The propped-open door that cost Castellane Health Partners $1.8 million
Renn Okafor had walked past that door probably four thousand times in six years. It was the server room on the third floor of Castellane Health Partners' regional claims-processing center — a mid-size third-party administrator handling health insurance claims for about 340,000 members across two states. The door had a badge reader. It had a sign that, in smaller print than anyone had bothered to update, still referenced a decommissioned access-control vendor. And on a Tuesday morning in March, it had a fire extinguisher wedged against it, propping it open, because a rack technician doing a two-hour cable pull hadn't wanted to keep badging in and out.
Renn found it at 11:40 a.m., closed it, and moved on. He didn't think much of it — this had happened before, and it would happen again. What he didn't know was that between 9:15 and 11:40 that morning, a contractor from the building's cleaning service, whose access badge had been cloned three weeks earlier by a subcontractor with a grudge over an unpaid invoice, had walked the corridor twice. The door was propped open both times. On the second pass, at 10:52, he stepped inside for ninety seconds, plugged a USB drive into an idle console port on a rack switch, and walked out. Nobody saw him. The room had no camera — that was a Control 7.4 gap, not 7.3, but it compounded the problem. The room did have a lock and a badge reader, which is precisely why nobody worried about it: the access control existed on paper, and that was where its diligence stopped.
It took four months for Castellane's security team to piece together how a credential-harvesting implant ended up on a switch that fed twelve claims-processing servers. By the time they did, the incident had metastasized into a breach notification obligation covering roughly 61,000 members, a forensic investigation, two state attorney-general inquiries, and the quiet loss of a health-plan client contract worth an eight-figure sum over its remaining term. Total direct cost: $1.8 million, not counting the reputational drag that took eighteen months to fully dissipate. The root cause, when the incident report finally landed on the CEO's desk, wasn't a firewall failure or a phishing email. It was a door. A door that was locked in the access-control system's logs and open in the physical world, in a room that anyone walking the public-facing corridor to the break room could see straight into through a glass panel, with a rack label visible from six feet away reading "CLAIMS-PROD-CORE."
Every element of that failure — the visible sensitive space, the door that could be defeated by a fire extinguisher and social pressure, the labeling that told an intruder exactly what he was looking at, the absence of a room-sensitivity policy that would have flagged this space as requiring escort and no-prop enforcement — is what ISO 27001 Control 7.3, Securing offices, rooms and facilities, exists to prevent. This is the control that takes the physical perimeter established by physical security perimeters and entry controls and pushes it inward, room by room, matching the level of protection to what's actually inside.
"Access control on a door is a promise, not a guarantee. Control 7.3 is where you go back and check whether the promise is actually being kept, room by room, for the spaces where a bad five minutes turns into a seven-figure incident." — Renn Okafor, IT Infrastructure Manager, Castellane Health Partners
Who this is for
This article is for facilities managers, IT infrastructure leads, physical security consultants, and ISMS implementers who are working through Annex A's physical controls and need a concrete, room-level plan for Control 7.3 — not a restatement of the standard, but a practitioner's approach to classifying rooms by sensitivity, hardening each tier appropriately, handling siting and signage correctly, and producing the evidence an auditor will actually accept. If you've already read the broader physical controls overview and the perimeter-and-entry deep dive, this is the next layer down: what happens once someone is legitimately inside the building, and which internal doors still need to stop them.
What Control 7.3 actually requires
ISO/IEC 27001:2022 Annex A Control 7.3 states, in full: "Physical security for offices, rooms and facilities shall be designed and implemented." That's the entire normative text — deliberately broad, because the standard expects you to apply judgment based on what each space contains and what would happen if that protection failed. ISO/IEC 27002:2022's implementation guidance fills in the intent, and it clusters around five themes I'll use as the backbone of this article:
Site sensitive facilities to avoid public access and observation. Don't put server rooms, executive offices, or R&D labs where they can be seen from a lobby, a public corridor, a parking lot, or a neighboring tenant's windows.
Protect against unauthorized access with controls proportionate to sensitivity. A supply closet and a comms room are not the same risk, and they shouldn't get the same lock.
Keep directories, signage, and floor plans from revealing sensitive locations. A lobby directory that says "Data Center — 3rd Floor, East Wing" is doing an attacker's reconnaissance for them.
Secure server and communications rooms specifically, because they concentrate risk in a way that a typical office does not — a single unlocked comms closet can expose an entire floor's network segment.
Account for health and safety regulations alongside security — fire codes, emergency egress, and accessibility requirements interact with locking strategy, and 7.3 has to be implemented in a way that doesn't create a life-safety violation.
