A.7.3 Physical
Securing offices, rooms and facilities
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (9)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-18mostlyaligns with — Both controls address the physical placement and visibility of system components to reduce exposure to unauthorized observation or access.
- PE-3mostlyaligns with — Both controls require physical barriers and procedures that restrict unauthorized entry to areas containing sensitive assets or operations.
- PE-19partialaligns with — Both controls consider countermeasures against emanations that could disclose sensitive information from within a facility.
- PE-2partialaligns with — Both controls establish who is authorized to enter specific physical areas that house sensitive processing activities.
- PE-5partialaligns with — Both controls limit the ability of unauthorized individuals to view or access information displayed or processed by equipment in physical spaces.
Aligned NIST CSF 2.0 outcomes (5)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-06mostlyaligns with — By restricting public access to critical facilities and limiting visibility of sensitive operations, the ISO guidance implements the CSF requirement to manage and enforce physical access commensurate with risk.
- PR.IR-02mostlyaligns with — The ISO control's focus on siting and configuring physical spaces to shield critical assets from unauthorized observation or access directly supports the CSF outcome of protecting technology assets from environmental threats.
- ID.AM-05partialaligns with — The control implicitly prioritizes physical protection for assets based on their criticality by siting confidential processing facilities away from public areas.
- PR.IR-01partialaligns with — Physical layout and shielding measures reduce the likelihood of unauthorized logical access by limiting opportunities for observation or proximity-based attacks.
Related weaknesses / CWE (8)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1263mostlyprevents — Requires securing offices, rooms and facilities to restrict physical access to areas containing sensitive information.
- CWE-1278partialmitigates — Securing rooms and facilities reduces opportunities for physical IC imaging attacks.
- CWE-1300partialmitigates — Securing rooms and facilities can shield equipment from side-channel probing.
- CWE-200partialprevents — Physical concealment and restricted availability of directories and maps limit the exposure of sensitive information about facility locations and processing activities to unauthorized observers.
- CWE-552partialmitigates — By siting critical facilities away from public areas and avoiding visible or audible disclosure of confidential activities, the control reduces the chance that an attacker can discover or reach sensitive resources that should not be exposed to external parties.
- CWE-497nonenone — Keeping internal maps, directories, and signage from public view prevents disclosure of system or facility details that could aid reconnaissance or targeted attacks.
Mitigated MITRE ATT&CK techniques (2)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1591.001partialmitigates — By siting critical facilities away from public view and avoiding signage or directories that reveal their purpose or location, the control reduces the adversary's ability to physically locate high-value targets for later compromise.
- T1595nonemitigates — Physical obscurity and restricted disclosure of facility locations hinder active scanning or reconnaissance that would otherwise help an attacker map and select targets for remote or physical attacks.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.