A.7.6 Physical
Working in secure areas
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (14)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-3mostlyaligns with — Both controls restrict and monitor physical presence and activities inside protected areas to prevent unauthorized actions.
- PE-17partialaligns with — Both address security and safety procedures that must be followed when personnel operate in non-standard or protected physical locations.
- PE-2partialaligns with — Both require that only authorized individuals are permitted to enter and work within designated secure physical zones.
- PE-5partialaligns with — Both limit the introduction and use of endpoint devices that could capture or exfiltrate information from controlled areas.
- PE-6partialaligns with — Both emphasize ongoing observation of activities within secure physical spaces to detect and deter malicious behavior.
- PE-17covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PE-2covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PE-5covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PE-6covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (13)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-06mostlyaligns with — The ISO control enforces physical access restrictions and monitoring inside secure areas, directly supporting the CSF outcome of managing and enforcing physical access commensurate with risk.
- PR.AT-01partialaligns with — Personnel are made aware of secure-area rules on a need-to-know basis and shown emergency procedures, fulfilling the CSF requirement to give staff the knowledge needed to perform tasks securely.
- PR.IR-01partialaligns with — By restricting recording devices, unsupervised work, and visibility of activities, the control helps protect the environment from unauthorized logical or physical access and usage.
- PR.PS-04partialaligns with — Periodic inspections of vacant secure areas generate observable evidence that can be logged and made available for continuous monitoring.
- PR.AA-06implements — A.7.6 operationalizes physical-entry controls, monitoring, and enforcement inside secure areas to achieve the exact risk-commensurate physical-access outcome named by PR.AA-06
- PR.AT-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-04implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related weaknesses / CWE (7)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1263prevents — Defines rules for working in secure areas that reinforce physical access restrictions.
- CWE-1278mitigates — Rules for working in secure areas limit who can handle or image ICs.
- CWE-200prevents — Restricting knowledge of secure-area existence and activities to a need-to-know basis reduces the chance that sensitive information about protected assets will be exposed to unauthorized actors.
- CWE-284mitigates — Enforcing physical locks, supervision, and device controls in secure areas limits opportunities for unauthorized access to resources or functions that should be protected by access-control mechanisms.
- CWE-552mitigates — Banning unauthorized recording equipment and controlling endpoint devices prevents attackers from obtaining direct copies of files or directories that would otherwise be accessible inside the secure area.
Mitigated MITRE ATT&CK techniques (47)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1052prevents — A.7.6's rules on need-to-know awareness, no unsupervised work, locking vacant areas, and especially banning/controlling recording/endpoint devices in secure areas directly stop an insider from introducing or using removable media to exfiltrate data from air-gapped systems; the remainder is non-secure-area activity and external-personnel vectors.
- T1052.001prevents — A.7.6's rules on need-to-know awareness, no unsupervised work, locking vacant areas, and especially controlling endpoint devices (including banning unauthorized recording equipment) directly constrain an insider's ability to introduce or use a USB device for exfiltration in a secure area, but only for that slice of the technique — it does not address non-secure-area use, external USB introduction, or post-introduction hopping.
- T1091prevents — A.7.6's rules on need-to-know awareness, no unsupervised work, locking vacant areas, and especially controlling endpoint devices (incl. mobile/USB) and banning unauthorized recording equipment in secure areas directly constrain the insider or visitor who would load malware onto removable media or a mobile device to carry out T1091, but only for the subset of attacks originating inside a physically-secured facility; the technique's core vectors (external media, firmware modification, or air-gap bridging outside any secure area) remain untouched.
- T1113prevents — A.7.6 explicitly prohibits unauthorized recording equipment (including cameras in endpoint devices) in secure areas and controls their use, which directly stops the native/API screen-capture methods named in T1113 while the adversary is physically present in those areas; it does not address remote post-compromise tools or captures outside secure areas.
- T1123prevents — A.7.6 explicitly prohibits unauthorized recording equipment (including endpoint device cameras/microphones) in secure areas and controls their use, which stops the technique from executing inside those physical perimeters; this is only a slice of the technique's scope across all platforms and non-secure environments.
- T1125prevents — A.7.6 explicitly requires not allowing (i.e. prohibiting) photographic/video/recording equipment such as endpoint cameras in secure areas unless authorized, which directly stops the adversary technique of leveraging those same devices for video capture while the personnel are inside the protected physical space.
- T1200prevents — A.7.6's rules on need-to-know awareness, no unsupervised work, locking vacant areas, and controlling endpoint devices/recording equipment in secure areas directly stop many physical hardware-addition vectors (e.g. rogue devices, implants, or DMA tools) from being introduced by personnel; partial because the control is scoped only to secure areas and authorized insiders, leaving external supply-chain or non-secure-area insertions untouched.
- T1219.003prevents — A.7.6's rules on need-to-know awareness, no unsupervised work, locking vacant areas, and controlling endpoint devices (incl. cameras) in secure areas directly constrain physical installation and unsupervised use of remote access hardware like KVMs inside those perimeters, but leave post-compromise software-bypass use, non-secure-area deployment, and authorized legitimate tools untouched.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.