A.7.4 Physical
Physical security monitoring
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (14)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-3mostlycovers — A.7.4's monitoring to detect/deter unauthorized access accounts for the audit-log, verification, and control-of-ingress/egress pieces of PE-3, but leaves a real residual around pre-authorization enforcement mechanisms and designated public-area handling that sit outside pure monitoring.
- PE-6mostlyaligns with — Both controls require continuous monitoring of physical access points and areas containing critical assets to detect unauthorized entry or suspicious activity.
- PE-6mostlycovers — A.7.4's monitoring to detect and deter unauthorized physical access accounts for the core detection/review portion of PE-6, but leaves a real residual (explicit coordination with incident response and the 'respond' part of PE-6) uncovered.
- PE-2partialaligns with — Surveillance and alarm coverage of sensitive areas helps verify that only authorized personnel are granted physical access, supporting the NIST authorization process.
- PE-3partialaligns with — The ISO control's use of alarms, detectors, and tamper protection on access points supports the enforcement of physical access restrictions required by the NIST control.
- PE-8partialaligns with — Video and alarm monitoring systems generate records of physical access events that align with the NIST requirement to maintain visitor access records.
- SI-4partialaligns with — The ISO control's monitoring of physical premises and alarm events parallels the NIST requirement for ongoing system monitoring to detect anomalies and unauthorized activities.
- PE-2covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PE-8covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (12)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- DE.CM-02mostlyaligns with — The ISO control's deployment of surveillance systems and intrusion alarms fulfills the CSF outcome of monitoring the physical environment to identify potentially adverse events.
- PR.AA-06mostlyaligns with — By requiring video monitoring, alarms, and tamper protection for critical areas, the ISO control implements the CSF outcome of managing and enforcing physical access commensurate with risk.
- PR.IR-02mostlyaligns with — The ISO control's focus on continuous surveillance and intrusion detection directly supports the CSF outcome of protecting technology assets from environmental threats by using physical monitoring to detect unauthorized access.
- GV.OC-03partialaligns with — The ISO control's explicit requirement to comply with local laws, data protection, and PII legislation when implementing monitoring directly supports the CSF outcome of addressing legal and regulatory cybersecurity obligations.
- PR.PS-04partialaligns with — The ISO control's requirement to generate and protect surveillance recordings aligns with the CSF outcome of making log records available for continuous monitoring, extending that concept to physical security events.
- DE.CM-02implements — A.7.4 directly operationalizes physical monitoring to detect adverse events, which is exactly what DE.CM-02 requires
- GV.OC-03implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AA-06implements — A.7.4 directly operationalizes the monitoring and enforcement of physical access that PR.AA-06 requires
- PR.IR-02implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-04implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related weaknesses / CWE (9)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1263finds — Monitoring supports detection but does not itself prevent unauthorized physical access.
- CWE-1278finds — Monitoring can detect suspicious activity around sensitive hardware but does not prevent imaging itself.
- CWE-1300mitigates — Monitoring deters or detects attempts to exploit physical side channels.
- CWE-1384finds — Physical security monitoring can detect environmental anomalies or tampering.
- CWE-200finds — Tamper-proof alarm panels and restricted access to video feeds reduce the chance that an intruder can obtain or alter surveillance data that might expose sensitive system locations.
- CWE-284finds — Continuous video and sensor surveillance of physical entry points makes it harder for an attacker who has bypassed logical controls to reach or tamper with hardware without detection.
- CWE-732finds — Placing the alarm control panel inside an alarmed zone and protecting it with tamper-proof mechanisms limits an attacker’s ability to reconfigure physical security devices after gaining physical proximity.
Mitigated MITRE ATT&CK techniques (113)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1003.003detects — A.7.4's physical surveillance, alarms, and motion detectors can surface unauthorized physical access to a domain controller (or its backup media) as a precursor to NTDS extraction, but the technique itself is a logical credential-access action that can be performed entirely remotely or post-compromise without any physical breach.
- T1011.001detects — A.7.4's physical surveillance, motion/contact/sound detectors, and alarms can surface an adversary in sufficient proximity attempting Bluetooth exfiltration (a close-range physical act), but this is limited to observable physical presence/behavior and does not address the data transfer itself or non-physical vectors
- T1021.001detects — A.7.4 deploys physical surveillance, alarms, and motion detectors that can surface unauthorized physical presence at the RDP endpoint itself (e.g., an intruder at a console or server room), but the technique is a logical/remote network session that leaves no physical trace and is therefore unseen by the control in the dominant remote-use case.
- T1021.005detects — A.7.4's physical surveillance, alarms, and motion detectors can surface unauthorized physical access to VNC-enabled systems or devices (e.g., an intruder at a console or server room), but have no view of the network-based remote VNC session itself which is the technique's core.
