A.7.12 Physical
Cabling security
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (12)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-4mostlycovers — Both controls focus on protecting transmission media from physical tampering and unauthorized access through conduit, shielding, and restricted entry points.
- PE-9mostlyaligns with — The ISO guidance on segregating power and communications cabling and protecting underground lines directly supports the NIST objective of safeguarding power equipment and cabling from interference and damage.
- PE-9mostlycovers — A.7.12's explicit scope for power and comms cabling (preventing loss/damage/theft/compromise and operational interruption) accounts for the bulk of PE-9's narrower requirement to protect power equipment/cabling from damage and destruction, but leaves a residual on explicit equipment protection and non-cabling power elements not addressed by the ISO control.
- PE-3partialaligns with — Controlled access to cable rooms, patch panels, and termination points extends physical access control measures to the supporting infrastructure of information systems.
- SC-7partialaligns with — Physical cabling protections contribute to boundary protection by reducing the risk of unauthorized interception or tampering at the physical layer of network connections.
- SC-8partialaligns with — Use of armoured conduit, fibre-optic cable, and electromagnetic shielding helps maintain transmission confidentiality and integrity against physical-layer threats.
- SC-8covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (15)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.IR-01mostlyaligns with — Physical cabling protections and access controls directly support the outcome of shielding networks and environments from unauthorized logical or physical access.
- PR.IR-02mostlyaligns with — Measures such as underground routing, armoured conduits, and electromagnetic shielding address protection of technology assets against environmental and physical threats.
- ID.AM-03partialaligns with — Detailed source-and-destination labelling of cables supports the maintenance of accurate representations of authorized network communication paths.
- PR.AA-06partialaligns with — Locked rooms, patch-panel controls, and inspection-point alarms implement physical-access management commensurate with the sensitivity of the cabling assets.
- PR.PS-01partialaligns with — Requirements for labelling, segregation, and controlled access to cabling infrastructure contribute to disciplined configuration and change-management practices.
- ID.AM-03implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AA-06implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-02implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related weaknesses / CWE (2)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200noneprevents — Physical protection and shielding of cables reduce the chance that an attacker can tap or intercept the transmitted data, thereby lowering the likelihood of sensitive information exposure.
- CWE-319mitigates — Armoured conduits, electromagnetic shielding and locked enclosures make passive eavesdropping on unencrypted traffic traversing the cables more difficult, mitigating exposure of sensitive data in transit.
Mitigated MITRE ATT&CK techniques (46)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1011detects — A.7.12.c.3's periodical technical sweeps and physical inspections directly surface unauthorized devices attached to cables, which can enable or indicate use of an alternate exfiltration medium such as Bluetooth/RF/modem; this is a genuine but minority slice of the broad technique (most T1011 vectors are not cable-taps).
- T1020.001detects — A.7.12.c.3 explicitly requires periodical technical sweeps and physical inspections to detect unauthorized devices attached to cables, which would surface malicious traffic mirroring/redirection modifications on network cabling or devices
- T1040prevents — Physical protection and shielding of network cabling reduces the feasibility of passive network sniffing by making it harder for an adversary to attach devices or intercept traffic at the cable level.
- T1040detects — A.7.12.c.3 explicitly requires periodical technical sweeps and physical inspections to detect unauthorized devices attached to cables, which surfaces a subset of network sniffing setups (e.g. taps or inline devices on wired links) but does not address promiscuous mode, span ports, cloud traffic mirroring, or CLI-based captures on network devices.
- T1048.003detects — A.7.12 point c.3 explicitly requires periodical technical sweeps and physical inspections to detect unauthorized devices attached to cables, which can surface physical-layer exfiltration activity over unencrypted links (e.g. taps or implants on network cabling) but does not address protocol-level detection of the T1048.003 behavior itself.
- T1052detects — A.7.12.c.3 explicitly requires periodical technical sweeps and physical inspections to detect unauthorized devices attached to the cables, which would surface an exfiltration device introduced onto physical cabling; this is a genuine but minority slice of T1052 (only the cable-tapping subset, not removable drives, optical media, or air-gap sneaker-net hops).
