Priya Anand had been CISO at Alderney Mutual Insurance for eleven months when the call came in at 6:40 a.m. on a Tuesday. A senior claims adjuster's laptop had been stolen from a rental car outside a downtown Denver hotel during an industry conference. The laptop wasn't unusual — a standard-issue Dell Latitude, three years old, running the same endpoint protection stack as every other machine in the fleet. What made the call different was what was on it: a local, unencrypted export of 41,000 policyholder records the adjuster had pulled two weeks earlier to build a regional loss-ratio analysis, and never deleted.
Full-disk encryption had been "in progress" as a fleet rollout for six months. The adjuster's machine, provisioned before the rollout window, had been missed. Nobody had checked. There was no asset tag linking the device to a documented off-premises use approval, no record of what data had left the building, and no remote-wipe capability configured because the device predated the mobile device management (MDM) enrollment policy.
By the time outside counsel, forensic investigators, a credit-monitoring vendor, and two state insurance regulators had finished their work, Alderney's finance team had booked $2.4 million against the incident: notification costs for 41,000 policyholders across nine states, two years of credit monitoring, forensic reconstruction of exactly which records were on the device, a six-figure regulatory settlement in the adjuster's home state, and the unbudgeted hours of Priya's own team for the ninety days that followed. None of it involved a firewall, a phishing email, or a zero-day. It was a control that ISO 27001 spells out in six numbered clauses most implementers treat as an afterthought.
That's the gap this article closes: Annex A controls 7.8 through 7.13 — equipment siting and protection, security of assets off-premises, storage media, supporting utilities, cabling security, and equipment maintenance. Together they govern the physical machines, drives, cables, and power feeds that everything else in your ISMS — access control, encryption, backup — actually depends on. Get the "boring" physical layer wrong, and it doesn't matter how good your Annex A technological controls are on paper.
Who this is for
This is for the person who owns the Statement of Applicability line items for 7.8–7.13 and has to turn six sparse Annex A sentences into policies, physical measures, and evidence an auditor will accept — typically a CISO, IT operations manager, facilities lead, or compliance manager running a first-time or renewal ISO 27001 certification. You'll walk away with a defensible equipment-siting standard, an off-premises and remote-work asset policy with encryption and tracking requirements, a removable-media lifecycle policy, a utilities and power-resilience approach that won't get flagged in Stage 2, cabling protection guidance, and a maintenance regime with the records to prove it's real. If you're building Annex A control-by-control, this article assumes you've already read the physical controls overview and are ready to go deep on the equipment layer.
The six controls at a glance
Control | Name | Core question it answers | Typical owner |
|---|---|---|---|
7.8 | Equipment siting and protection | Is equipment physically placed and protected so threats and unauthorized people can't easily reach it? | Facilities / IT Ops |
7.9 | Security of assets off-premises | Are laptops, phones, and field equipment protected to the same standard once they leave the building? | IT Ops / Security |
7.10 | Storage media | Is removable media (USB drives, tapes, external disks) controlled from issue to disposal? | Records Management / IT |
7.11 | Supporting utilities | Will power, HVAC, and water failures be prevented from disrupting information processing? | Facilities / Data Center Ops |
7.12 | Cabling security | Is power and telecom cabling protected from interception, interference, and physical damage? | Facilities / Network Engineering |
7.13 | Equipment maintenance | Is equipment maintained correctly to preserve availability, integrity, and confidentiality? | IT Ops / Vendor Management |
These six sit inside the fourteen-control Physical theme (7.1–7.14) of Annex A, and they pick up where the perimeter and room-level controls covered in physical security perimeters and entry controls and securing offices, rooms, and facilities leave off. Those controls stop unauthorized people from reaching a room. 7.8–7.13 protect the equipment, media, and infrastructure inside that room — and, critically, outside it, once equipment leaves the building. If any of the terminology below is unfamiliar, our ISO 27001 glossary is a fast reference for the exact definitions ISO 27002:2022 uses.
Control 7.8: Equipment siting and protection
Equipment siting is the control most auditors assume is "obvious" and most organizations have never actually documented. ISO/IEC 27002:2022 frames it plainly: equipment should be sited and protected to reduce the risks from environmental threats and hazards, and opportunities for unauthorized access. That covers two very different failure modes. The first is environmental — a server rack under a bathroom on the floor above, a UPS room with no water detection sitting below a sprinkler main, a comms cabinet backed against an exterior wall that floods every spring. The second is access — a printer with cached print jobs sitting in an open reception area, a network switch in an unlocked closet visitors walk past, a workstation with an unlocked screen facing a lobby window.
