ISO27001

Securing Offices, Rooms, and Facilities: ISO 27001 Control 7.3

Securing Offices, Rooms, and Facilities: ISO 27001 Control 7.3
Loading advertisement...
37

The propped-open door that cost Castellane Health Partners $1.8 million

Renn Okafor had walked past that door probably four thousand times in six years. It was the server room on the third floor of Castellane Health Partners' regional claims-processing center — a mid-size third-party administrator handling health insurance claims for about 340,000 members across two states. The door had a badge reader. It had a sign that, in smaller print than anyone had bothered to update, still referenced a decommissioned access-control vendor. And on a Tuesday morning in March, it had a fire extinguisher wedged against it, propping it open, because a rack technician doing a two-hour cable pull hadn't wanted to keep badging in and out.

Renn found it at 11:40 a.m., closed it, and moved on. He didn't think much of it — this had happened before, and it would happen again. What he didn't know was that between 9:15 and 11:40 that morning, a contractor from the building's cleaning service, whose access badge had been cloned three weeks earlier by a subcontractor with a grudge over an unpaid invoice, had walked the corridor twice. The door was propped open both times. On the second pass, at 10:52, he stepped inside for ninety seconds, plugged a USB drive into an idle console port on a rack switch, and walked out. Nobody saw him. The room had no camera — that was a Control 7.4 gap, not 7.3, but it compounded the problem. The room did have a lock and a badge reader, which is precisely why nobody worried about it: the access control existed on paper, and that was where its diligence stopped.

It took four months for Castellane's security team to piece together how a credential-harvesting implant ended up on a switch that fed twelve claims-processing servers. By the time they did, the incident had metastasized into a breach notification obligation covering roughly 61,000 members, a forensic investigation, two state attorney-general inquiries, and the quiet loss of a health-plan client contract worth an eight-figure sum over its remaining term. Total direct cost: $1.8 million, not counting the reputational drag that took eighteen months to fully dissipate. The root cause, when the incident report finally landed on the CEO's desk, wasn't a firewall failure or a phishing email. It was a door. A door that was locked in the access-control system's logs and open in the physical world, in a room that anyone walking the public-facing corridor to the break room could see straight into through a glass panel, with a rack label visible from six feet away reading "CLAIMS-PROD-CORE."

Every element of that failure — the visible sensitive space, the door that could be defeated by a fire extinguisher and social pressure, the labeling that told an intruder exactly what he was looking at, the absence of a room-sensitivity policy that would have flagged this space as requiring escort and no-prop enforcement — is what ISO 27001 Control 7.3, Securing offices, rooms and facilities, exists to prevent. This is the control that takes the physical perimeter established by physical security perimeters and entry controls and pushes it inward, room by room, matching the level of protection to what's actually inside.

"Access control on a door is a promise, not a guarantee. Control 7.3 is where you go back and check whether the promise is actually being kept, room by room, for the spaces where a bad five minutes turns into a seven-figure incident." — Renn Okafor, IT Infrastructure Manager, Castellane Health Partners

Who this is for

This article is for facilities managers, IT infrastructure leads, physical security consultants, and ISMS implementers who are working through Annex A's physical controls and need a concrete, room-level plan for Control 7.3 — not a restatement of the standard, but a practitioner's approach to classifying rooms by sensitivity, hardening each tier appropriately, handling siting and signage correctly, and producing the evidence an auditor will actually accept. If you've already read the broader physical controls overview and the perimeter-and-entry deep dive, this is the next layer down: what happens once someone is legitimately inside the building, and which internal doors still need to stop them.

What Control 7.3 actually requires

ISO/IEC 27001:2022 Annex A Control 7.3 states, in full: "Physical security for offices, rooms and facilities shall be designed and implemented." That's the entire normative text — deliberately broad, because the standard expects you to apply judgment based on what each space contains and what would happen if that protection failed. ISO/IEC 27002:2022's implementation guidance fills in the intent, and it clusters around five themes I'll use as the backbone of this article:

  1. Site sensitive facilities to avoid public access and observation. Don't put server rooms, executive offices, or R&D labs where they can be seen from a lobby, a public corridor, a parking lot, or a neighboring tenant's windows.

  2. Protect against unauthorized access with controls proportionate to sensitivity. A supply closet and a comms room are not the same risk, and they shouldn't get the same lock.

  3. Keep directories, signage, and floor plans from revealing sensitive locations. A lobby directory that says "Data Center — 3rd Floor, East Wing" is doing an attacker's reconnaissance for them.

  4. Secure server and communications rooms specifically, because they concentrate risk in a way that a typical office does not — a single unlocked comms closet can expose an entire floor's network segment.

  5. Account for health and safety regulations alongside security — fire codes, emergency egress, and accessibility requirements interact with locking strategy, and 7.3 has to be implemented in a way that doesn't create a life-safety violation.

