms and notification and do they still work here? Have you done periodic checks of vacant secure areas.

3. Your document and version control is wrong

Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.

Applicability across different business models

Business TypeApplicabilityExamples of Control Implementation
Small BusinessesApplies if the business has a small comms room, server closet, or a safe for physical documents. The goal is to ensure that even trusted staff or visitors don’t accidentally compromise security while inside these spaces.
  • Implementing a “No Unaccompanied Guests” rule for the office server closet.
  • Requiring that the server closet door is never propped open and is visually inspected at the end of each day.
  • Training staff on the “Need to Know” rule, ensuring only the owner and IT lead have access keys to the document safe.
Tech StartupsCritical for startups with dedicated development labs or high-security data centers. Focus is on preventing data leakage via unauthorized photography and ensuring that technical work is supervised.
  • Enforcing a “No Photography” policy in the development lab to prevent photos of proprietary hardware or screen configurations.
  • Requiring that all third-party AC or power technicians are supervised by a vetted staff member at all times.
  • Using digital access logs to maintain a verifiable audit trail of everyone who entered the server room and for how long.
AI CompaniesVital for protecting GPU clusters and rooms where high-value proprietary model weights are processed. Focus is on preventing insider interference and maintaining absolute visual privacy.
  • Mandating a “Two-Man Rule” for high-risk maintenance tasks within the GPU cluster room to reduce the risk of accidental damage.
  • Using MDM (Mobile Device Management) to logically disable camera functions on corporate devices used within the secure AI research zone.
  • Positioning all monitors within the secure area away from windows to prevent “shoulder surfing” or long-range visual interception.

FAQ

Are mobile phones and cameras allowed in secure areas?

No, the use of recording equipment, including mobile phones and cameras, is generally prohibited or strictly controlled within secure areas to prevent unauthorised data exfiltration.
Personnel should store personal mobile devices in secure lockers outside the perimeter.
Authorised photography requires a written business justification and supervision.
MDM (Mobile Device Management) policies may be used to disable camera functions.
Physical signage must clearly state the prohibition of recording devices.

Do visitors require constant supervision in secure areas?

Yes, all visitors and unvetted third-party personnel must be supervised at all times when working within or moving through secure areas.
Visitors must be assigned an internal “host” responsible for their actions.
Their access must be logged, and their identity verified before entry.
Unsupervised access is only permitted for personnel who have passed relevant background checks.
Supervision ensures visitors do not stray into restricted zones or view sensitive data.

What is the difference between Annex A 7.2 and 7.6?

While Annex A 7.2 focuses on the physical entry and access controls to the building, Annex A 7.6 specifically governs the behaviour and activities of people once they are inside the secure zone.
7.2 deals with locks, badges, and perimeter security.
7.6 deals with supervision, clean desk habits, and recording restrictions.
7.2 prevents unauthorised entry; 7.6 prevents insider threats or accidental disclosures.

How should unannounced maintenance be handled in secure areas?

Unannounced maintenance should be treated as a high-risk event requiring strict identity verification and constant visual oversight by a designated staff member.
Verify the technician’s identity and work order before allowing entry.
Ensure a staff member “shadows” the technician for the duration of the work.
Log the entry and exit times specifically in the secure area access log.
Ensure the technician only accesses the specific equipment required for repair.

Should secure areas be left vacant while unlocked?

No, secure areas must never be left vacant and unlocked; they must be physically secured or continuously occupied by authorised personnel.
Implement auto-locking doors to prevent human error.
Last-person-out procedures must include a sweep and lock verification.
Sensitive data must be cleared from desks if the area is to be left.
Intrusion detection systems should be active when the area is unoccupied.

Further Reading

ISO 27001 Annex A 7.6 Attribute Table

Control type
Information
security properties
Cybersecurity
concepts
Operational
capabilities
Security domains
Preventive
Confidentiality
ProtectPhysical securityProtection
Integrity
Availability

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

ISO 27001 Annex A 7.6 Working in secure areas
Shopping Basket
Scroll to Top