Neither failure mode requires malice to hurt you. Priya's incident above wasn't caused by 7.8, but plenty of Alderney's peers have had cleaning contractors quietly photograph screens visible through un-shaded conference-room glass, or lost a rack of switches to a slow leak nobody noticed because the equipment room doubled as janitorial storage.
What "good" looks like in practice:
A documented equipment placement standard covering server rooms, comms closets, printer/copier locations, and end-user workstations, tied to a risk assessment (not a gut feeling about which corner has a free outlet).
Physical separation of high-value or high-sensitivity equipment from general foot traffic, food and drink areas, and public-facing space.
Environmental controls for anything beyond standard office equipment — temperature and humidity monitoring, water detection, and clean-agent fire suppression where the risk assessment warrants it.
Screen positioning and privacy filters for workstations that face windows, lobbies, or shared corridors, feeding into the same discipline covered in the clear desk and clear screen policy — but 7.8 is about where the screen sits, not what's left on the desk.
A rule against eating, drinking, or smoking near equipment that would suffer real damage from a spill.
Requirement | What good looks like | Evidence an auditor accepts |
|---|---|---|
Risk-based placement | Equipment sited using a documented risk assessment (fire, flood, dust, vibration, EMI, foot traffic) | Site risk assessment referencing specific rooms/racks, dated and owned |
Restricted physical access | Server rooms, comms closets, and equipment racks locked, with access limited to a named list | Access control list for the room, correlated to badge/key logs |
Environmental monitoring | Temperature, humidity, water leak, and smoke detection in server/comms rooms | Monitoring system export or facilities log showing alert thresholds and recent readings |
Screen and output protection | Screens and printers positioned away from public view; sensitive output not left in trays | Site walk-through photos/checklist; printer release-code configuration |
No consumables near equipment | Written rule against food/drink in server rooms and comms closets | Facilities policy plus signage; incident log showing zero related events |
"The site walk is where I catch more nonconformities than anywhere else in the audit. I'll ask to see the server room, and half the time there's a case of bottled water someone's storing on top of a UPS. It's a five-minute fix, but it tells me nobody's actually looking." — Marcus Webb, Facilities & Physical Security Manager, Alderney Mutual Insurance
Equipment siting also has to account for growth. A comms closet sized correctly for the network in year one is routinely repurposed as general storage by year three once a new switch stack goes in a different room — and the labeling, environmental monitoring, and access list rarely follow it. Build a review of equipment locations into your annual asset management inventory refresh rather than treating 7.8 as a one-time site survey.
Control 7.9: Security of assets off-premises
Control 7.9 is where Priya's incident actually lives. Once equipment or the data it carries leaves a building you control, every environmental and access assumption behind 7.8 disappears. ISO 27002:2022 requires equivalent protection for off-site assets, and explicitly extends that to laptops, phones, removable media, and equipment used for home or remote working, field service, and business travel.
The practical challenge is that "off-premises" isn't one scenario — it's at least four, each with a different risk profile: the laptop that goes home every night, the laptop that goes to a client site or conference, the field technician's ruggedized tablet that lives in a vehicle, and the home-office setup that's effectively a permanent secondary site under the remote working provisions. Each needs the same underlying protections — encryption, tracking, and an approval trail — but the controls have to flex for how the device is actually used.
Requirement | What good looks like | Evidence an auditor accepts |
|---|---|---|
Authorization to remove equipment | Formal approval before equipment leaves the premises, tied to the asset register | Equipment removal log or MDM enrollment record showing approver and date |
Equivalent protection off-site | Same encryption, patching, and endpoint protection standard applied regardless of location | Configuration baseline report; MDM compliance dashboard |
Physical protection while traveling | Guidance on not leaving devices unattended, in checked baggage, or visible in vehicles | Travel security guidance issued to staff; signed acknowledgment |
Loss/theft reporting | Clear, fast reporting path feeding into incident management | Incident tickets showing time-to-report and time-to-remote-wipe |
Insurance/liability coverage | Off-site equipment covered under corporate insurance, not left to the employee | Insurance policy schedule referencing IT equipment off-premises |
The single highest-leverage control in this whole cluster is full-disk encryption on every device that can leave the building, enforced and verified centrally — not "enabled by default and never checked." Alderney's post-incident review found the encryption rollout dashboard had been reporting "94% compliant" for months; nobody had drilled into which 6% and why. A stale exception list is functionally the same as no policy.