Control 7.3 sits in the physical theme alongside thirteen other controls, and it's most useful when you understand its neighbors rather than treating it in isolation. Physical security perimeters and entry controls (Controls 7.1 and 7.2) establish the building-level boundary and who gets through the front door. Control 7.4, Physical security monitoring, adds the cameras and alarms that watch what happens after that. Control 7.5, Protecting against physical and environmental threats, covers fire, flood, and power events. Control 7.6, Working in secure areas, governs behavior once people are inside a restricted zone — visitor escort, no-photography rules, and so on. Control 7.11, Supporting utilities, covers the power and HVAC that keep a secured room actually functioning. Control 7.3 is the hinge between all of them: it's the control that says this specific room, because of what's in it, needs this specific combination of siting, structural hardening, and access restriction — and then leans on 7.4 through 7.6 and 7.11 to fill in the monitoring, behavioral, and environmental detail.

A note on scope, because auditors ask this constantly: Control 7.3 is not only about IT infrastructure. It applies to any room whose contents or activities carry elevated confidentiality, integrity, or availability risk — finance offices where wire transfer approvals happen, HR rooms holding personnel files, executive suites where M&A discussions occur, R&D labs with prototype hardware or proprietary formulas, and yes, server and communications rooms. The standard doesn't hand you a list. You build one, based on what a walk-through of your own facility actually turns up.

Facility design principles: get these right before you buy a single lock

Every facility security program I've reviewed that failed an audit or, worse, failed in production, skipped straight to hardware — better locks, more cameras, a fancier badge system — without first getting the underlying design principles right. Hardware fixes symptoms. Design principles fix the conditions that create the symptoms in the first place. Five principles do most of the work.

Principle 1: Sensitivity drives siting, not convenience. The single most common mistake I see is a server room placed wherever there happened to be spare floor space when the building was fitted out — often near a lobby, a loading dock, or an exterior wall, because that's where the empty room was. Sensitivity should be decided first, and the room assigned to a location second. High-sensitivity spaces belong in building interiors, away from exterior walls (which are vulnerable to forced entry and environmental exposure), away from public circulation routes, and ideally not on a ground floor with street-facing windows or a floor immediately below a public restroom or kitchen (water damage risk feeds directly into Control 7.5's environmental scope, but it starts with a 7.3 siting decision).

Principle 2: Layered access, not flat access. A visitor who can badge into the building lobby should not be one badge swipe away from the server room. Effective facilities build concentric rings — public zone, general employee zone, restricted zone, high-security zone — and each ring requires a separate authorization decision to cross, ideally on a different credential tier. This is the physical equivalent of network segmentation, and I use exactly that analogy with clients who come from an IT background: you wouldn't let every authenticated user reach your domain controllers with a single login, so don't let every badge holder reach your server room with a single swipe.

Principle 3: Observability is a vulnerability. Glass walls, open-plan sightlines, and "transparency" as an architectural value are genuinely good for collaboration and genuinely bad for a comms room, an executive boardroom during a board call, or an R&D bench. If a sensitive activity or asset can be seen from a public corridor, a lobby, an adjacent building, or a street, the room fails 7.3's intent regardless of how good its lock is. I've walked into more than one glass-fronted "innovation lab" where a competitor could photograph a prototype from the sidewalk with a phone camera.

Principle 4: Minimize disclosure of what a room is. Signage, floor directories, org charts posted near reception, and even generic labeling conventions ("Room 304 — Data Center") all leak reconnaissance value to anyone casing a building, whether that's a social engineer, a disgruntled ex-employee, or an opportunistic thief. Neutral room numbering with no descriptive label, absent from public directories, is a small design choice with outsized payoff.

Principle 5: Design for the failure mode, not just the steady state. A propped door, a tailgated visitor, a badge reader in fail-open mode during a power cut — these are the actual conditions under which most physical breaches happen, not a clean forced-entry scenario. Facility design has to account for how a control degrades under real operating pressure: a busy loading dock, a fire drill, a contractor rush job. Renn Okafor's fire-extinguisher door prop is the textbook version of this — the room was designed around the assumption that the door would behave as configured, and nobody designed for the moment someone found it inconvenient.

"I ask every client the same question during a facilities walkthrough: if I were a stranger with a clipboard and a confident walk, how far could I get before someone stopped me? In about a third of the buildings I assess, the honest answer is 'to the server room.'" — Marcus Bell, Physical Security Consultant, Ironclad Risk Advisors

Room-sensitivity classification: the foundation everything else builds on

You cannot proportion physical controls without first classifying rooms by sensitivity, in the same spirit as asset management under ISO 27001 classifies information. I use a four-tier model with clients, and it maps cleanly onto both risk assessment and audit evidence.