Control 7.3 sits in the physical theme alongside thirteen other controls, and it's most useful when you understand its neighbors rather than treating it in isolation. Physical security perimeters and entry controls (Controls 7.1 and 7.2) establish the building-level boundary and who gets through the front door. Control 7.4, Physical security monitoring, adds the cameras and alarms that watch what happens after that. Control 7.5, Protecting against physical and environmental threats, covers fire, flood, and power events. Control 7.6, Working in secure areas, governs behavior once people are inside a restricted zone — visitor escort, no-photography rules, and so on. Control 7.11, Supporting utilities, covers the power and HVAC that keep a secured room actually functioning. Control 7.3 is the hinge between all of them: it's the control that says this specific room, because of what's in it, needs this specific combination of siting, structural hardening, and access restriction — and then leans on 7.4 through 7.6 and 7.11 to fill in the monitoring, behavioral, and environmental detail.
A note on scope, because auditors ask this constantly: Control 7.3 is not only about IT infrastructure. It applies to any room whose contents or activities carry elevated confidentiality, integrity, or availability risk — finance offices where wire transfer approvals happen, HR rooms holding personnel files, executive suites where M&A discussions occur, R&D labs with prototype hardware or proprietary formulas, and yes, server and communications rooms. The standard doesn't hand you a list. You build one, based on what a walk-through of your own facility actually turns up.
Facility design principles: get these right before you buy a single lock
Every facility security program I've reviewed that failed an audit or, worse, failed in production, skipped straight to hardware — better locks, more cameras, a fancier badge system — without first getting the underlying design principles right. Hardware fixes symptoms. Design principles fix the conditions that create the symptoms in the first place. Five principles do most of the work.
Principle 1: Sensitivity drives siting, not convenience. The single most common mistake I see is a server room placed wherever there happened to be spare floor space when the building was fitted out — often near a lobby, a loading dock, or an exterior wall, because that's where the empty room was. Sensitivity should be decided first, and the room assigned to a location second. High-sensitivity spaces belong in building interiors, away from exterior walls (which are vulnerable to forced entry and environmental exposure), away from public circulation routes, and ideally not on a ground floor with street-facing windows or a floor immediately below a public restroom or kitchen (water damage risk feeds directly into Control 7.5's environmental scope, but it starts with a 7.3 siting decision).
Principle 2: Layered access, not flat access. A visitor who can badge into the building lobby should not be one badge swipe away from the server room. Effective facilities build concentric rings — public zone, general employee zone, restricted zone, high-security zone — and each ring requires a separate authorization decision to cross, ideally on a different credential tier. This is the physical equivalent of network segmentation, and I use exactly that analogy with clients who come from an IT background: you wouldn't let every authenticated user reach your domain controllers with a single login, so don't let every badge holder reach your server room with a single swipe.
Principle 3: Observability is a vulnerability. Glass walls, open-plan sightlines, and "transparency" as an architectural value are genuinely good for collaboration and genuinely bad for a comms room, an executive boardroom during a board call, or an R&D bench. If a sensitive activity or asset can be seen from a public corridor, a lobby, an adjacent building, or a street, the room fails 7.3's intent regardless of how good its lock is. I've walked into more than one glass-fronted "innovation lab" where a competitor could photograph a prototype from the sidewalk with a phone camera.
Principle 4: Minimize disclosure of what a room is. Signage, floor directories, org charts posted near reception, and even generic labeling conventions ("Room 304 — Data Center") all leak reconnaissance value to anyone casing a building, whether that's a social engineer, a disgruntled ex-employee, or an opportunistic thief. Neutral room numbering with no descriptive label, absent from public directories, is a small design choice with outsized payoff.
Principle 5: Design for the failure mode, not just the steady state. A propped door, a tailgated visitor, a badge reader in fail-open mode during a power cut — these are the actual conditions under which most physical breaches happen, not a clean forced-entry scenario. Facility design has to account for how a control degrades under real operating pressure: a busy loading dock, a fire drill, a contractor rush job. Renn Okafor's fire-extinguisher door prop is the textbook version of this — the room was designed around the assumption that the door would behave as configured, and nobody designed for the moment someone found it inconvenient.
"I ask every client the same question during a facilities walkthrough: if I were a stranger with a clipboard and a confident walk, how far could I get before someone stopped me? In about a third of the buildings I assess, the honest answer is 'to the server room.'" — Marcus Bell, Physical Security Consultant, Ironclad Risk Advisors
Room-sensitivity classification: the foundation everything else builds on
You cannot proportion physical controls without first classifying rooms by sensitivity, in the same spirit as asset management under ISO 27001 classifies information. I use a four-tier model with clients, and it maps cleanly onto both risk assessment and audit evidence.