Off-premises and remote asset control table
Asset type | Encryption requirement | Tracking/inventory control | Travel-specific control |
|---|---|---|---|
Corporate laptop | Full-disk encryption, centrally managed keys | MDM-enrolled, asset-tagged, tied to named user | Never left unattended in vehicles; hotel safe or carried |
Mobile phone | Device encryption + remote wipe capability | MDM-enrolled, linked to identity management | Screen lock + biometric required before travel |
Removable media (in transit) | Encrypted container or hardware-encrypted drive | Logged out/in against media register | Hand-carried only for classified data; no checked baggage |
Field service tablet/rugged device | Full-disk encryption, offline-capable | Fleet inventory with asset tracking | Secured mount in vehicle; end-of-shift check-in |
Home office workstation/monitor setup | Same corporate endpoint build as office device | Recorded in asset register as "home deployed" | Home network security baseline (separate SSID, no shared use) |
"We stopped treating remote work as an edge case years ago — it's the default deployment model now. The mistake I still see is companies writing a beautiful remote-work security policy and then never checking whether the laptops actually match the policy. Encryption status has to be something you can pull a report on, not something you assume." — Renata Osei, Director of IT Operations, Kestrel Dynamics Manufacturing
Off-premises assets also intersect with asset management — specifically return of assets — and with access control, since a stolen device is only as dangerous as the access rights and cached credentials it carries. When an employee leaves or a contract ends, the off-boarding checklist has to reconcile against the off-premises asset register, not just the badge system — a gap that shows up constantly in internal audits of fast-growing companies.
Control 7.10: Storage media
Storage media control covers the full lifecycle of removable and portable media — USB drives, external hard disks, backup tapes, SD cards, and in some organizations' scope definitions, printed output — from acquisition through use, transport, storage, and disposal. ISO 27002:2022 ties the required protection level to the classification of the information the media holds, which means 7.10 can't be written as a single blanket rule; it has to flex by classification the same way your asset management and information classification scheme does.
Media control is also one of the more common areas where an organization's controls look fine on paper and fail in practice, because removable media is cheap, small, and easy to acquire outside official channels. An employee who needs to move a 20GB file to a client uses whatever USB stick is in the desk drawer, not the encrypted one IT issued eighteen months ago that's since been lost.
Requirement | What good looks like | Evidence an auditor accepts |
|---|---|---|
Media inventory | All corporate-issued removable media logged and tracked to an owner | Media register with serial numbers, custodians, and classification handled |
Encryption by classification | Hardware or software encryption required for media carrying confidential/restricted data | Procurement standard requiring encrypted media; sample device check |
Approved acquisition channel | Only IT-procured, approved media permitted; personal USB drives blocked or restricted | Endpoint policy (USB port control/DLP configuration) |
Secure transport | Media transported between sites via controlled courier or encrypted transfer, not personal carry-on for sensitive data | Courier/chain-of-custody log for physical media transfers |
Secure storage when not in use | Media stored in locked cabinets/safes when not actively in use | Facilities inspection log; storage cabinet access list |
Secure disposal/reuse | Media wiped or destroyed per classification before reuse or disposal | Certificate of destruction; degaussing/shredding vendor log |
"Tape media is the one people forget about because it feels like a legacy problem. We still found four unencrypted backup tapes in a courier bag that had been sitting in a supply closet for over a year, unaccounted for in any register. If it can hold data and it can walk out the door, it needs an owner and a log entry." — Tom Halvorsen, Records & Information Governance Lead, Bramwell & Voss LLP
Removable media policy table
Media type | Default classification handling | Encryption | Retention/reuse rule |
|---|---|---|---|
Corporate-issued USB drive | Confidential unless labeled otherwise | Hardware-encrypted (FIPS-validated where required) | Reissued only after certified wipe; logged in media register |
External backup/portable hard disk | Restricted (bulk data) | Full-disk encryption mandatory | Rotated per backup schedule; retired disks physically destroyed |
Backup tape (on-site/off-site rotation) | Restricted | Encrypted at write time | Chain-of-custody log for every off-site movement; retention aligned to information backup schedule (control 8.13) |
SD card/camera media (site surveys, field work) | Internal-use unless flagged | Encrypted container where feasible | Offloaded and wiped within 24 hours of field use |
Personal/unmanaged removable media | Not permitted for corporate data | N/A — blocked at endpoint | Blocked via DLP/USB control policy; exceptions require written approval |
Printed output containing classified data | Per document classification | N/A | Cross-cut shredding at end of life; no general recycling bin |
This lifecycle discipline mirrors requirements security teams already recognize from other frameworks — PCI DSS's media handling and destruction requirements for cardholder data are built on the same "control it from issue to destruction" logic, even though the standards use different language to get there.