Tier

Definition

Typical Rooms

Who Gets In

Consequence of Compromise

Public

Areas open to visitors, customers, or the general public with no escort required

Lobby, reception, public restrooms, customer-facing meeting rooms

Anyone

Low — no sensitive assets present by design

General

Employee work areas with routine business information

Open-plan desks, standard meeting rooms, break rooms, general storage

Employees and escorted visitors

Moderate — clear desk violations, casual observation of screens or documents

Restricted

Areas holding confidential business information or limited-scope sensitive systems

Finance office, HR office, legal files room, print/mail room with sensitive output

Authorized role-based personnel, logged visitor access

High — financial fraud, privacy breach, regulatory exposure

High-security

Areas where compromise threatens core operations, intellectual property, or a large population of data subjects

Server room, comms/MDF room, executive boardroom during sensitive sessions, R&D lab, key/credential vault

Named individuals, dual-control for some tasks, logged and monitored access

Severe — operational outage, IP theft, mass data breach, regulatory penalty

Classification isn't a one-time exercise. I recommend re-running it whenever a room's use changes — a storage closet that becomes a network aggregation point, a meeting room that starts hosting board sessions, a lab that starts holding pre-patent prototypes — and as part of the annual internal audit cycle referenced in Clause 9. The classification also needs to be documented somewhere durable — a facility register, not tribal knowledge — because that register is exactly what an auditor will ask to see as evidence that Control 7.3 was "designed," not improvised.

One nuance worth flagging: sensitivity tier and access-control sophistication should scale together, but they don't have to scale together in cost. A restricted-tier HR office doesn't need a mantrap; it needs a good lock, restricted keying, and a policy against propping the door. Over-engineering a moderate-risk room wastes budget that a genuinely high-security room — the one holding the domain controllers — actually needs.

Hardening measures by room type

The classification tier tells you how much protection a room needs. This section tells you what that protection actually looks like for the six room types I encounter most often in facility assessments. Start with the summary matrix, then use the room-specific checklists for implementation detail.

Room Type

Sensitivity Tier

Wall/Door Construction

Access Method

Observation Control

Monitoring Baseline (feeds 7.4)

Reception/lobby

Public

Standard

Unlocked, staffed or receptionist-controlled

N/A — intentionally open

Camera at entry, visitor log

Server room

High-security

Slab-to-slab walls, solid core or rated door

Badge + PIN or biometric, no shared credentials

No windows; interior location

CCTV, door-forced/held alarms, entry log

Comms/MDF room

High-security

Slab-to-slab walls, solid core door

Badge, restricted list

No windows; unlabeled

CCTV or door contact alarm, entry log

Finance/HR office

Restricted

Standard with solid door

Badge or restricted key, no master-key sharing

Blinds/frosted glass on interior windows

Door contact alarm optional

Executive suite/boardroom

Restricted–High (context-dependent)

Standard to reinforced

Badge, calendar-gated for board sessions

Non-transparent walls facing corridors; sound dampening

Camera at corridor approach

R&D lab

High-security

Reinforced walls, solid core or rated door

Badge + logged sign-in, escort for visitors

No exterior-facing windows or covered glass; no photography policy

CCTV, motion sensors after hours

Server room

The server room is the room every 7.3 assessment starts with, and for good reason — it's usually the single highest-consequence space in the building. Requirements I treat as non-negotiable:

Control Element

Minimum Standard

Location

Interior room, not on an exterior wall, not below a bathroom/kitchen, not adjacent to a loading dock

Wall construction

Slab-to-slab (real ceiling to real floor, not just to a drop ceiling grid, which anyone can push aside and climb through)

Door

Solid core or fire-rated, self-closing, no propping mechanically possible without triggering an alarm

Access credential

Badge plus PIN or biometric for named individuals only; no shared or generic "IT" badge

Windows

None, or glazed with obscured/reinforced glass if legacy building constraints require it

Signage

No exterior label indicating server room, data center, or similar

Visitor policy

Logged, escorted, time-boxed access for vendors and contractors — ties directly into Working in Secure Areas, Control 7.6

Fire suppression

Clean-agent or pre-action system appropriate to electronic equipment (a Control 7.5 environmental concern that has to be designed into the room from day one)

Renn Okafor's incident traces to exactly two failures on this list: a door that could be physically propped without triggering an alarm, and a room visible enough from a public corridor that its purpose was obvious. Fixing either one alone would likely have prevented the breach.

Communications/MDF room

Comms rooms and main distribution frames get less attention than server rooms because they often look unglamorous — a wall of patch panels, not a rack of blinking servers — but a compromised comms closet gives an attacker physical access to an entire floor's or building's network segment. I've seen comms rooms used as general storage, propped open by janitorial staff for cart access, and left with an unlocked door because "there's nothing valuable in there, it's just cables." That's backwards: it's because it's just cables, and those cables terminate everything, that it needs the same tier of protection as the server room itself.

Control Element

Minimum Standard

Access credential

Badge, restricted access group distinct from general IT staff list

Storage discipline

No general storage — janitorial supplies, spare furniture, and boxes do not belong in an MDF room

Landlord/building coordination

Written agreement on who else (building engineers, other tenants) can access a shared MDF, with logging

Cable labeling

Patch-panel and port labeling kept inside the room only, never duplicated on public-facing documentation

Environmental tie-in

Dedicated cooling and UPS coverage, coordinated with Control 7.11

Comms rooms are frequently shared with building management or a landlord in multi-tenant properties, which I address separately below.

