Skip to content
Singahi

Compliance · guide

ISO 27001 A.7.6: Working in Secure Areas

19 min read

Share
On this page

Quick Reference (60 Seconds)

ISO 27001:2022 Annex A 7.6 requires that security measures for working in secure areas be designed and implemented, governing how people behave once they are inside a sensitive area, not just how they get in.

ElementWhat You Need to Know
Control NumberA.7.6
Control NameWorking in Secure Areas
Standard ReferenceISO/IEC 27001:2022, Annex A, Control 7.6
27002 GuidanceISO/IEC 27002:2022, Clause 7.6
Control TypePreventive
ObjectiveProtect information and assets in secure areas from damage and unauthorised interference by people working there
What You Must DoDefine rules for conduct in secure areas: need-to-know, supervision, no recording devices, locking/inspection, emergency procedures
OwnerPhysical Security / Facilities (with CISO and area owners)
Maturity L1 → L5No rules → posted rules → enforced device/camera bans + supervision → monitored compliance → integrated, audited secure-area governance
Audit Red FlagPhones/cameras in a data hall, lone unsupervised contractor in a secure room, vacant server room left unlocked
Quick WinPost secure-area rules (no cameras, no unsupervised work, emergency steps) at the server-room door this week
Time to Implement2–4 weeks for rules, signage, and enforcement process
Related ControlsA.7.2 Physical entry · A.7.3 Securing offices/rooms · A.7.4 Physical monitoring · A.7.7 Clear desk & screen · A.8.1 User endpoint devices

The Bottom Line: A.7.2 controls who gets in; A.7.6 controls what they can do once inside. An authorised person, or a supervised contractor, can still photograph a screen, plug in a USB, or tamper with a server. Working-in-secure-areas rules close that gap with need-to-know, supervision, device restrictions, and a locked, inspected, emergency-ready environment.


What the Standard Actually Requires

Figure · Process

What A.7.6 asks you to do

The 5 requirements of ISO 27001 A.7.6, working in secure areas, in order: documented, posted rules; no unauthorised recording devices; supervision; vacant secure areas locked; emergency procedures posted.
The 5 things the control expects. Each is expanded in the section below.

The ISO 27001:2022 Text

Annex A 7.6 states:

ISO 27001:2022 Annex A 7.6 asks organizations to design and apply controls that govern how people work inside secure areas.

What ISO 27002:2022 Adds

The measures apply to all personnel and cover all activities in the secure area. ISO 27002 says to consider:

  • (a) making personnel aware of the existence of, or activities within, a secure area only on a need-to-know basis;
  • (b) avoiding unsupervised work in secure areas, both for safety and to reduce the chance of malicious activity;
  • (c) physically locking and periodically inspecting vacant secure areas;
  • (d) not allowing photographic, video, audio or other recording equipment (such as cameras in user endpoint devices) unless authorised;
  • (e) appropriately controlling the carrying and use of user endpoint devices in secure areas;
  • (f) posting emergency procedures in a readily visible/accessible manner.

The "shall vs should" Analysis

PhraseForceMeaning
"shall be designed and implemented"MandatoryYou must have, and enforce, secure-area working rules
The six measures (a)–(f)Recommended menuApply those relevant to the area's sensitivity
"all personnel… all activities"Mandatory in substanceRules apply to staff, contractors and visitors alike

What Auditors Actually Check

  1. Documented, posted rules for secure areas (and awareness of them).
  2. No unauthorised recording devices (phones/cameras) where prohibited.
  3. Supervision, no lone/unsupervised work or unsupervised third parties in sensitive areas.
  4. Vacant secure areas locked and periodically inspected.
  5. Emergency procedures posted and known.

Why Working in Secure Areas Matters

The Business Risk Narrative

Entry control (7.2) gets the right people into the room; it does nothing about what they do next. A legitimately-badged contractor servicing an air-conditioner in a data hall can photograph racks, read a screen, or insert a USB. A lone engineer working unsupervised at 2 a.m. could tamper with a server with no one to notice. A.7.6 addresses the insider-and-inside-the-room risk, the activities of people who are already, validly, in a secure area.