The information backup control referenced above (8.13, logged as a new article below) governs how backup media specifically is retained and tested; 7.10 governs how any removable media — backup or otherwise — is handled physically. Where you decommission media entirely, the process should hand off cleanly into information deletion (control 8.10) for the data, and secure disposal or re-use of equipment (control 7.14) for the physical device — a boundary worth drawing explicitly in your policy so nobody assumes "wiped" and "destroyed" mean the same evidence.
Control 7.11: Supporting utilities
Supporting utilities control addresses the infrastructure everything else depends on and almost nobody in security thinks about day to day: electrical power, HVAC, water supply, and telecommunications feeds. ISO 27002:2022 requires protecting equipment from power failures and other disruptions caused by failures in supporting utilities — which in plain terms means: don't let a blown transformer, a failed chiller, or a burst pipe take down information processing that the rest of your ISMS assumes is always available.
This control sits right next to business continuity and ICT readiness in terms of intent — control 5.30 is about your organization's ability to keep ICT services running through a disruption at a strategic and planning level; 7.11 is the physical infrastructure layer that makes that possible. You can have a beautifully documented ICT continuity plan and still lose a data hall because nobody tested the automatic transfer switch between utility power and the backup generator.
Requirement | What good looks like | Evidence an auditor accepts |
|---|---|---|
Power redundancy | UPS coverage for all critical equipment; generator backup for extended outages | UPS runtime specification; generator maintenance/test log |
Load testing | UPS and generator tested under load on a defined schedule | Test reports with dates, load percentages, and results |
HVAC resilience | Redundant cooling (N+1 minimum) for server/comms rooms | HVAC maintenance contract and service records |
Water/leak protection | Leak detection and water shut-off near critical equipment | Facilities inspection log; leak detection alert history |
Utility monitoring | Real-time monitoring/alerting for power, temperature, humidity | Building management system (BMS) dashboard export |
Single points of failure documented | Utility dependency map identifying single feeds/circuits | Risk register entry referencing utility SPOFs with treatment plan |
Utilities and power resilience table
Element | Minimum baseline (small office) | Enterprise baseline (data center/critical site) | Test frequency |
|---|---|---|---|
UPS | Covers safe shutdown window (15–30 min) | N+1 redundant UPS, sized for full load plus growth | Load-tested quarterly |
Generator | Not always required | On-site diesel/gas generator with automatic transfer switch | Load-tested monthly; full-load test annually |
HVAC | Standard office HVAC, temperature alarm | Redundant precision cooling, hot/cold aisle containment | Preventive maintenance quarterly |
Water/fire | Smoke detection minimum | Water leak detection, clean-agent suppression, sub-floor sensors | Inspected per fire code plus annual test |
Utility feed | Single utility feed acceptable | Dual utility feeds from separate substations where available | Reviewed annually in BC/DR test |
Fuel supply (generator) | N/A | Contracted fuel resupply SLA (typically 24–72 hr runtime on-site) | Verified annually against contract |
"The generator test that actually matters is the one where you cut utility power without warning and watch what happens, not the scheduled Tuesday-morning test everyone's standing around for. We found our transfer switch had a firmware issue that only showed up on an unplanned cutover — two years of clean scheduled tests had never caught it." — Chidi Nwosu, Data Center Facilities Engineer, Solace Health Partners
For most PentesterWorld readers who aren't running their own data center, 7.11 scopes down considerably — a UPS sized to give a clean shutdown window, a documented relationship with the facility's landlord or colocation provider covering their power/cooling SLAs, and evidence that you've actually read and mapped those SLAs against your recovery time objectives. Auditors calibrate expectations to your actual infrastructure; what they won't accept is silence — no UPS runtime spec, no test record, no idea what the colocation provider's power redundancy actually looks like. The same environmental and power-resilience thinking shows up in SOC 2 audits: the Availability trust services criteria examine essentially the same UPS, generator, and HVAC evidence auditors ask for under 7.11, so organizations pursuing both frameworks can usually reuse one evidence package for both.
Control 7.12: Cabling security
Cabling is the control most frequently skipped entirely in first-time ISMS builds, because it's invisible once installed and rarely fails in an obviously security-relevant way. ISO 27002:2022 requires power and telecommunications cabling carrying data or supporting information services to be protected from interception, interference, and damage. That covers three distinct threats: someone physically tapping a cable run, electromagnetic interference corrupting or exposing signal (particularly relevant for older unshielded runs near heavy electrical equipment), and simple physical damage — a cable run through a public ceiling void that a contractor nicks while running HVAC ductwork.