Finance and HR offices

These rooms hold personally identifiable information, payroll data, wire-transfer authority, and disciplinary records — restricted tier, not high-security, but still a step above general office space. The practical hardening list:

Control Element

Minimum Standard

Door

Solid door with a real lock (not a privacy latch), no propping during business hours

Key/credential control

Restricted keying — not on the building master key, or if on a badge system, a distinct access group

Visual privacy

Blinds or frosted film on any interior glazing facing a corridor

Document handling

Locking file cabinets for physical HR/finance files, aligned with Clear Desk and Clear Screen, Control 7.7

After-hours access

Logged, exception-based only

Executive suites and boardrooms

Executive areas are context-dependent — a CEO's office used for routine work is closer to general/restricted, but the same room during an M&A negotiation or board session becomes momentarily high-security. Design for the worst case that will realistically occur there: sound-dampened walls (conversations carry further than people expect through standard drywall), non-transparent sightlines from adjoining corridors, and calendar-gated access controls so that a board meeting automatically restricts badge access to the invite list for its duration. I've had more than one client discover, during a walkthrough, that their boardroom had a glass wall facing an open-plan area where analysts sat close enough to read a projected screen.

Control Element

Minimum Standard

Sightlines

No uncovered glass facing open-plan or public circulation areas

Acoustic control

Sound-dampening wall assembly or acoustic treatment sufficient to prevent corridor eavesdropping

Access during sensitive sessions

Calendar-linked, invite-list-only badge access for board or M&A sessions

Device policy

No unmanaged recording devices; visitor phones/devices logged for board-level sessions

Document handling

Locking storage for physical board packs, cleared immediately after sessions

"Boardrooms get treated like a status symbol, all glass and visibility, right up until the day the numbers on that screen are a pending acquisition target. Then everyone wants blinds installed yesterday. Design it right the first time." — Dana Whitfield, CISO, Bellcrest Financial Group

R&D and product labs

Labs holding prototypes, proprietary formulas, or pre-patent designs need the same structural rigor as a server room, plus controls aimed specifically at intellectual-property leakage rather than data confidentiality alone: no-photography policies enforced with signage and spot checks, visitor logs with NDA acknowledgment, covered or absent exterior-facing glazing, and — increasingly common in biotech and hardware clients I work with — a policy that visiting vendors and contractors are escorted at all times, not just badged in once and left alone. This is where 7.3's siting principle and Control 6.6 (confidentiality agreements) intersect directly with intellectual property protection under Control 5.32.

Control Element

Minimum Standard

Glazing

No uncovered exterior-facing glass; frosted film or interior-only layout

Photography/recording

Signed no-photography policy, enforced with signage and periodic spot checks

Visitor handling

NDA acknowledgment plus escort for all non-employees, no exceptions for "quick" visits

Prototype/sample storage

Locked storage separate from general bench workspace when not actively in use

IP tie-in

Documented linkage to intellectual property protection under Control 5.32

Reception and lobby

The one deliberately open room on this list, but 7.3 still applies: the lobby's job is to be the last public-tier space before every other tier begins, which means its design should make the transition from public to controlled unambiguous — a staffed desk or turnstile, a clear "authorized personnel beyond this point" boundary, and critically, no line of sight from the lobby into anything above general tier. A lobby with a glass wall overlooking an open-plan finance team's screens, which I've seen more than once in ground-floor fintech offices, defeats the entire point of having a reception control in the first place.

Control Element

Minimum Standard

Staffing/coverage

Staffed desk during business hours, or a monitored kiosk with intercom outside them

Boundary clarity

Physical or signed boundary marking where public access ends and controlled access begins

Sightlines beyond reception

No visibility into general, restricted, or high-security tier areas from public seating

Visitor registration

Sign-in with host notification for anyone proceeding past the lobby boundary

Directory content

Generic tenant/floor listing only — no room-level or department-level sensitive detail

"The lobby is where I judge a facility in the first ninety seconds. Can I see a whiteboard with real numbers on it? Is there a directory telling me which floor has the server room? Nine times out of ten, the lobby tells me exactly how seriously the rest of the building takes 7.3." — Priya Nandakumar, Facilities & Security Director, Voss Manufacturing

Siting and signage: the do's and don'ts that get missed

Siting and signage decisions are cheap to get right during a lease negotiation or office fit-out and expensive to fix afterward — moving a server room after occupancy means downtime, cabling rework, and often a change-management process spanning weeks. Get these decisions made early, and revisit them every time a floor plan changes.

