A.7.6 Physical
Working in secure areas
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (10)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-3mostlyaligns with — Both controls restrict and monitor physical presence and activities inside protected areas to prevent unauthorized actions.
- PE-17partialaligns with — Both address security and safety procedures that must be followed when personnel operate in non-standard or protected physical locations.
- PE-2partialaligns with — Both require that only authorized individuals are permitted to enter and work within designated secure physical zones.
- PE-5partialaligns with — Both limit the introduction and use of endpoint devices that could capture or exfiltrate information from controlled areas.
- PE-6partialaligns with — Both emphasize ongoing observation of activities within secure physical spaces to detect and deter malicious behavior.
Aligned NIST CSF 2.0 outcomes (7)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-06mostlyaligns with — The ISO control enforces physical access restrictions and monitoring inside secure areas, directly supporting the CSF outcome of managing and enforcing physical access commensurate with risk.
- PR.AT-01partialaligns with — Personnel are made aware of secure-area rules on a need-to-know basis and shown emergency procedures, fulfilling the CSF requirement to give staff the knowledge needed to perform tasks securely.
- PR.IR-01partialaligns with — By restricting recording devices, unsupervised work, and visibility of activities, the control helps protect the environment from unauthorized logical or physical access and usage.
- PR.PS-04partialaligns with — Periodic inspections of vacant secure areas generate observable evidence that can be logged and made available for continuous monitoring.
Related weaknesses / CWE (8)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1263partialprevents — Defines rules for working in secure areas that reinforce physical access restrictions.
- CWE-1278partialmitigates — Rules for working in secure areas limit who can handle or image ICs.
- CWE-200partialprevents — Restricting knowledge of secure-area existence and activities to a need-to-know basis reduces the chance that sensitive information about protected assets will be exposed to unauthorized actors.
- CWE-284partialmitigates — Enforcing physical locks, supervision, and device controls in secure areas limits opportunities for unauthorized access to resources or functions that should be protected by access-control mechanisms.
- CWE-552partialmitigates — Banning unauthorized recording equipment and controlling endpoint devices prevents attackers from obtaining direct copies of files or directories that would otherwise be accessible inside the secure area.
- CWE-532nonenone — Limiting unsupervised presence and recording capability lowers the likelihood that sensitive operational details will be captured in logs, notes, or device storage that could later be inspected by unauthorized parties.
Mitigated MITRE ATT&CK techniques (6)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1005partialmitigates — Controlling endpoint devices and prohibiting unsupervised work reduces opportunities for adversaries to copy or exfiltrate data stored on local systems within the secure area.
- T1025nonemitigates — Restricting portable devices and media in secure areas limits the ability to collect data onto removable media for later exfiltration.
- T1056nonemitigates — Restricting recording devices and endpoint use in secure areas limits an adversary's ability to capture keystrokes, screen content, or other input from within the protected zone.
- T1113nonemitigates — Banning unauthorized cameras and recording equipment directly reduces the feasibility of capturing screenshots or video of sensitive information displayed on screens.
- T1123nonemitigates — Forbidding audio recording equipment in secure areas hinders adversaries from capturing spoken credentials, discussions, or other audible sensitive information.
- T1125nonemitigates — Prohibiting video recording devices prevents adversaries from covertly filming physical surroundings or displayed data to gather intelligence.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.