Tier | Definition | Typical Rooms | Who Gets In | Consequence of Compromise |
|---|---|---|---|---|
Public | Areas open to visitors, customers, or the general public with no escort required | Lobby, reception, public restrooms, customer-facing meeting rooms | Anyone | Low — no sensitive assets present by design |
General | Employee work areas with routine business information | Open-plan desks, standard meeting rooms, break rooms, general storage | Employees and escorted visitors | Moderate — clear desk violations, casual observation of screens or documents |
Restricted | Areas holding confidential business information or limited-scope sensitive systems | Finance office, HR office, legal files room, print/mail room with sensitive output | Authorized role-based personnel, logged visitor access | High — financial fraud, privacy breach, regulatory exposure |
High-security | Areas where compromise threatens core operations, intellectual property, or a large population of data subjects | Server room, comms/MDF room, executive boardroom during sensitive sessions, R&D lab, key/credential vault | Named individuals, dual-control for some tasks, logged and monitored access | Severe — operational outage, IP theft, mass data breach, regulatory penalty |
Classification isn't a one-time exercise. I recommend re-running it whenever a room's use changes — a storage closet that becomes a network aggregation point, a meeting room that starts hosting board sessions, a lab that starts holding pre-patent prototypes — and as part of the annual internal audit cycle referenced in Clause 9. The classification also needs to be documented somewhere durable — a facility register, not tribal knowledge — because that register is exactly what an auditor will ask to see as evidence that Control 7.3 was "designed," not improvised.
One nuance worth flagging: sensitivity tier and access-control sophistication should scale together, but they don't have to scale together in cost. A restricted-tier HR office doesn't need a mantrap; it needs a good lock, restricted keying, and a policy against propping the door. Over-engineering a moderate-risk room wastes budget that a genuinely high-security room — the one holding the domain controllers — actually needs.
Hardening measures by room type
The classification tier tells you how much protection a room needs. This section tells you what that protection actually looks like for the six room types I encounter most often in facility assessments. Start with the summary matrix, then use the room-specific checklists for implementation detail.
Room Type | Sensitivity Tier | Wall/Door Construction | Access Method | Observation Control | Monitoring Baseline (feeds 7.4) |
|---|---|---|---|---|---|
Reception/lobby | Public | Standard | Unlocked, staffed or receptionist-controlled | N/A — intentionally open | Camera at entry, visitor log |
Server room | High-security | Slab-to-slab walls, solid core or rated door | Badge + PIN or biometric, no shared credentials | No windows; interior location | CCTV, door-forced/held alarms, entry log |
Comms/MDF room | High-security | Slab-to-slab walls, solid core door | Badge, restricted list | No windows; unlabeled | CCTV or door contact alarm, entry log |
Finance/HR office | Restricted | Standard with solid door | Badge or restricted key, no master-key sharing | Blinds/frosted glass on interior windows | Door contact alarm optional |
Executive suite/boardroom | Restricted–High (context-dependent) | Standard to reinforced | Badge, calendar-gated for board sessions | Non-transparent walls facing corridors; sound dampening | Camera at corridor approach |
R&D lab | High-security | Reinforced walls, solid core or rated door | Badge + logged sign-in, escort for visitors | No exterior-facing windows or covered glass; no photography policy | CCTV, motion sensors after hours |
Server room
The server room is the room every 7.3 assessment starts with, and for good reason — it's usually the single highest-consequence space in the building. Requirements I treat as non-negotiable:
Control Element | Minimum Standard |
|---|---|
Location | Interior room, not on an exterior wall, not below a bathroom/kitchen, not adjacent to a loading dock |
Wall construction | Slab-to-slab (real ceiling to real floor, not just to a drop ceiling grid, which anyone can push aside and climb through) |
Door | Solid core or fire-rated, self-closing, no propping mechanically possible without triggering an alarm |
Access credential | Badge plus PIN or biometric for named individuals only; no shared or generic "IT" badge |
Windows | None, or glazed with obscured/reinforced glass if legacy building constraints require it |
Signage | No exterior label indicating server room, data center, or similar |
Visitor policy | Logged, escorted, time-boxed access for vendors and contractors — ties directly into Working in Secure Areas, Control 7.6 |
Fire suppression | Clean-agent or pre-action system appropriate to electronic equipment (a Control 7.5 environmental concern that has to be designed into the room from day one) |
Renn Okafor's incident traces to exactly two failures on this list: a door that could be physically propped without triggering an alarm, and a room visible enough from a public corridor that its purpose was obvious. Fixing either one alone would likely have prevented the breach.
Communications/MDF room
Comms rooms and main distribution frames get less attention than server rooms because they often look unglamorous — a wall of patch panels, not a rack of blinking servers — but a compromised comms closet gives an attacker physical access to an entire floor's or building's network segment. I've seen comms rooms used as general storage, propped open by janitorial staff for cart access, and left with an unlocked door because "there's nothing valuable in there, it's just cables." That's backwards: it's because it's just cables, and those cables terminate everything, that it needs the same tier of protection as the server room itself.