Do

Don't

Locate high-security rooms in the building interior, away from exterior walls and public sightlines

Place a server or comms room against an exterior wall or a ground-floor street-facing façade

Use neutral room numbers with no descriptive label on doors or in directories

Label a door "Data Center," "Server Room," or "Wire Room" where visitors or the public can read it

Keep sensitive-room references out of lobby directories, wayfinding maps, and public floor plans filed with the landlord

Publish a floor plan (even for fire-code posting) that names sensitive rooms without a redacted or generic version for public display

Route public and visitor circulation paths away from restricted and high-security zones entirely

Route the shortest path from the lobby to the break room past the comms closet, "because it was convenient"

Use obscured, frosted, or covered glazing on any interior window facing a corridor for restricted/high-security rooms

Leave glass panels, sidelights, or interior windows uncovered on doors to sensitive rooms

Reference sensitive locations by internal code in maintenance tickets, vendor work orders, and building management system labels

Let a vendor work order or building-system label spell out "Data Center — Floor 3" where a subcontractor with no need-to-know can read it

Train reception and facilities staff to redirect, rather than answer, questions like "where's your server room?"

Let front-desk staff casually answer that question because "everyone in the building already knows anyway"

The public-directory point deserves emphasis because it's the one I see violated most often, usually by people with no bad intent: a building lobby's digital directory board, configured by whoever set up the tenant improvement, that cheerfully lists "Suite 310 — IT / Data Center." Fire marshals and code officials sometimes require floor plans that show mechanical and electrical rooms; where that's unavoidable, ISO 27002's guidance on health and safety interplay (echoed in Control 7.5) means you satisfy the code requirement with the minimum disclosure that meets it — a generic "Mechanical/Electrical" label rather than one that flags a specific room as an attractive target, and restrict who can view the full-detail version.

Shared offices, co-working spaces, and multi-tenant buildings

A growing share of the organizations I assess don't control their own building — they lease a floor or a suite inside a multi-tenant office building, or they run entirely out of a co-working space. Control 7.3 doesn't get easier in that scenario; it gets harder, because you're negotiating physical security with a landlord or a shared-space operator whose interests aren't identical to yours.

Scenario

Primary Risk

Practical Mitigation

Shared building, dedicated suite

Shared lobby, shared elevators, shared building-wide comms/MDF room accessible to other tenants' contractors

Negotiate a lease rider requiring landlord notification before any access to shared comms infrastructure; install your own lockable sub-enclosure inside a shared MDF room

Co-working space, dedicated office within the space

Shared reception, shared meeting rooms, cleaning and maintenance staff with broad access

Use a private, lockable room for anything restricted or above; never hold restricted-tier conversations in bookable shared meeting rooms without confirming no adjacent glass walls or thin partitions

Co-working space, hot-desk / open plan only

No dedicated restricted space at all

Treat the entire physical environment as public tier; prohibit processing of restricted or high-security information on-site, and route that work to a controlled alternative location

Serviced office with shared IT closet

Building-provided network equipment shared across tenants in a single rack

Require your own locked cage or cabinet within the shared room, contractually, and confirm in writing who holds spare keys

The recurring theme across all four scenarios: in a space you don't fully control, your Control 7.3 obligations don't disappear — they shift into contract language, lease riders, and documented compensating controls. An auditor assessing an organization in a co-working space will expect to see exactly this kind of documented risk acceptance or compensating control, not a shrug that says "we don't own the building, so it doesn't apply to us."

"The startups I work with almost always get this wrong first: they assume that because they're renting three desks in a co-working space, ISO doesn't care about the room. It cares more, not less, because you have less control and need to document how you compensated for that." — Tomas Ligeti, Lead ISO 27001 Auditor, Meridian Assurance Group

Environmental and safety interplay: 7.3 doesn't operate alone

Physical security for a room and environmental protection of that same room are two sides of one design decision, and the standard treats them as separate controls precisely because they require different expertise — but they have to be designed together or you end up with a room that's secure against intruders and defenseless against a burst pipe. The table below maps where 7.3's siting and access decisions hand off to its environmental and utility neighbors.

7.3 Decision

Hands Off To

Why It Matters

Siting a server room away from exterior walls and away from floors below restrooms/kitchens

Control 7.5, Protecting against physical and environmental threats

Water ingress and temperature extremes are environmental risks that start with a siting choice made under 7.3

Restricting who can enter a high-security room

Control 7.6, Working in secure areas

7.3 decides which rooms are restricted; 7.6 governs behavior once someone is legitimately inside

Adding door alarms, motion sensors, and cameras to a restricted room

Control 7.4, Physical security monitoring

7.3 hardens the room; 7.4 watches it continuously and generates the alert when the hardening is tested

Ensuring a server room has adequate, resilient power and cooling

Control 7.11, Supporting utilities

A physically secure room that loses power or cooling still fails availability requirements

Fire-rated door and wall construction for a high-security room

Building and fire code, plus Control 7.5

Security hardening cannot create an emergency-egress violation; both requirements must be satisfied simultaneously

Health and safety regulation is the constraint that trips up security-first thinking most often. I've seen well-intentioned facilities teams install a keypad-only, badge-only door on a server room with no mechanical override — a genuinely strong security control — that turned out to violate local fire code because it could trap a technician inside during a power failure, or because it blocked a required secondary egress route. The fix is never to weaken the security control; it's to use hardware designed for exactly this tension: fail-safe electronic locks that release on fire-alarm trigger while still logging and alarming an unauthorized exit, panic bars that allow exit without allowing re-entry, and coordination with your local fire marshal before, not after, installation. Get your facilities/security lead and whoever handles regulatory compliance in the same room (pun intended) before signing off on any high-security door hardware.