Insider/Inside-Area Statistics

StatisticSourceImplication
Insiders account for a significant share of incidentsInsider-threat researchBehaviour inside secure areas matters
Smartphone cameras make data exfiltration trivialSecurity studiesDevice/camera control is essential
Maintenance/third-party personnel are a common overlooked vectorPhysical-security reviewsSupervision of contractors is key
Unsupervised access raises both safety and tamper riskOperational risk studies"Two-person" rules reduce risk

Indian Regulatory and Client Context

  • DPDP Act 2023: Physical safeguards (Section 8(5)) extend to preventing unauthorised interference with systems holding personal data, including by people inside secure areas.
  • BFSI / RBI: Data-centre and sensitive-area working rules (supervision, no unauthorised recording) are expected for facilities housing customer/critical data.
  • IT/ITeS & BPO client mandates: Global clients routinely impose no-phone / no-camera / no-paper "clean floor" rules on secure delivery floors, plus supervision and clear-desk requirements, frequently audited.
  • Defence/CII: Strict no-recording, supervision and inspection regimes for classified/critical areas.

Industry-Specific Consequences

SectorFailure modeConsequence
IT/ITeSPhone photo of customer data on a secure floorDPDP/contract breach, client loss
BFSIUnsupervised vendor in the data hallRBI finding, tamper/fraud risk
HealthcareRecording in a records/imaging areaPatient-privacy breach
Manufacturing/R&DCamera in a design labIP theft

impact of Non-Compliance

A single photograph of a screen or a USB inserted in a server can cause a breach that no firewall would have stopped, and on a client's secure floor, it can overhead the contract. The controls (signage, device lockers, supervision, locking vacant rooms) are inexpensive; the incidents they prevent are not.


Scope and Applicability

What the Control Covers

  • Conduct and activities within secure areas, server/comms rooms, data halls, records vaults, R&D/design labs, secure delivery floors, and any area designated sensitive.
  • Rules for all personnel (staff, contractors, visitors) and all activities in those areas.

Who It Applies To

Any organisation that has secure areas, scaled to context. A small firm sets rules for its server cupboard; a BPO enforces clean-floor rules across thousands of secure seats; a DC operator runs strict supervised-work and no-recording regimes.

Size-Based Applicability

SizeRealistic implementation
Micro/SMEPosted rules for the server room; lock when vacant; no unsupervised contractor work; phones-away during maintenance
Growing companiesDesignated secure areas with rules, signage, device control, supervision, periodic inspection
Enterprise / DC / BPOClean-floor regimes, device lockers, escorted/supervised work, monitored compliance, formal inspection schedules

Key Definitions and Terminology

Figure · At a glance

A.7.6 at a glance

Secure area
A designated area requiring controlled
Need-to-know
Limiting even awareness of a secure area/its
Unsupervised work
Working alone in a secure area without
Two-person rule
Requiring two authorised people for work
Recording equipment
Cameras (incl. phone cameras), video
Clean floor
A regime prohibiting personal devices/paper
The essentials before reading further. The full reference table follows.
TermDefinition
Secure areaA designated area requiring controlled access and conduct (e.g. server room, secure floor)
Need-to-know (existence)Limiting even awareness of a secure area/its activities to those who must know
Unsupervised workWorking alone in a secure area without oversight
Two-person ruleRequiring two authorised people for work in highly sensitive areas
Recording equipmentCameras (incl. phone cameras), video, audio or other recording devices
Clean floorA regime prohibiting personal devices/paper on a secure work floor
Vacant-area inspectionPeriodic check that an unoccupied secure area is locked/secure

Relationship to Other Controls

ControlRelationship to A.7.6
A.7.2 Physical entryUpstream. Entry control gets people in; 7.6 governs conduct inside
A.7.3 Securing offices, rooms and facilitiesParallel. Securing the areas themselves
A.7.4 Physical security monitoringParallel. CCTV/monitoring helps detect unsupervised/prohibited activity
A.7.7 Clear desk and clear screenParallel. Conduct rules to prevent information exposure
A.8.1 User endpoint devicesParallel. Controls on carrying/using devices in secure areas
A.6.3 Awareness & trainingUpstream. Personnel must know the rules
A.7.13 / A.7.4 Maintenance & monitoringParallel. Supervision of maintenance staff working in secure areas

Entry vs Conduct

A.7.2 and A.7.6 are a pair: entry (7.2) decides who passes the door; conduct (7.6) governs what they do once through it. Both are needed, strong entry control with no conduct rules still allows an authorised insider or supervised contractor to photograph, copy, or tamper. A.7.6 is the behavioural layer of physical security.


The Six Working-in-Secure-Areas Rules

Operationalise ISO 27002's six measures:

#RulePractice
1Need-to-know awareness (a)Don't advertise the location/contents of secure areas; brief only those who must know
2No unsupervised work (b)No lone work in sensitive areas; two-person rule for the most critical; buddy/escort otherwise
3Lock & inspect vacant areas (c)Secure areas locked when empty; periodic inspection to confirm
4No recording devices (d)Prohibit cameras/phones/recorders unless explicitly authorised
5Control endpoint devices (e)Restrict what devices may be carried/used inside
6Post emergency procedures (f)Display evacuation/emergency steps visibly

These translate directly into signage, a short policy, and an enforcement/inspection routine.