Control Element | Minimum Standard |
|---|---|
Access credential | Badge, restricted access group distinct from general IT staff list |
Storage discipline | No general storage — janitorial supplies, spare furniture, and boxes do not belong in an MDF room |
Landlord/building coordination | Written agreement on who else (building engineers, other tenants) can access a shared MDF, with logging |
Cable labeling | Patch-panel and port labeling kept inside the room only, never duplicated on public-facing documentation |
Environmental tie-in | Dedicated cooling and UPS coverage, coordinated with Control 7.11 |
Comms rooms are frequently shared with building management or a landlord in multi-tenant properties, which I address separately below.
Finance and HR offices
These rooms hold personally identifiable information, payroll data, wire-transfer authority, and disciplinary records — restricted tier, not high-security, but still a step above general office space. The practical hardening list:
Control Element | Minimum Standard |
|---|---|
Door | Solid door with a real lock (not a privacy latch), no propping during business hours |
Key/credential control | Restricted keying — not on the building master key, or if on a badge system, a distinct access group |
Visual privacy | Blinds or frosted film on any interior glazing facing a corridor |
Document handling | Locking file cabinets for physical HR/finance files, aligned with Clear Desk and Clear Screen, Control 7.7 |
After-hours access | Logged, exception-based only |
Executive suites and boardrooms
Executive areas are context-dependent — a CEO's office used for routine work is closer to general/restricted, but the same room during an M&A negotiation or board session becomes momentarily high-security. Design for the worst case that will realistically occur there: sound-dampened walls (conversations carry further than people expect through standard drywall), non-transparent sightlines from adjoining corridors, and calendar-gated access controls so that a board meeting automatically restricts badge access to the invite list for its duration. I've had more than one client discover, during a walkthrough, that their boardroom had a glass wall facing an open-plan area where analysts sat close enough to read a projected screen.
Control Element | Minimum Standard |
|---|---|
Sightlines | No uncovered glass facing open-plan or public circulation areas |
Acoustic control | Sound-dampening wall assembly or acoustic treatment sufficient to prevent corridor eavesdropping |
Access during sensitive sessions | Calendar-linked, invite-list-only badge access for board or M&A sessions |
Device policy | No unmanaged recording devices; visitor phones/devices logged for board-level sessions |
Document handling | Locking storage for physical board packs, cleared immediately after sessions |
"Boardrooms get treated like a status symbol, all glass and visibility, right up until the day the numbers on that screen are a pending acquisition target. Then everyone wants blinds installed yesterday. Design it right the first time." — Dana Whitfield, CISO, Bellcrest Financial Group
R&D and product labs
Labs holding prototypes, proprietary formulas, or pre-patent designs need the same structural rigor as a server room, plus controls aimed specifically at intellectual-property leakage rather than data confidentiality alone: no-photography policies enforced with signage and spot checks, visitor logs with NDA acknowledgment, covered or absent exterior-facing glazing, and — increasingly common in biotech and hardware clients I work with — a policy that visiting vendors and contractors are escorted at all times, not just badged in once and left alone. This is where 7.3's siting principle and Control 6.6 (confidentiality agreements) intersect directly with intellectual property protection under Control 5.32.
Control Element | Minimum Standard |
|---|---|
Glazing | No uncovered exterior-facing glass; frosted film or interior-only layout |
Photography/recording | Signed no-photography policy, enforced with signage and periodic spot checks |
Visitor handling | NDA acknowledgment plus escort for all non-employees, no exceptions for "quick" visits |
Prototype/sample storage | Locked storage separate from general bench workspace when not actively in use |
IP tie-in | Documented linkage to intellectual property protection under Control 5.32 |
Reception and lobby
The one deliberately open room on this list, but 7.3 still applies: the lobby's job is to be the last public-tier space before every other tier begins, which means its design should make the transition from public to controlled unambiguous — a staffed desk or turnstile, a clear "authorized personnel beyond this point" boundary, and critically, no line of sight from the lobby into anything above general tier. A lobby with a glass wall overlooking an open-plan finance team's screens, which I've seen more than once in ground-floor fintech offices, defeats the entire point of having a reception control in the first place.