Requirement | What good looks like | Evidence an auditor accepts |
|---|---|---|
Segregation of cable types | Power and data cabling run separately, with minimum separation distances observed | Cabling installation standard/as-built diagram |
Protection from interception | Sensitive runs use conduit, locked cable trays, or shielded cable in shared/public spaces | Site inspection; cabling contractor completion certificate |
Physical damage protection | Cabling routed away from high-traffic, high-risk areas; conduit used where exposed | Facilities walk-through; cable management standard |
Labeling and documentation | Cable runs labeled and mapped, tied to a current network diagram | As-built cabling diagram, patch panel labeling scheme |
Access to patch panels/distribution frames | Patch panels and main distribution frames in locked, access-controlled spaces | Access control list for comms rooms; patch panel photos |
Periodic inspection | Scheduled inspection of exposed or externally routed cabling | Inspection log/maintenance ticket history |
"Cabling security gets treated like an installation problem — something you solve once when the building's fitted out — instead of an ongoing control. I've walked into 'secure' comms rooms where the patch panel is locked but the cable tray running through the drop ceiling above the open-plan floor is completely exposed, unlabeled, and running through space three different contractors have keys to." — Dana Kowalski, Network Infrastructure Manager, Ferrous Bank
The practical fix for most organizations isn't a full rewire — it's documentation and containment. Get an as-built cabling diagram if one doesn't exist (most commercial fit-outs have one from the original contractor; ask facilities before assuming you need a full re-survey), confirm sensitive runs pass through locked or conduit-protected paths rather than open ceiling voids in shared-tenant buildings, and fold periodic cabling inspection into the same walk-through you're already doing for equipment siting. For leased space and multi-tenant buildings, this is also where landlord and property-management responsibilities need to be explicit in the lease or service agreement — you can't control what you don't have access to inspect.
Control 7.13: Equipment maintenance
Equipment maintenance is deceptively broad in ISO 27002:2022's framing: equipment must be maintained correctly to ensure the availability, integrity, and confidentiality of information. Availability is the obvious one — a server that fails because a fan filter was never cleaned is an availability incident. Integrity and confidentiality are less obvious but just as real: a third-party maintenance technician with unsupervised access to a device that still has cached credentials or unencrypted data on it is a confidentiality risk dressed up as a routine service call.
This control covers scheduled preventive maintenance, break-fix repairs, vendor and manufacturer service visits, and the decision points around when equipment gets patched, repaired, or retired. It's also one of the more evidence-rich controls to demonstrate, because maintenance activity naturally generates records — the challenge is usually consolidating scattered vendor tickets and warranty paperwork into something an auditor can actually review in one sitting.
Requirement | What good looks like | Evidence an auditor accepts |
|---|---|---|
Maintenance schedule | Documented preventive maintenance schedule by equipment type/criticality | Maintenance calendar/CMMS export with completed vs. scheduled |
Authorized maintenance personnel | Only approved internal staff or vetted vendors perform maintenance | Approved vendor list; NDA/contract on file |
Supervision of external technicians | Vendor technicians escorted/logged in sensitive areas | Visitor/escort log cross-referenced to maintenance tickets |
Data protection during maintenance | Data sanitized or encrypted before equipment leaves custody for repair | Data removal/encryption confirmation prior to RMA/repair shipment |
Maintenance records retained | Records of all maintenance activity, including remedial/emergency work | Maintenance log with date, technician, work performed, parts used |
Manufacturer recommendations followed | Maintenance intervals follow manufacturer/vendor specification | Vendor maintenance contract referencing specified intervals |
Warranty and support tracking | Equipment tracked against warranty/support expiry to avoid unsupported gaps | Asset register field for warranty/support end date |
Maintenance regime and records
Equipment category | Maintenance frequency | Who performs it | Record required |
|---|---|---|---|
Server/network hardware (critical) | Per manufacturer spec, minimum quarterly review | Internal IT plus vendor support contract | Ticket/CMMS record, firmware/patch level noted |
UPS/generator | Monthly visual, quarterly load test, annual full service | Certified electrical/facilities vendor | Signed service report retained 3+ years |
HVAC (server/comms rooms) | Quarterly filter/service, annual full inspection | HVAC contractor | Service report; temperature log correlation |
End-user laptops/desktops | As-needed break-fix; annual health check | Internal IT / authorized repair vendor | Repair ticket; data sanitization confirmation if off-site |
Printers/copiers (with local storage) | Per manufacturer schedule | Vendor under service contract | Service log; confirmation of storage wipe at contract end |
Physical security equipment (badge readers, CCTV) | Per manufacturer schedule, minimum semi-annual | Security systems vendor | Test/inspection log with functional confirmation |
"The maintenance record most companies are missing isn't the routine stuff — it's proof of what happened when a vendor technician had physical access to a device that still had data on it. If you can't show me the device was sanitized, escorted, or under an NDA before it left your custody for repair, I have to treat that as an open confidentiality question, not a maintenance question." — Yusuf Rahman, Maintenance & Vendor Manager, Alderney Mutual Insurance
Maintenance also has a lifecycle dimension: equipment past its supportable maintenance window (end-of-life hardware, unsupported firmware) is a growing and frequently underweighted risk. If your asset register doesn't flag warranty and support expiry dates, you'll find out equipment is unmaintainable at the worst possible moment — during an incident, not during a planning cycle.