- T1052detects — A.7.4's surveillance, alarms, and motion/contact detectors can surface suspicious physical access or device introduction in monitored premises (especially critical-system areas), but this is limited to observable entry/behavior and does not broadly detect the exfiltration act or data movement itself on the medium.
- T1052prevents — A.7.4's continuous physical monitoring (CCTV, motion/contact/sound detectors, alarms on doors/windows/rooms) can deter and enable response to an adversary physically introducing or removing a medium in monitored premises, but does not stop the exfiltration act itself once the medium is in an authorized user's hands or on an air-gapped system.
- T1052.001detects — A.7.4's surveillance, alarms, and video monitoring of physical premises and access points can surface suspicious USB device introductions or handling in monitored areas, but this is limited to observable physical behavior and does not address the data exfiltration technique itself once the device is connected or removed.
- T1055detects — A.7.4 deploys physical surveillance, alarms, and motion detectors that can surface anomalous human activity around systems (e.g., an intruder at a console), but has no instrumentation, telemetry, or scope that reaches in-process code execution or memory manipulation on Linux/macOS/Windows.
- T1070detects — A.7.4's surveillance, alarms, and video monitoring can surface physical tampering or anomalous access that might accompany selective indicator removal on-premises (e.g. altered logs tied to break-in), but the control is scoped exclusively to physical premises and has no view of digital artifacts, logs, command history, or file metadata on the listed platforms.
- T1074detects — physical premises surveillance (guards, CCTV, motion/intruder alarms) can surface staging activity only when it produces observable physical or facility-level indicators inside monitored buildings/rooms; the technique is predominantly logical/file-system behavior on ESXi/IaaS/Linux/macOS/Windows with no required physical footprint
- T1074.001detects — physical surveillance and alarms can surface suspicious local behavior (e.g. an adversary at a console or server room performing staging) but have no view of the technique when performed remotely or without triggering physical sensors
- T1078detects — A.7.4's physical surveillance, alarms, and motion detectors can surface suspicious physical behavior around facilities housing systems (e.g., unauthorized entry attempts that might precede credential abuse), but this has no view of the technique's core (credential compromise, logical pivoting, or inactive-account abuse across any listed platform).
- T1078.001detects — physical surveillance, alarms, and motion detectors can surface unauthorized physical access to premises or devices that might enable abuse of default accounts (e.g., on network appliances or ESXi hosts), but this is a minority slice of the technique which is overwhelmingly credential abuse over networks, remote services, or post-compromise without any physical component
- T1078.002detects — A.7.4's surveillance, alarms, and motion/contact detectors can surface physical attempts to access systems housing domain credentials (e.g., servers), but have no view of the technique's core methods like credential dumping or password reuse on the network or endpoints.
- T1078.003detects — physical monitoring (alarms, CCTV, motion detectors) can surface unauthorized physical access that precedes or accompanies local-account abuse on the compromised device, but has no view of purely logical credential use, dumping, or lateral movement
- T1091detects — Intruder alarms and tamper-proof sensors on doors and windows increase the chance that removable-media replication or data transfer through physical media will trigger an alert before the adversary can complete the action.
- T1110detects — A.7.4's physical surveillance, alarms, and motion detectors can surface physical tampering or unauthorized proximity that sometimes accompanies on-site brute-force attempts (e.g. against network devices or consoles), but the vast majority of T1110 occurs remotely or offline with no physical footprint.
- T1123detects — A.7.4 deploys physical sensors (motion, sound, contact) and video to detect unauthorized physical access or suspicious behavior in premises; this can surface the physical act of an adversary or malware interacting with a peripheral microphone/webcam in a monitored sensitive area (e.g., computer room), but does not detect the software technique, API calls, file writes, or exfiltration itself.
- T1125detects — A.7.4 deploys physical surveillance (CCTV, motion/sound detectors, alarms) that can surface unauthorized physical tampering with or proximity to a device’s camera, but has no view of the malware/script/API-driven digital capture of video once the adversary is inside the host.
- T1127.001detects — physical premises monitoring (CCTV, motion detectors, alarms) can surface anomalous physical access or tampering that precedes or accompanies launching MSBuild.exe on a monitored workstation, but has no view of the technique's execution, proxying, or code compilation itself
- T1133detects — A.7.4 deploys physical surveillance, alarms, and motion detectors that can surface unauthorized physical presence at facilities housing remote-service gateways or on-prem systems, but the technique is overwhelmingly logical/remote (VPN, exposed APIs, Tor hidden services, credentialed access from anywhere) with no physical component required.
- T1199detects — A.7.4's physical surveillance, alarms, and motion detectors can surface unauthorized physical presence by third-party infrastructure contractors (explicitly named in T1199 examples) before or during initial access, but this is a minority slice of a technique that is predominantly logical/network-based via compromised accounts, delegated admin relationships, and cloud tenants with no physical component.