Control Element | Minimum Standard |
|---|---|
Staffing/coverage | Staffed desk during business hours, or a monitored kiosk with intercom outside them |
Boundary clarity | Physical or signed boundary marking where public access ends and controlled access begins |
Sightlines beyond reception | No visibility into general, restricted, or high-security tier areas from public seating |
Visitor registration | Sign-in with host notification for anyone proceeding past the lobby boundary |
Directory content | Generic tenant/floor listing only — no room-level or department-level sensitive detail |
"The lobby is where I judge a facility in the first ninety seconds. Can I see a whiteboard with real numbers on it? Is there a directory telling me which floor has the server room? Nine times out of ten, the lobby tells me exactly how seriously the rest of the building takes 7.3." — Priya Nandakumar, Facilities & Security Director, Voss Manufacturing
Siting and signage: the do's and don'ts that get missed
Siting and signage decisions are cheap to get right during a lease negotiation or office fit-out and expensive to fix afterward — moving a server room after occupancy means downtime, cabling rework, and often a change-management process spanning weeks. Get these decisions made early, and revisit them every time a floor plan changes.
Do | Don't |
|---|---|
Locate high-security rooms in the building interior, away from exterior walls and public sightlines | Place a server or comms room against an exterior wall or a ground-floor street-facing façade |
Use neutral room numbers with no descriptive label on doors or in directories | Label a door "Data Center," "Server Room," or "Wire Room" where visitors or the public can read it |
Keep sensitive-room references out of lobby directories, wayfinding maps, and public floor plans filed with the landlord | Publish a floor plan (even for fire-code posting) that names sensitive rooms without a redacted or generic version for public display |
Route public and visitor circulation paths away from restricted and high-security zones entirely | Route the shortest path from the lobby to the break room past the comms closet, "because it was convenient" |
Use obscured, frosted, or covered glazing on any interior window facing a corridor for restricted/high-security rooms | Leave glass panels, sidelights, or interior windows uncovered on doors to sensitive rooms |
Reference sensitive locations by internal code in maintenance tickets, vendor work orders, and building management system labels | Let a vendor work order or building-system label spell out "Data Center — Floor 3" where a subcontractor with no need-to-know can read it |
Train reception and facilities staff to redirect, rather than answer, questions like "where's your server room?" | Let front-desk staff casually answer that question because "everyone in the building already knows anyway" |
The public-directory point deserves emphasis because it's the one I see violated most often, usually by people with no bad intent: a building lobby's digital directory board, configured by whoever set up the tenant improvement, that cheerfully lists "Suite 310 — IT / Data Center." Fire marshals and code officials sometimes require floor plans that show mechanical and electrical rooms; where that's unavoidable, ISO 27002's guidance on health and safety interplay (echoed in Control 7.5) means you satisfy the code requirement with the minimum disclosure that meets it — a generic "Mechanical/Electrical" label rather than one that flags a specific room as an attractive target, and restrict who can view the full-detail version.
Shared offices, co-working spaces, and multi-tenant buildings
A growing share of the organizations I assess don't control their own building — they lease a floor or a suite inside a multi-tenant office building, or they run entirely out of a co-working space. Control 7.3 doesn't get easier in that scenario; it gets harder, because you're negotiating physical security with a landlord or a shared-space operator whose interests aren't identical to yours.
Scenario | Primary Risk | Practical Mitigation |
|---|---|---|
Shared building, dedicated suite | Shared lobby, shared elevators, shared building-wide comms/MDF room accessible to other tenants' contractors | Negotiate a lease rider requiring landlord notification before any access to shared comms infrastructure; install your own lockable sub-enclosure inside a shared MDF room |
Co-working space, dedicated office within the space | Shared reception, shared meeting rooms, cleaning and maintenance staff with broad access | Use a private, lockable room for anything restricted or above; never hold restricted-tier conversations in bookable shared meeting rooms without confirming no adjacent glass walls or thin partitions |
Co-working space, hot-desk / open plan only | No dedicated restricted space at all | Treat the entire physical environment as public tier; prohibit processing of restricted or high-security information on-site, and route that work to a controlled alternative location |
Serviced office with shared IT closet | Building-provided network equipment shared across tenants in a single rack | Require your own locked cage or cabinet within the shared room, contractually, and confirm in writing who holds spare keys |
The recurring theme across all four scenarios: in a space you don't fully control, your Control 7.3 obligations don't disappear — they shift into contract language, lease riders, and documented compensating controls. An auditor assessing an organization in a co-working space will expect to see exactly this kind of documented risk acceptance or compensating control, not a shrug that says "we don't own the building, so it doesn't apply to us."
"The startups I work with almost always get this wrong first: they assume that because they're renting three desks in a co-working space, ISO doesn't care about the room. It cares more, not less, because you have less control and need to document how you compensated for that." — Tomas Ligeti, Lead ISO 27001 Auditor, Meridian Assurance Group
Environmental and safety interplay: 7.3 doesn't operate alone
Physical security for a room and environmental protection of that same room are two sides of one design decision, and the standard treats them as separate controls precisely because they require different expertise — but they have to be designed together or you end up with a room that's secure against intruders and defenseless against a burst pipe. The table below maps where 7.3's siting and access decisions hand off to its environmental and utility neighbors.