The equipment lifecycle, end to end
Controls 7.8 through 7.13 aren't six independent checklists — they're checkpoints along a single asset lifecycle that starts at procurement and ends at disposal. Mapping them this way is also the fastest way to explain the cluster to an auditor or a skeptical budget owner: each control owns a specific stage, and gaps between stages — not within a single control — are where most real incidents originate. That's exactly what happened to Priya's stolen laptop, which fell through the crack between "asset provisioned" and "off-premises use approved."
flowchart LR
A[Procure equipment] --> B["Site & protect (7.8)"]
B --> C["Operate & maintain (7.13)"]
C --> D["Supporting utilities (7.11)"]
C --> E["Cabling security (7.12)"]
C --> F{Leaves premises?}
F -->|Yes| G["Off-premises use (7.9)"]
F -->|No| C
G --> C
C --> H["Media handling (7.10)"]
H --> I["Disposal / re-use handoff (7.14)"]
G --> IRead left to right: equipment is procured, sited and protected under 7.8, then enters an operate-and-maintain loop under 7.13 that depends on the utilities (7.11) and cabling (7.12) around it staying healthy. Any time that equipment or its media leaves the building, 7.9 and 7.10 take over protection, then the asset returns to the maintain loop or proceeds to disposal. Control 7.14 — secure disposal or re-use of equipment — sits just outside this article's scope but is the natural next read once you've got 7.8–7.13 in place.
Roles and responsibilities across 7.8–7.13
No single role owns all six controls, and pretending otherwise is how gaps open up between IT, facilities, and records management. A typical RACI split:
Activity | Facilities | IT Operations | Security/Compliance | Records Management |
|---|---|---|---|---|
Equipment siting decisions (7.8) | Responsible | Consulted | Accountable | Informed |
Off-premises asset policy (7.9) | Informed | Responsible | Accountable | Informed |
Media register and handling (7.10) | Informed | Consulted | Accountable | Responsible |
UPS/generator/HVAC (7.11) | Responsible | Consulted | Accountable | Informed |
Cabling security (7.12) | Responsible | Responsible | Accountable | Informed |
Maintenance scheduling and records (7.13) | Consulted | Responsible | Accountable | Informed |
Security or compliance typically holds accountability for the control existing and being evidenced, without necessarily performing the day-to-day work — that stays with facilities, IT operations, or records management depending on the control. Write this split into your ISMS roles documentation explicitly; "everyone assumes someone else logs the UPS test" is a more common finding than any single technical gap in this cluster.
Implementation roadmap: sequencing 7.8–7.13
Organizations building this cluster from zero rarely need to do all six simultaneously. A practical sequencing, drawn from how most PentesterWorld clients actually get through it:
Phase | Focus | Typical duration | Key output |
|---|---|---|---|
1 | Inventory and risk baseline | 2–4 weeks | Asset register updated with location, classification, off-premises status |
2 | Off-premises and media policy (7.9, 7.10) | 3–5 weeks | Policies published; encryption/MDM compliance verified, not assumed |
3 | Equipment siting and cabling review (7.8, 7.12) | 3–6 weeks | Site walk-throughs completed; as-built cabling diagram obtained or created |
4 | Utilities resilience (7.11) | 4–8 weeks | UPS/generator test schedule established; provider SLAs mapped |
5 | Maintenance regime (7.13) | Ongoing from month 2 | Maintenance calendar/CMMS live; vendor sanitization checkpoint added |
6 | Evidence consolidation and internal audit dry run | 2 weeks | Evidence pack assembled per control, ready for Stage 1/2 or surveillance |
Phases 2 and 5 tend to run longest in practice because they depend on behavior change — people actually logging media, vendors actually following a new sanitization step — rather than a one-time technical fix. Budget extra follow-up time there rather than treating "policy published" as "control implemented."
