A.7.12 Physical
Cabling security
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (9)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-4mostlycovers — Both controls focus on protecting transmission media from physical tampering and unauthorized access through conduit, shielding, and restricted entry points.
- PE-9mostlyaligns with — The ISO guidance on segregating power and communications cabling and protecting underground lines directly supports the NIST objective of safeguarding power equipment and cabling from interference and damage.
- PE-3partialaligns with — Controlled access to cable rooms, patch panels, and termination points extends physical access control measures to the supporting infrastructure of information systems.
- SC-7partialaligns with — Physical cabling protections contribute to boundary protection by reducing the risk of unauthorized interception or tampering at the physical layer of network connections.
- SC-8partialaligns with — Use of armoured conduit, fibre-optic cable, and electromagnetic shielding helps maintain transmission confidentiality and integrity against physical-layer threats.
Aligned NIST CSF 2.0 outcomes (9)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.IR-01mostlyaligns with — Physical cabling protections and access controls directly support the outcome of shielding networks and environments from unauthorized logical or physical access.
- PR.IR-02mostlyaligns with — Measures such as underground routing, armoured conduits, and electromagnetic shielding address protection of technology assets against environmental and physical threats.
- ID.AM-03partialaligns with — Detailed source-and-destination labelling of cables supports the maintenance of accurate representations of authorized network communication paths.
- PR.AA-06partialaligns with — Locked rooms, patch-panel controls, and inspection-point alarms implement physical-access management commensurate with the sensitivity of the cabling assets.
- PR.PS-01partialaligns with — Requirements for labelling, segregation, and controlled access to cabling infrastructure contribute to disciplined configuration and change-management practices.
Related weaknesses / CWE (3)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-319partialmitigates — Armoured conduits, electromagnetic shielding and locked enclosures make passive eavesdropping on unencrypted traffic traversing the cables more difficult, mitigating exposure of sensitive data in transit.
- CWE-200noneprevents — Physical protection and shielding of cables reduce the chance that an attacker can tap or intercept the transmitted data, thereby lowering the likelihood of sensitive information exposure.
- CWE-532nonenone — By limiting physical access to cabling infrastructure, the control reduces the opportunity for an attacker to attach devices that could capture log or debug data flowing over the network.
Mitigated MITRE ATT&CK techniques (4)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1040partialprevents — Physical protection and shielding of network cabling reduces the feasibility of passive network sniffing by making it harder for an adversary to attach devices or intercept traffic at the cable level.
- T1095nonemitigates — Segregation and shielding of cabling reduces the attack surface for adversaries attempting to intercept or manipulate non-application layer network traffic at the physical medium.
- T1185nonemitigates — Controlled access to patch panels and cable rooms limits opportunities for an adversary to physically tap into network infrastructure to hijack active browser sessions.
- T1557.002nonemitigates — Armoured conduits, locked termination points, and periodic inspections hinder an adversary's ability to insert hardware for ARP cache poisoning or other on-path interception attacks.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.