7.3 Decision | Hands Off To | Why It Matters |
|---|---|---|
Siting a server room away from exterior walls and away from floors below restrooms/kitchens | Control 7.5, Protecting against physical and environmental threats | Water ingress and temperature extremes are environmental risks that start with a siting choice made under 7.3 |
Restricting who can enter a high-security room | Control 7.6, Working in secure areas | 7.3 decides which rooms are restricted; 7.6 governs behavior once someone is legitimately inside |
Adding door alarms, motion sensors, and cameras to a restricted room | Control 7.4, Physical security monitoring | 7.3 hardens the room; 7.4 watches it continuously and generates the alert when the hardening is tested |
Ensuring a server room has adequate, resilient power and cooling | Control 7.11, Supporting utilities | A physically secure room that loses power or cooling still fails availability requirements |
Fire-rated door and wall construction for a high-security room | Building and fire code, plus Control 7.5 | Security hardening cannot create an emergency-egress violation; both requirements must be satisfied simultaneously |
Health and safety regulation is the constraint that trips up security-first thinking most often. I've seen well-intentioned facilities teams install a keypad-only, badge-only door on a server room with no mechanical override — a genuinely strong security control — that turned out to violate local fire code because it could trap a technician inside during a power failure, or because it blocked a required secondary egress route. The fix is never to weaken the security control; it's to use hardware designed for exactly this tension: fail-safe electronic locks that release on fire-alarm trigger while still logging and alarming an unauthorized exit, panic bars that allow exit without allowing re-entry, and coordination with your local fire marshal before, not after, installation. Get your facilities/security lead and whoever handles regulatory compliance in the same room (pun intended) before signing off on any high-security door hardware.
Who owns what: a practical RACI for Control 7.3
One of the fastest ways to stall a Control 7.3 program is leaving ownership ambiguous — facilities assumes IT is handling the server room, IT assumes facilities owns the locks, and nobody owns the classification register itself. Assign it explicitly.
Activity | Facilities/Real Estate | IT/Infrastructure | Security/ISMS Owner | HR/Legal |
|---|---|---|---|---|
Room-sensitivity classification | Consulted | Consulted | Accountable/Responsible | Consulted |
Siting decisions for new/relocated rooms | Responsible | Consulted | Accountable | Informed |
Door hardware, locks, and structural hardening | Responsible | Consulted | Accountable | Informed |
Access-control matrix and badge groups | Consulted | Responsible | Accountable | Consulted |
Signage and directory content | Responsible | Informed | Accountable | Informed |
Lease/landlord negotiation for shared spaces | Accountable/Responsible | Informed | Consulted | Responsible |
Visitor/contractor escort policy enforcement | Responsible | Informed | Accountable | Consulted |
Audit evidence collection and SoA justification | Consulted | Consulted | Accountable/Responsible | Informed |
Evidence for auditors: what actually gets checked
Control 7.3 is one of the more satisfying controls to audit because the evidence is tangible — an auditor can walk the space, not just read a policy. In my experience running and supporting internal and certification audits, this is the evidence trail that closes 7.3 cleanly.
Evidence Type | What the Auditor Looks For | Where It Usually Lives |
|---|---|---|
Room-sensitivity classification register | Every room mapped to a tier, with the rationale documented and a review date | Facilities or ISMS document register |
Facility design/siting rationale | Documentation showing why high-security rooms were located where they are (interior, no exterior wall, no public sightline) | Facility fit-out records, ISMS risk assessment |
Access control matrix | Who is authorized into which tier, tied to role, reviewed periodically | Access-control system export, HR/IT joiner-mover-leaver records |
Physical walkthrough | Auditor physically inspects doors, signage, sightlines, and tests whether a propped door triggers a response | Live observation during audit |
Visitor and contractor logs | Evidence that restricted/high-security access was logged, escorted, and time-boxed | Visitor management system or paper log |
Signage and directory review | Confirmation that public directories and signage do not disclose sensitive room locations | Physical inspection plus photos in audit workpapers |
Incident and near-miss records | Any propped-door, tailgating, or unauthorized-access events, with corrective action | Incident log, tied to Controls 5.24–5.28 |
Statement of Applicability justification | Documented rationale for how 7.3 is implemented and, if excluded, why | ISMS SoA |
That last row matters more than people expect. Every organization I've supported through certification has needed to justify Control 7.3's inclusion and scope in its Statement of Applicability — and for physical controls specifically, "we lease the building, so this doesn't apply to us" is not an acceptable justification for exclusion. It's a justification for a compensating-control narrative, which is different and needs to be written out explicitly, not implied.