Who owns what: a practical RACI for Control 7.3

One of the fastest ways to stall a Control 7.3 program is leaving ownership ambiguous — facilities assumes IT is handling the server room, IT assumes facilities owns the locks, and nobody owns the classification register itself. Assign it explicitly.

Activity

Facilities/Real Estate

IT/Infrastructure

Security/ISMS Owner

HR/Legal

Room-sensitivity classification

Consulted

Consulted

Accountable/Responsible

Consulted

Siting decisions for new/relocated rooms

Responsible

Consulted

Accountable

Informed

Door hardware, locks, and structural hardening

Responsible

Consulted

Accountable

Informed

Access-control matrix and badge groups

Consulted

Responsible

Accountable

Consulted

Signage and directory content

Responsible

Informed

Accountable

Informed

Lease/landlord negotiation for shared spaces

Accountable/Responsible

Informed

Consulted

Responsible

Visitor/contractor escort policy enforcement

Responsible

Informed

Accountable

Consulted

Audit evidence collection and SoA justification

Consulted

Consulted

Accountable/Responsible

Informed

Evidence for auditors: what actually gets checked

Control 7.3 is one of the more satisfying controls to audit because the evidence is tangible — an auditor can walk the space, not just read a policy. In my experience running and supporting internal and certification audits, this is the evidence trail that closes 7.3 cleanly.

Evidence Type

What the Auditor Looks For

Where It Usually Lives

Room-sensitivity classification register

Every room mapped to a tier, with the rationale documented and a review date

Facilities or ISMS document register

Facility design/siting rationale

Documentation showing why high-security rooms were located where they are (interior, no exterior wall, no public sightline)

Facility fit-out records, ISMS risk assessment

Access control matrix

Who is authorized into which tier, tied to role, reviewed periodically

Access-control system export, HR/IT joiner-mover-leaver records

Physical walkthrough

Auditor physically inspects doors, signage, sightlines, and tests whether a propped door triggers a response

Live observation during audit

Visitor and contractor logs

Evidence that restricted/high-security access was logged, escorted, and time-boxed

Visitor management system or paper log

Signage and directory review

Confirmation that public directories and signage do not disclose sensitive room locations

Physical inspection plus photos in audit workpapers

Incident and near-miss records

Any propped-door, tailgating, or unauthorized-access events, with corrective action

Incident log, tied to Controls 5.24–5.28

Statement of Applicability justification

Documented rationale for how 7.3 is implemented and, if excluded, why

ISMS SoA

That last row matters more than people expect. Every organization I've supported through certification has needed to justify Control 7.3's inclusion and scope in its Statement of Applicability — and for physical controls specifically, "we lease the building, so this doesn't apply to us" is not an acceptable justification for exclusion. It's a justification for a compensating-control narrative, which is different and needs to be written out explicitly, not implied.

A quiet but critical piece of evidence auditors increasingly ask for: proof that the room classification register and the access-control matrix are reviewed, not just created once during initial certification and forgotten. I recommend tying this review to the same cadence as your internal audit program — annually at minimum, and immediately after any office move, lease change, or major floor-plan reconfiguration.

Common mistakes I keep seeing

Mistake

Why It Happens

Fix

Treating access control on a door as sufficient evidence of security, without testing whether it's actually enforced

Nobody checks whether propping, tailgating, or badge-sharing happens in practice

Conduct unannounced physical walkthroughs and tailgating tests as part of internal audit

Server room sited for convenience, not sensitivity

Fit-out decisions made before a security review, based on available floor space

Classify rooms before space planning, not after

Sensitive rooms labeled clearly on doors and in directories

Building signage standards applied uniformly with no security exception

Carve out a signage exception for restricted/high-security rooms in the facilities standard

Master keys or generic "IT" badges shared across a whole team

Perceived convenience, resistance to individual accountability

Move to named-individual credentials with logging; retire generic keys/badges entirely

Glass walls and open sightlines into restricted areas, added for aesthetic or collaborative reasons

Architectural trend toward transparency, decided without security input

Involve security/ISMS owner in office design and lease decisions from the outset

No documented room-sensitivity classification at all

7.3 treated as "we have locks on doors," without the underlying design rationale

Build and maintain a facility register mapping every room to a tier

Co-working or shared-building tenants assuming 7.3 doesn't apply to them

Misunderstanding that physical control ownership requires building ownership

Document compensating controls and contractual provisions explicitly in the ISMS

Physical hardening added without coordinating with fire/life-safety code

Security and facilities/compliance functions working in silos

Joint sign-off between security and facilities/compliance on any high-security door hardware

Room-sensitivity tiers to hardening measures

The diagram below summarizes the flow this article has walked through: classify the room, then apply the hardening tier appropriate to it.