- T1200detects — Continuous video and motion detection at entry points raises the likelihood that an adversary physically attaching or tampering with hardware will be observed or recorded, limiting covert hardware-introduction attempts.
- T1200prevents — continuous physical monitoring (alarms, CCTV, motion detectors on doors/windows/sensitive areas) deters and enables rapid response to unauthorized hardware additions in covered premises, but cannot stop all vectors such as social engineering, insider placement, or additions outside monitored zones/times
- T1211detects — A.7.4 deploys physical surveillance, alarms, and detectors that surface unauthorized physical access or suspicious behavior; this can detect some physical exploitation attempts that trigger those sensors but has no reach into the technique's dominant logical, software, logging, or cloud evasion vectors.
- T1218.004detects — surveillance, alarms, motion/sound detectors and video monitoring can surface physical access to a system where an adversary would need to be present to run InstallUtil locally, but the control has no view of the technique's execution, proxying, or signed-binary abuse once the adversary is on the host
- T1219.002detects — A.7.4's physical surveillance, alarms, and motion detectors can surface suspicious physical access to facilities housing systems that an adversary later uses for remote-desktop C2, but have no view of the logical technique itself once the session is established over the network.
- T1219.003detects — A.7.4's physical surveillance, motion/contact/sound detectors, and alarms can surface unauthorized physical installation or tampering with remote access hardware inside monitored premises, but this is limited to the physical act and does not address logical C2 use, post-compromise software bypass, or hardware already inside the environment.
- T1485detects — physical premises monitoring (CCTV, alarms, guards) can surface physical access or suspicious behavior that precedes or accompanies on-prem data-destruction activity, but has no view of remote, cloud, virtualized, or purely logical/credentialed execution of T1485
- T1489detects — A.7.4's physical surveillance, alarms, and motion/contact detectors can surface physical tampering or unauthorized presence that precedes or accompanies a local service-stop (e.g., an intruder at a server room console), but the technique is predominantly logical/remote (API, sc, net stop, cloud DisableAPIServiceAccess) with no physical prerequisite, leaving most executions outside the control's scope.
- T1496.001detects — physical monitoring (CCTV, alarms, motion detectors) can surface suspicious physical access that precedes or accompanies compute hijacking on on-prem servers/endpoints, but has no view of remote cloud/container compromise, API-driven deployment, or in-process resource consumption
- T1529detects — A.7.4 deploys physical surveillance, alarms, and motion detectors that can surface unauthorized physical presence or tampering preceding a local shutdown/reboot, but the technique is predominantly remote, API-driven, or privilege-based with no physical component, leaving most executions outside the control's scope.
- T1542detects — A.7.4's physical surveillance, alarms, and motion detectors can surface unauthorized physical access to premises or devices that would enable a pre-OS boot attack, but this is a minority slice of the technique (which is overwhelmingly a logical firmware overwrite performed remotely or after initial access, invisible to physical sensors).
- T1542.001detects — physical surveillance, alarms and motion detectors can surface unauthorized physical access that precedes or enables firmware modification on the device itself (e.g., evil-maid or supply-chain tampering), but the control has no view of the firmware-modification technique once it has already run on a booted or remote-managed system
- T1542.004detects — A.7.4's physical surveillance, alarms, and motion/contact detectors can surface local physical tampering or unauthorized access required to load a ROMMONkit (especially on-prem network gear), but miss remote TFTP-based overwrites, firmware-level changes, and non-physical persistence that the technique explicitly allows.
- T1546detects — A.7.4 deploys physical surveillance, alarms, and motion detectors that can surface unauthorized physical access events, but T1546 is a post-compromise software persistence technique (modifying OS/cloud event triggers) that operates entirely in logical space with no required physical component.
- T1546.017detects — A.7.4's physical surveillance, alarms, and motion/contact detectors can surface suspicious physical access (e.g., to insert a malicious USB device that triggers a udev rule), but this is unrelated to detecting the software persistence technique itself once the rule is installed and runs on Linux.
- T1547.010detects — A.7.4 deploys physical surveillance, alarms, and motion detectors that can surface anomalous physical access or tampering attempts that might enable the initial foothold for a Windows port monitor technique, but has no view of the registry, DLL loading, or boot-time execution itself.
- T1548.006detects — A.7.4's physical surveillance, alarms, and motion detectors can surface suspicious physical access (e.g., to a device where the adversary disables SIP or tampers with the TCC.db), but have no view of the macOS software technique itself.
- T1555.004detects — A.7.4's surveillance, alarms, and motion/contact detectors can surface physical access to a device (or its backups) as suspicious behavior before or during T1555.004 execution, but the technique itself is a post-access logical credential theft with no required physical component.