Common mistakes I see across 7.8–7.13
After walking this cluster of controls through dozens of certification and surveillance audits, the failure patterns repeat more than people expect:
Treating "off-premises" as an edge case. Once more than a handful of staff work remotely or travel regularly, off-premises is the default operating mode, not the exception — and the policy needs to be written that way, not bolted on as a footnote to an office-centric security policy.
Encryption dashboards nobody drills into. A "94% compliant" MDM report feels reassuring until you ask what's in the 6% and why it's been there for eight months.
No media register, or one that's stopped being updated. Media registers decay fast because issuing media is a five-second favor and logging it is a separate step people skip under deadline pressure.
UPS and generator tests that are too gentle to find real problems. A scheduled, announced test rarely replicates the failure conditions of a real outage — Chidi Nwosu's unplanned-cutover example above is the pattern to copy.
Cabling assumed "someone else's problem" in leased space. Multi-tenant buildings blur responsibility for cable pathway security; without an explicit clause in the lease or facilities agreement, nobody owns it.
Maintenance vendor access with no data sanitization step. Sending a failed drive back under warranty without first destroying or sanitizing it is one of the most common — and most avoidable — confidentiality gaps in this whole cluster.
Asset registers that don't track warranty/support expiry. Equipment quietly becomes unsupported and unpatchable, and nobody notices until an incident forces the question.
Mistake | Why it happens | Fastest fix |
|---|---|---|
Off-premises policy written as an exception, not the default | Legacy office-centric security thinking | Rewrite policy assuming remote/travel use is normal, not exceptional |
Stale encryption compliance dashboard | Nobody owns investigating the non-compliant tail | Assign named owner to chase every exception weekly until closed |
Media register not maintained | Issuing is fast; logging is a separate, skippable step | Bundle logging into the issuance workflow (e.g., ticketing system) itself |
UPS/generator tests too predictable | Scheduled, low-stress test windows | Run at least one unannounced load-shed test annually |
Cabling pathway ownership unclear in leased space | No explicit lease clause | Add cabling/pathway security responsibility to lease or facilities SLA |
No sanitization step before vendor repair/RMA | Treated as a logistics task, not a security task | Add mandatory sanitization checkpoint to the RMA/repair workflow |
Warranty/support expiry untracked | Asset register missing the field | Add warranty/support-end date as a mandatory asset register field |
Audit evidence checklist across the cluster
Control | Minimum evidence to have ready before an audit |
|---|---|
7.8 | Site risk assessment, room access list, environmental monitoring export |
7.9 | Off-premises authorization log, MDM/encryption compliance report, travel security guidance |
7.10 | Media register, encryption confirmation, chain-of-custody logs, destruction certificates |
7.11 | UPS/generator test reports, HVAC service records, utility single-point-of-failure risk register entry |
7.12 | As-built cabling diagram, comms room access list, cabling inspection log |
7.13 | Maintenance calendar/CMMS export, vendor NDA/contract, data sanitization confirmations |
Keep these six evidence sets in a single, clearly labeled folder structure mapped to control numbers — auditors move faster, ask fewer clarifying questions, and form a better impression of your ISMS maturity when evidence retrieval doesn't require five people and three systems to assemble on the spot.
Case study: the laptop that never made the encryption rollout
Alderney Mutual Insurance's $2.4 million lesson, introduced at the top of this article, became the forcing function for a full rebuild of controls 7.9 and 7.10. Within four months of the incident, Priya Anand's team had closed the encryption rollout gap entirely, moving from "94% compliant, unverified" to 100% verified full-disk encryption with automated weekly compliance reporting; implemented a formal off-premises equipment authorization workflow tied to the asset register, so no device leaves the building without a logged approval; and rebuilt the media register from scratch, reconciling it against procurement records to account for every removable drive issued in the prior three years. Fourteen were unaccounted for and presumed retired without a disposal record — each one became its own micro-investigation.
The regulatory settlement required an independent audit of remediation within twelve months. Alderney passed it, and used the same evidence package to sail through its next ISO 27001 surveillance audit with zero nonconformities against the physical controls theme — a notable turnaround for an organization that had, eleven months earlier, no documented equipment-siting standard at all. Priya's own framing of the turnaround, in a debrief with her audit committee, was blunt: the incident cost more than the entire three-year ISMS budget that preceded it, and every dollar of remediation was money that a properly resourced 7.9 and 7.10 implementation would have spent anyway — just without the forensic investigators and regulators watching.