Case studies

Castellane Health Partners: the propped door, revisited

We opened this article with Renn Okafor's server room. The resolution is worth documenting because it shows what a proper 7.3 remediation looks like in practice, not just in policy. After the breach investigation closed, Castellane's facilities and security teams jointly ran a full room-sensitivity classification across both regional offices — something that had never formally existed before. The server room was relocated eight months later during a lease renewal to an interior space with no exterior walls and no corridor sightlines. In the interim, they installed a door contact sensor wired to trigger an immediate alert if the door stayed open longer than ninety seconds, removed all exterior signage referencing the room's function, and moved from a shared "Facilities" badge group to named-individual access for the eleven people who genuinely needed entry. Total remediation cost: roughly $94,000, spread across the door hardware, the classification exercise, and the eventual relocation build-out. Measured against the $1.8 million incident cost, and against the health-plan client relationship they were able to retain going forward, the payback was immediate and the lesson became a fixture of Castellane's new-hire security orientation.

Voss Manufacturing: the lab a competitor could see into

Priya Nandakumar's R&D lab at Voss Manufacturing, a mid-size industrial equipment maker, sat in a single-story building with a full glass wall facing the employee parking lot — a design choice made for natural light, years before Voss began developing a next-generation actuator design intended to be its flagship product launch. During a routine physical security assessment ahead of ISO 27001 certification, an outside consultant photographed a prototype sitting on a lab bench from the parking lot, using nothing more than a phone camera, in under thirty seconds. There was no evidence a competitor had actually done this, but the exposure was real and had existed for over a year. Voss's remediation: frosted security film on the glass wall (four-day install, roughly $18,000), a strict no-photography policy enforced with signage and periodic spot checks, relocation of the most sensitive bench work to an interior room with no exterior glazing, and a visitor NDA and escort requirement for any non-employee entering the lab. The company's leadership treated the finding seriously enough that it became a driver, not just a compliance checkbox, for accelerating their broader physical security program.

Ledgerway Capital: physical security in a co-working space

Ledgerway Capital, a twelve-person fintech startup, ran its entire operation out of three private offices inside a shared co-working facility. Their comms closet — a small IT cabinet holding their router, switch, and a backup server — sat inside a shared utility room accessible to the co-working operator's cleaning staff and, in principle, to any other tenant's badge if the operator's access groups weren't configured carefully (an audit later found they weren't). During their first internal audit ahead of certification, this was flagged as a critical gap: a high-security-tier asset sitting in a space Ledgerway didn't control and hadn't documented any compensating control for. The remediation was contractual and physical: they negotiated a lease addendum with the co-working operator restricting shared-room access to a documented list, installed their own locked, keyed cabinet inside the shared utility room so their equipment had an independent physical barrier beyond the room's own door, and documented the entire arrangement — lease terms, access list, and compensating-control rationale — in their ISMS as formal evidence for Control 7.3. The fix cost under $2,000 in hardware and a half-day of legal review, and it closed what would otherwise have been a significant nonconformity at certification.

"Ledgerway's fix is the one I point every co-working tenant toward now: you can't always control the room, but you can always control what's inside a locked box within it, and you can always put the arrangement in writing. That's enough to satisfy 7.3 even when you don't own the building." — Aisha Coker, Facilities Manager, Halloway Biotech Labs

Organization

Root Gap

Remediation Cost

Prior Incident/Exposure Cost

Time to Remediate

Castellane Health Partners

Propped, visible, unmonitored server room door

~$94,000

$1.8M (breach notification, forensics, lost contract)

8 months (full relocation)

Voss Manufacturing

Unobscured exterior glazing into R&D lab

~$18,000

Undetermined IP exposure, ~12+ months' duration

2 weeks (film install), 3 months (bench relocation)

Ledgerway Capital

High-security asset in uncontrolled shared space

<$2,000

Certification-blocking nonconformity (avoided)

3 weeks (lease addendum + cabinet install)

The strategic case: physical security as a trust signal, not just a checkbox

It's tempting to treat Control 7.3 as a facilities-department chore — locks, signage, floor plans — that has little to do with the business case for ISO 27001 certification. I'd push back on that framing. Every client-side security questionnaire I've reviewed in the last five years asks some version of "how do you physically protect systems and data," and a vague answer here undermines confidence built by strong technical controls elsewhere. Sales teams selling into regulated industries — healthcare, finance, defense-adjacent manufacturing — routinely tell me that a confident, specific answer about room-level physical security closes deals that a generic "we have badge access" answer stalls. This is the same physical-safeguards expectation that shows up under SOC 2 and PCI DSS — none of these frameworks certifies you as legally compliant with sector regulation on its own, but a well-documented Control 7.3 program gives you a reusable, auditable answer across all of them, which materially shortens due-diligence cycles with enterprise customers and cyber insurers alike.