- T1052prevents — A.7.12's physical protections (underground/armoured cabling, segregation, shielding, sweeps, locked rooms/panels) stop many physical-medium exfiltration paths that rely on tapping, splicing, or attaching devices to cables, but leave the dominant removable-media vector (USB drives, external HDDs carried by users) untouched.
- T1052.001detects — A.7.12.c.3 explicitly requires periodical technical sweeps and physical inspections to detect unauthorized devices attached to cables, which surfaces the presence of a USB exfiltration device in the physical cabling environment (especially air-gapped); this is a genuine but minority slice of the technique's full surface (USB insertion anywhere, not just cabling, plus the data transfer act itself).
- T1091detects — A.7.12.c.3 explicitly requires periodical technical sweeps and physical inspections to detect unauthorized devices attached to cables, which surfaces the use of USB charging cables or modified removable media carrying malware before or during the T1091 infection vector
- T1200detects — A.7.12.c.3 explicitly requires periodical technical sweeps and physical inspections to detect unauthorized devices attached to cables, which surfaces a subset of hardware additions (network taps or similar on comms lines) but does not address non-cable vectors such as keystroke injectors, DMA devices, or wireless APs.
- T1200prevents — A.7.12's physical protections (underground/armoured cabling, locked rooms/boxes at termination points, controlled patch-panel access, sweeps/inspections for attached devices, and fibre/EMI shielding) directly stop many hardware-addition vectors at the cable or inspection layer, but leave open slices such as wireless additions, internal DMA devices, or additions that do not touch protected cabling/rooms.
- T1219.003detects — A.7.12.c.3 explicitly requires periodical technical sweeps and physical inspections to detect unauthorized devices attached to cables, which would surface many instances of post-compromise remote access hardware (KVM) installation on communications lines; this is only a slice of the technique because it is scoped to cable-attached devices, does not address pre-installed or non-cable hardware, and is not required for non-sensitive systems.
- T1219.003prevents — A.7.12's physical protections (underground/armoured cabling, locked rooms/boxes at termination points, controlled patch-panel access, sweeps/inspections for attached devices) directly raise the bar for an adversary physically installing or attaching remote-access hardware such as KVM devices post-compromise, but leave many vectors (e.g., already-permitted peripherals, software-configured KVM, or non-cable hardware) untouched.
- T1542.005detects — A.7.12.c.3 explicitly requires periodical technical sweeps and physical inspections to detect unauthorized devices attached to cables, which would surface a malicious TFTP server or rogue cabling used to enable the netboot technique on network devices.
- T1557detects — A.7.12.c.3 explicitly requires periodical technical sweeps and physical inspections to detect unauthorized devices attached to cables, which can surface some physical-layer AiTM setups (e.g. rogue taps or inline devices) but does not address protocol-abuse, DNS/ARP poisoning, or logical MITM performed without a physical attachment.
- T1557prevents — A.7.12's physical cabling protections (underground routing, segregation, armoured conduits, shielding, fibre-optic use, sweeps/inspections) directly stop some physical-layer or proximity-based AiTM vectors such as tapping or interference on exposed cables, but leave the dominant protocol-abuse methods (ARP/DNS/LLMNR poisoning, downgrade attacks, DNS manipulation) untouched.
- T1557.002detects — A.7.12.c.3 explicitly requires periodical technical sweeps and physical inspections to detect unauthorized devices attached to cables, which can surface ARP poisoning performed via a malicious tap or inline device on the physical segment; this is a genuine but minority slice of the technique (most ARP cache poisoning is performed in software from a compromised endpoint without any cable attachment).
- T1565.002detects — A.7.12.c.3 explicitly requires periodical technical sweeps and physical inspections to detect unauthorized devices attached to cables, which would surface some (but not all) interception tools used for transmitted-data manipulation on physical cabling
- T1565.002prevents — A.7.12's physical protections (underground/armoured cabling, segregation, shielding, sweeps, locked access) stop many on-path interception opportunities for transmitted-data manipulation, especially over physical network links; partial because the technique also applies to in-process manipulation, wireless, logical-layer attacks, and complex systems where physical cabling is not the vector.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.