Case study: the UPS that passed every test except the one that mattered
A regional healthcare network's data center — Solace Health Partners, where Chidi Nwosu leads facilities engineering — had passed eleven consecutive quarterly UPS load tests before a genuine utility outage during a summer storm took down primary power for fourteen minutes. The automatic transfer switch to backup generator failed to engage. Server infrastructure ran on UPS battery alone, which was sized for a clean shutdown window, not sustained operation, and began shedding non-critical load automatically at the nine-minute mark — including, briefly, one clinical scheduling system that clinicians needed during the outage window.
No patient data was lost or exposed, but the near-miss triggered a root-cause review that found the transfer switch firmware had a known defect requiring a manual override under certain fault conditions — a defect invisible to every scheduled test because scheduled tests didn't replicate the specific fault signature of the real outage. Solace's facilities team redesigned its test program around unannounced load-shed drills, upgraded the transfer switch firmware, and added the drill results as a standing agenda item in quarterly business continuity reviews tied to their broader ICT readiness planning. The estimated cost of the redesigned testing program was roughly $38,000 annually in vendor time and after-hours testing premiums — against an internal estimate that the near-miss, had it fully cascaded, would have cost several times that in a single clinical-system outage.
Case study: the media mishandling that surfaced during a routine audit
Bramwell & Voss, a mid-sized litigation support firm, discovered its exposure during what should have been a routine internal audit walk-through, not an incident. Tom Halvorsen's records governance team, preparing evidence for an ISO 27001 surveillance audit, went looking for the chain-of-custody log for a set of backup tapes rotated to off-site storage monthly. The log existed for the prior eighteen months — but four tapes from an eleven-month-old rotation cycle had no corresponding "received at off-site facility" confirmation. After two weeks of investigation involving the courier vendor and the off-site storage provider, the tapes were located, misfiled at the storage facility under an incorrect client code, unopened and with no evidence of unauthorized access.
No breach occurred, but the near-miss was treated as seriously as one internally, because it revealed the real gap: chain-of-custody confirmation had never been a hard gate, just an assumption that "the courier usually confirms." The firm rebuilt its removable media policy to require signed, time-stamped confirmation at every custody transfer point, with any unconfirmed transfer automatically escalating to records management within 24 hours rather than being caught, if at all, at the next audit cycle. The fix cost essentially nothing beyond a workflow change and roughly $6,000 in courier-side confirmation service fees annually — a rounding error next to what a genuine breach notification exercise across the firm's client base would have cost.
Turning equipment controls into a business advantage
It's tempting to file 7.8–7.13 under "facilities housekeeping" and move on to the controls that feel more strategically interesting. That's a mistake, and not just because auditors will find the gaps. Equipment and media controls are where physical security and information security visibly intersect for people outside the security team — the sales prospect touring your office, the client asking how their data is protected when your staff travel, the cyber-insurance underwriter pricing your policy after a site questionnaire. A well-run equipment protection program is one of the easiest parts of ISO 27001 to actually show someone, and showing it builds trust faster than describing a firewall rule ever will.
It's also cheaper to get right proactively than reactively. Every dollar figure in the case studies above — Alderney's $2.4 million, Solace's near-miss, Bramwell & Voss's near-breach — dwarfs the cost of the fix that would have prevented it. Encryption rollout verification, an unannounced UPS test, a chain-of-custody confirmation gate: none of these are expensive controls. They're controls that are easy to skip until the day they aren't.
If you're building or refreshing your Statement of Applicability, don't treat 7.8–7.13 as a box-ticking pass through six short Annex A sentences. Walk the actual site. Pull the actual encryption compliance report and look at the non-compliant tail. Ask facilities what the last unannounced generator test found. The gap between a paper policy and a real, evidenced control is exactly where these six controls tend to live — and it's exactly where an experienced auditor will look first.
For teams building this evidence base from scratch, PentesterWorld's Annex A — All 93 Controls at a Glance cheat sheet is a fast way to see where 7.8–7.13 sits against your full control set, and the ISO 27001 Mandatory Documents Checklist will confirm which policies from this article — equipment protection standard, off-premises asset policy, media handling policy — need to exist as named documents versus embedded procedure. If you're starting your equipment and media policies from a blank page, our Information Security Policy Template gives you a structured starting point, and the Complete ISO 27001 Implementation Guide eBook walks the full physical controls theme in sequence. Not sure where your current gaps sit across 7.8–7.13? Run our ISO 27001 Gap Analysis Tool against your current equipment, media, and utilities controls before your next internal audit — it's a faster way to find the "94% compliant, nobody checked the 6%" problem than waiting for an auditor to find it for you.