The cost asymmetry is stark, and it's worth stating plainly to whoever holds the facilities budget: Castellane's full remediation ran under $100,000; the incident it followed cost $1.8 million. Voss's frosted glass and lab reorganization cost under $20,000 against a flagship product's worth of exposed intellectual property. Ledgerway's fix cost under $2,000 and closed a certification-blocking nonconformity. Physical security for offices, rooms, and facilities is one of the highest-leverage line items in a physical controls budget precisely because the failure mode — an unsecured room that concentrates risk — is so much more expensive than the fix.

If you're building out this control alongside its neighbors, pair it with equipment security and maintenance for what happens to the hardware once it's inside a secured room, and with clear desk and clear screen practices for what happens on the desks and screens inside restricted offices day to day. Together, these controls form a coherent physical security program rather than a collection of disconnected requirements.

Start by pulling our Annex A — All 93 Controls at a Glance cheat sheet to see where 7.3 sits against the full control set, then work through our Mandatory Documents Checklist to confirm your room-classification register and facility documentation are audit-ready. If you're earlier in the process, our Complete ISO 27001 Implementation Guide eBook walks the physical controls theme end to end, and our Gap Analysis Tool will flag exactly which rooms in your facility register are missing classification or hardening evidence before an auditor finds them for you. When you're ready to test what you've built, run it against our Internal Audit Checklist — it includes the physical-walkthrough prompts auditors actually use for Control 7.3. And if any of the terminology in this article was new, our ISO 27001 Glossary of Terms covers it in plain language.

Renn Okafor's fire extinguisher is still, eighteen months later, the story his team tells new hires during physical security orientation — not because it was a dramatic hack, but because it wasn't one. It was a door, an unremarkable convenience, and a room that anyone walking past could tell was worth opening. Control 7.3 exists to make sure that story doesn't get told at your organization.

Frequently asked questions

Is Control 7.3 only about server rooms and data centers?

No. It's often anchored there because server rooms carry the highest concentrated risk, but the control applies to any office, room, or facility whose contents or activity warrant elevated protection — finance offices, HR rooms, executive suites, R&D labs, and even print/mail rooms handling sensitive output. Build your room-sensitivity classification first and let it tell you which rooms 7.3 applies to most heavily.

How is Control 7.3 different from Control 7.2, Physical entry?

Control 7.2 governs entry to the facility as a whole — the front door, the badge system at the main entrance, visitor sign-in at reception. Control 7.3 goes further inside the building and asks whether individual rooms have protection proportionate to what they hold. A building can have excellent 7.2 entry control and still fail 7.3 if the server room inside it is visible from a public corridor with a badge reader anyone on staff can use.

Do we need a mantrap or biometric access for every restricted room?

No — that's over-engineering for most restricted-tier rooms and a waste of budget better spent on genuinely high-security spaces. A solid door, a real lock or restricted badge group, and a no-propping policy is usually proportionate for finance and HR offices. Reserve biometric or dual-factor access for high-security tier rooms like server rooms, comms closets, and sensitive R&D labs.

We lease our office space. Does Control 7.3 still apply to us?

Yes, and auditors specifically look for how you've addressed it. You may not control building-wide elements like the main lobby or a shared comms room, but you're still expected to document compensating controls — lease provisions, your own locked sub-enclosures, contractual access restrictions — rather than treating leased space as out of scope.

What's the single most common finding auditors write up under Control 7.3?

In my experience, it's a sensitive room with no documented classification rationale — the room has a lock, sometimes a good one, but nobody can produce evidence of why that room was determined to need that level of protection, or evidence that the classification is reviewed periodically. The second most common finding is signage or a public directory disclosing a sensitive room's location.

How does Control 7.3 relate to fire and building codes?

They have to be satisfied simultaneously, not traded off against each other. Security hardening — locks, restricted access, alarm-linked doors — must never create a life-safety or emergency-egress violation. Use fail-safe hardware that releases on fire-alarm trigger while still logging the event, and involve your fire marshal or life-safety consultant before installing high-security door hardware, not after.

Does 7.3 cover cameras and alarms?

Not directly — that's Control 7.4, Physical security monitoring. Control 7.3 is about the design and structural/access hardening of the room itself; 7.4 covers the ongoing surveillance and alerting layered on top of it. They're closely related and usually implemented together, but they're distinct controls with distinct evidence requirements.

How often should room classifications and access lists be reviewed?

At minimum annually, aligned with your internal audit cycle, and immediately after any office move, lease change, floor-plan reconfiguration, or significant change in a room's use — for example, a storage room that becomes a network aggregation point, or an office that starts hosting board-level discussions.

37

About the author

Cybersecurity Expert

Satish Kumar writes about cybersecurity, offensive security, and practical defense strategies on PentesterWorld.

Related Articles

Comments (0)

No comments yet. Be the first to share your thoughts!