A.7.4 Physical
Physical security monitoring
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (10)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-6mostlyaligns with — Both controls require continuous monitoring of physical access points and areas containing critical assets to detect unauthorized entry or suspicious activity.
- PE-2partialaligns with — Surveillance and alarm coverage of sensitive areas helps verify that only authorized personnel are granted physical access, supporting the NIST authorization process.
- PE-3partialaligns with — The ISO control's use of alarms, detectors, and tamper protection on access points supports the enforcement of physical access restrictions required by the NIST control.
- PE-8partialaligns with — Video and alarm monitoring systems generate records of physical access events that align with the NIST requirement to maintain visitor access records.
- SI-4partialaligns with — The ISO control's monitoring of physical premises and alarm events parallels the NIST requirement for ongoing system monitoring to detect anomalies and unauthorized activities.
Aligned NIST CSF 2.0 outcomes (7)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- DE.CM-02mostlyaligns with — The ISO control's deployment of surveillance systems and intrusion alarms fulfills the CSF outcome of monitoring the physical environment to identify potentially adverse events.
- PR.AA-06mostlyaligns with — By requiring video monitoring, alarms, and tamper protection for critical areas, the ISO control implements the CSF outcome of managing and enforcing physical access commensurate with risk.
- PR.IR-02mostlyaligns with — The ISO control's focus on continuous surveillance and intrusion detection directly supports the CSF outcome of protecting technology assets from environmental threats by using physical monitoring to detect unauthorized access.
- GV.OC-03partialaligns with — The ISO control's explicit requirement to comply with local laws, data protection, and PII legislation when implementing monitoring directly supports the CSF outcome of addressing legal and regulatory cybersecurity obligations.
- PR.PS-04partialaligns with — The ISO control's requirement to generate and protect surveillance recordings aligns with the CSF outcome of making log records available for continuous monitoring, extending that concept to physical security events.
Related weaknesses / CWE (9)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1263mostlyfinds — Monitoring supports detection but does not itself prevent unauthorized physical access.
- CWE-1384mostlyfinds — Physical security monitoring can detect environmental anomalies or tampering.
- CWE-1278partialfinds — Monitoring can detect suspicious activity around sensitive hardware but does not prevent imaging itself.
- CWE-1300partialmitigates — Monitoring deters or detects attempts to exploit physical side channels.
- CWE-200partialfinds — Tamper-proof alarm panels and restricted access to video feeds reduce the chance that an intruder can obtain or alter surveillance data that might expose sensitive system locations.
- CWE-284partialfinds — Continuous video and sensor surveillance of physical entry points makes it harder for an attacker who has bypassed logical controls to reach or tamper with hardware without detection.
- CWE-732partialfinds — Placing the alarm control panel inside an alarmed zone and protecting it with tamper-proof mechanisms limits an attacker’s ability to reconfigure physical security devices after gaining physical proximity.
Mitigated MITRE ATT&CK techniques (2)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1200mostlydetects — Continuous video and motion detection at entry points raises the likelihood that an adversary physically attaching or tampering with hardware will be observed or recorded, limiting covert hardware-introduction attempts.
- T1091partialdetects — Intruder alarms and tamper-proof sensors on doors and windows increase the chance that removable-media replication or data transfer through physical media will trigger an alert before the adversary can complete the action.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.