A quiet but critical piece of evidence auditors increasingly ask for: proof that the room classification register and the access-control matrix are reviewed, not just created once during initial certification and forgotten. I recommend tying this review to the same cadence as your internal audit program — annually at minimum, and immediately after any office move, lease change, or major floor-plan reconfiguration.
Common mistakes I keep seeing
Mistake | Why It Happens | Fix |
|---|---|---|
Treating access control on a door as sufficient evidence of security, without testing whether it's actually enforced | Nobody checks whether propping, tailgating, or badge-sharing happens in practice | Conduct unannounced physical walkthroughs and tailgating tests as part of internal audit |
Server room sited for convenience, not sensitivity | Fit-out decisions made before a security review, based on available floor space | Classify rooms before space planning, not after |
Sensitive rooms labeled clearly on doors and in directories | Building signage standards applied uniformly with no security exception | Carve out a signage exception for restricted/high-security rooms in the facilities standard |
Master keys or generic "IT" badges shared across a whole team | Perceived convenience, resistance to individual accountability | Move to named-individual credentials with logging; retire generic keys/badges entirely |
Glass walls and open sightlines into restricted areas, added for aesthetic or collaborative reasons | Architectural trend toward transparency, decided without security input | Involve security/ISMS owner in office design and lease decisions from the outset |
No documented room-sensitivity classification at all | 7.3 treated as "we have locks on doors," without the underlying design rationale | Build and maintain a facility register mapping every room to a tier |
Co-working or shared-building tenants assuming 7.3 doesn't apply to them | Misunderstanding that physical control ownership requires building ownership | Document compensating controls and contractual provisions explicitly in the ISMS |
Physical hardening added without coordinating with fire/life-safety code | Security and facilities/compliance functions working in silos | Joint sign-off between security and facilities/compliance on any high-security door hardware |
Room-sensitivity tiers to hardening measures
The diagram below summarizes the flow this article has walked through: classify the room, then apply the hardening tier appropriate to it.
flowchart TB
A[Facility Walkthrough & Room Inventory] --> B{Classify Sensitivity}
B --> C[Public: Lobby, Reception]
B --> D[General: Open-Plan, Standard Meeting Rooms]
B --> E[Restricted: Finance, HR, Legal]
B --> F[High-Security: Server Room, MDF, R&D Lab, Boardroom]
C --> C1[Staffed/receptionist control, visitor log, entry camera]
D --> D1[Badge entry, clear desk policy, standard signage]
E --> E1[Solid door + restricted key, visual privacy, logged after-hours access]
F --> F1[Interior siting, slab-to-slab walls, badge + PIN/biometric, no signage, escorted visitors, CCTV + alarms]
E1 --> G[Feeds Control 7.4 Monitoring]
F1 --> G
F1 --> H[Feeds Control 7.6 Secure-Area Behavior]
F1 --> I[Feeds Control 7.11 Utilities Resilience]Case studies
Castellane Health Partners: the propped door, revisited
We opened this article with Renn Okafor's server room. The resolution is worth documenting because it shows what a proper 7.3 remediation looks like in practice, not just in policy. After the breach investigation closed, Castellane's facilities and security teams jointly ran a full room-sensitivity classification across both regional offices — something that had never formally existed before. The server room was relocated eight months later during a lease renewal to an interior space with no exterior walls and no corridor sightlines. In the interim, they installed a door contact sensor wired to trigger an immediate alert if the door stayed open longer than ninety seconds, removed all exterior signage referencing the room's function, and moved from a shared "Facilities" badge group to named-individual access for the eleven people who genuinely needed entry. Total remediation cost: roughly $94,000, spread across the door hardware, the classification exercise, and the eventual relocation build-out. Measured against the $1.8 million incident cost, and against the health-plan client relationship they were able to retain going forward, the payback was immediate and the lesson became a fixture of Castellane's new-hire security orientation.
Voss Manufacturing: the lab a competitor could see into
Priya Nandakumar's R&D lab at Voss Manufacturing, a mid-size industrial equipment maker, sat in a single-story building with a full glass wall facing the employee parking lot — a design choice made for natural light, years before Voss began developing a next-generation actuator design intended to be its flagship product launch. During a routine physical security assessment ahead of ISO 27001 certification, an outside consultant photographed a prototype sitting on a lab bench from the parking lot, using nothing more than a phone camera, in under thirty seconds. There was no evidence a competitor had actually done this, but the exposure was real and had existed for over a year. Voss's remediation: frosted security film on the glass wall (four-day install, roughly $18,000), a strict no-photography policy enforced with signage and periodic spot checks, relocation of the most sensitive bench work to an interior room with no exterior glazing, and a visitor NDA and escort requirement for any non-employee entering the lab. The company's leadership treated the finding seriously enough that it became a driver, not just a compliance checkbox, for accelerating their broader physical security program.