- T1557.004detects — A.7.4's video, motion, sound and alarm mechanisms can surface physical setup/deployment of a rogue AP (e.g. in a coffee shop or library) as suspicious behaviour or unauthorized access, but the technique is predominantly logical/network-layer and leaves no physical trace once the AP is placed, so only a minority slice is detected.
- T1561detects — A.7.4's physical surveillance, alarms, and motion/contact detectors can surface unauthorized physical access that precedes or enables direct disk-wipe actions on local systems, but the control addresses only the physical vector and is silent on remote, network-device CLI, or already-authorized logical wipes described in the bulk of T1561.
- T1561.001detects — A.7.4's physical surveillance, alarms, and motion/contact detectors can surface physical break-ins that enable direct disk access on premises, but the technique itself (software-driven disk overwrite, including remote/worm-like propagation) is outside physical monitoring scope
- T1561.002detects — A.7.4's physical surveillance, alarms, and motion/contact detectors can surface an intruder's physical presence or tampering needed to deliver disk-wipe malware to critical systems, but the technique itself (logical overwrite of MBR/partition structures via malware or CLI) occurs post-access on already-compromised hosts and is invisible to physical monitoring.
- T1563.001detects — A.7.4 deploys physical surveillance, alarms, and motion detectors that can surface suspicious physical behavior by an adversary who must first obtain local/root access on a Linux/macOS host before hijacking an active SSH agent socket, but the control has no view of the network, process, or SSH-session artifacts that actually constitute the technique.
- T1563.002detects — A.7.4 deploys physical surveillance, alarms, and motion detectors that can surface unauthorized physical presence at a console or device enabling the RDP hijack, but the technique itself is a logical/session-level attack (tscon.exe, remote or local) with no required physical component.
- T1564detects — A.7.4's physical surveillance, alarms, and motion/contact/sound detectors can surface physical hiding behaviors (e.g., tampering with doors/windows or unauthorized presence in alarmed zones) but have no view of digital artifact-hiding techniques (files, accounts, virtualization) that dominate T1564 across its platforms.
- T1565detects — A.7.4's surveillance, alarms, and monitoring are scoped exclusively to physical premises and unauthorized physical access; they can surface physical tampering that enables T1565 but have no view of logical data manipulation performed over the network or from an authenticated session on Linux/macOS/Windows platforms.
- T1565.001detects — A.7.4 deploys physical surveillance, alarms, and motion/contact detectors that can surface unauthorized physical access attempts needed to reach and manipulate stored data at rest, but this is limited to the physical vector only and does not address remote, logical, or insider manipulation of files/databases.
- T1567.002detects — A.7.4's physical surveillance, alarms, and motion detectors can surface suspicious physical access that precedes or enables the exfiltration (e.g., an intruder at a server room), but have no view of the network-based data transfer to cloud storage itself.
- T1669detects — A.7.4's surveillance, alarms, and motion/contact detectors can surface physical proximity or unauthorized presence needed for close-access Wi-Fi connection attempts (especially at premises housing critical systems), but this is only a minority slice of T1669 which also covers remote dual-homed bridging, open networks, and post-connection sniffing without any physical intrusion
- T1669prevents — A.7.4's physical monitoring (alarms, CCTV, motion detectors on doors/windows/premises) directly deters and detects the physical-proximity method of connecting to Wi-Fi networks, but leaves the remote dual-homed bridge method, open networks, and credential-based access untouched.
- T1685detects — A.7.4 deploys physical sensors (motion, contact, sound, video) and alarms that can surface physical tampering or disablement of those very monitoring components, but the technique is far broader (logical/host/cloud tool tampering, ETW, syslog, EDR, etc.) with most of its surface unreachable by physical premises monitoring.
- T1686detects — A.7.4's surveillance, alarms, and motion/contact detectors can surface physical tampering or unauthorized presence that often precedes or accompanies firewall modification on premises (e.g. ESXi hosts), but the control is silent on logical/network monitoring of the firewall-tampering action itself and its scope is limited to physical premises.
- T1687detects — A.7.4 deploys physical monitoring (CCTV, alarms, guards) that can surface physical tampering or disablement of those very sensors/panels as suspicious behavior, but the technique is overwhelmingly a logical exploit of software/EDR/firewalls (including remote SaaS/cloud cases) that physical premises monitoring does not observe.
Prevented OWASP Web Top 10 (2025) risks (4)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A09finds — A.7.4's surveillance, alarms, and detectors directly discover unauthorized physical access and suspicious behavior (a core slice of security-relevant events), but the control is scoped exclusively to physical premises and has no view of application/web-layer logging, alerting, or log-integrity failures that dominate A09:2025.
- A09mitigates — physical monitoring (alarms, CCTV, guards) can bound the consequence of undetected physical tampering that would otherwise let an attacker disable or compromise logging/alerting infrastructure, but does nothing about the software logging, alerting, or log-integrity failures that are the dominant members of A09
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.