Ledgerway Capital: physical security in a co-working space
Ledgerway Capital, a twelve-person fintech startup, ran its entire operation out of three private offices inside a shared co-working facility. Their comms closet — a small IT cabinet holding their router, switch, and a backup server — sat inside a shared utility room accessible to the co-working operator's cleaning staff and, in principle, to any other tenant's badge if the operator's access groups weren't configured carefully (an audit later found they weren't). During their first internal audit ahead of certification, this was flagged as a critical gap: a high-security-tier asset sitting in a space Ledgerway didn't control and hadn't documented any compensating control for. The remediation was contractual and physical: they negotiated a lease addendum with the co-working operator restricting shared-room access to a documented list, installed their own locked, keyed cabinet inside the shared utility room so their equipment had an independent physical barrier beyond the room's own door, and documented the entire arrangement — lease terms, access list, and compensating-control rationale — in their ISMS as formal evidence for Control 7.3. The fix cost under $2,000 in hardware and a half-day of legal review, and it closed what would otherwise have been a significant nonconformity at certification.
"Ledgerway's fix is the one I point every co-working tenant toward now: you can't always control the room, but you can always control what's inside a locked box within it, and you can always put the arrangement in writing. That's enough to satisfy 7.3 even when you don't own the building." — Aisha Coker, Facilities Manager, Halloway Biotech Labs
Organization | Root Gap | Remediation Cost | Prior Incident/Exposure Cost | Time to Remediate |
|---|---|---|---|---|
Castellane Health Partners | Propped, visible, unmonitored server room door | ~$94,000 | $1.8M (breach notification, forensics, lost contract) | 8 months (full relocation) |
Voss Manufacturing | Unobscured exterior glazing into R&D lab | ~$18,000 | Undetermined IP exposure, ~12+ months' duration | 2 weeks (film install), 3 months (bench relocation) |
Ledgerway Capital | High-security asset in uncontrolled shared space | <$2,000 | Certification-blocking nonconformity (avoided) | 3 weeks (lease addendum + cabinet install) |
The strategic case: physical security as a trust signal, not just a checkbox
It's tempting to treat Control 7.3 as a facilities-department chore — locks, signage, floor plans — that has little to do with the business case for ISO 27001 certification. I'd push back on that framing. Every client-side security questionnaire I've reviewed in the last five years asks some version of "how do you physically protect systems and data," and a vague answer here undermines confidence built by strong technical controls elsewhere. Sales teams selling into regulated industries — healthcare, finance, defense-adjacent manufacturing — routinely tell me that a confident, specific answer about room-level physical security closes deals that a generic "we have badge access" answer stalls. This is the same physical-safeguards expectation that shows up under SOC 2 and PCI DSS — none of these frameworks certifies you as legally compliant with sector regulation on its own, but a well-documented Control 7.3 program gives you a reusable, auditable answer across all of them, which materially shortens due-diligence cycles with enterprise customers and cyber insurers alike.
The cost asymmetry is stark, and it's worth stating plainly to whoever holds the facilities budget: Castellane's full remediation ran under $100,000; the incident it followed cost $1.8 million. Voss's frosted glass and lab reorganization cost under $20,000 against a flagship product's worth of exposed intellectual property. Ledgerway's fix cost under $2,000 and closed a certification-blocking nonconformity. Physical security for offices, rooms, and facilities is one of the highest-leverage line items in a physical controls budget precisely because the failure mode — an unsecured room that concentrates risk — is so much more expensive than the fix.
If you're building out this control alongside its neighbors, pair it with equipment security and maintenance for what happens to the hardware once it's inside a secured room, and with clear desk and clear screen practices for what happens on the desks and screens inside restricted offices day to day. Together, these controls form a coherent physical security program rather than a collection of disconnected requirements.
Start by pulling our Annex A — All 93 Controls at a Glance cheat sheet to see where 7.3 sits against the full control set, then work through our Mandatory Documents Checklist to confirm your room-classification register and facility documentation are audit-ready. If you're earlier in the process, our Complete ISO 27001 Implementation Guide eBook walks the physical controls theme end to end, and our Gap Analysis Tool will flag exactly which rooms in your facility register are missing classification or hardening evidence before an auditor finds them for you. When you're ready to test what you've built, run it against our Internal Audit Checklist — it includes the physical-walkthrough prompts auditors actually use for Control 7.3. And if any of the terminology in this article was new, our ISO 27001 Glossary of Terms covers it in plain language.
Renn Okafor's fire extinguisher is still, eighteen months later, the story his team tells new hires during physical security orientation — not because it was a dramatic hack, but because it wasn't one. It was a door, an unremarkable convenience, and a room that anyone walking past could tell was worth opening. Control 7.3 exists to make sure that story doesn't get told at your organization.