Device, Camera and Recording Controls

The highest-use rules for data-exfiltration risk:

  • Prohibit recording (cameras, phone cameras, video/audio) in designated areas unless authorised (27002 (d)). Use device lockers at the entrance to secure floors.
  • Control endpoint devices (27002 (e)): define which devices may be carried/used; block/secure USB ports where warranted (link A.8.1, A.7.10 storage media); prohibit personal devices on clean floors.
  • Authorised exceptions: where recording is needed (e.g. documenting an incident or a maintenance task), authorise, log, and supervise it.
  • Enforcement: signage + awareness + spot checks + CCTV (7.4). Make the rule visible and the culture supportive of challenge.

Detailed Implementation Guidance

Designate Secure Areas and Their Rules

Identify which areas are "secure" (server/comms rooms, data halls, records vaults, R&D labs, client secure floors) and define the conduct rules for each, proportionate to sensitivity.

Post Rules and Emergency Procedures

Put concise rules and emergency procedures at the entrance/inside (27002 (f)). Visible signage is both a control and audit evidence.

Enforce Supervision and the Two-Person Principle

Prohibit unsupervised work in sensitive areas (27002 (b)); apply a two-person rule for the most critical (e.g. work in the data hall). Ensure contractors are escorted/supervised (Section 10).

Lock and Inspect Vacant Areas

Ensure secure areas are locked when vacant and run periodic inspections to confirm (27002 (c)); record inspections.

Control Devices and Recording

Implement the device/camera controls in Section 8, lockers, USB control, no-camera signage, authorised exceptions.

Train and Build Awareness

Brief all who enter secure areas on the rules (link A.6.3); reinforce a challenge culture so violations are reported.

Monitor and Review

Use CCTV/monitoring (7.4) to detect prohibited activity; review incidents and inspection records; update rules as areas/risks change.


Supervising Third Parties and Maintenance

Maintenance and vendor staff are a frequently-overlooked vector, they have a legitimate reason to be inside, often near critical equipment:

  • Authorise the specific work and personnel in advance.
  • Escort/supervise them throughout (no unsupervised access to the secure area).
  • Brief them on the secure-area rules (no recording, device limits).
  • Restrict their access to only the equipment/area required.
  • Log entry, the work performed, and departure (link A.7.13 equipment maintenance, A.7.2 entry).
  • Inspect the area after the work (nothing left, nothing taken, area re-secured).

Working in Secure Areas Policy (Template)

Illustrative extract (full version in the toolkit):

Working in Secure Areas Policy — Acme Technologies Pvt Ltd (A.7.6)

Applies to all personnel, contractors and visitors, and all activities, in designated
secure areas (server/comms rooms, data halls, records vaults, secure delivery floors).

1. Awareness of secure areas and their activities is on a need-to-know basis.
2. Unsupervised work in secure areas is prohibited; a two-person rule applies to [data hall].
3. Secure areas shall be locked when vacant and inspected [weekly]; inspections recorded.
4. Photographic, video, audio and other recording equipment (including phone cameras) is
   prohibited in secure areas unless explicitly authorised, logged and supervised.
5. The carrying and use of user endpoint devices in secure areas is restricted; personal
   devices are prohibited on [secure floors]; device lockers are provided at entry.
6. Emergency procedures are posted visibly in all secure areas.
7. Third-party/maintenance personnel shall be authorised, escorted, briefed, restricted to
   the required area, logged, and the area inspected after work.

Risk Assessment and Treatment

Figure · Risk grid

Working in secure areas risks by likelihood and impact

High131
Medium11
LowMediumHigh

Likelihood across · impact up

  • Data exfiltration via phone cameraHigh/High
  • Unsupervised contractor tampers/copiesMedium/High
  • Lone after-hours work, no oversightMedium/High
  • Vacant server room left unlockedMedium/High
  • Emergency mishandledLow/High
  • Personal USB used on secure floorMedium/Medium
  • Sensitive activity overheard/observedLow/Medium
The risks this control addresses, plotted from the register below. Treatments are listed against each.
RiskLikelihoodImpactRisk LevelTreatment
Data exfiltration via phone cameraHighHighCriticalNo-recording rule + lockers + signage + CCTV
Unsupervised contractor tampers/copiesMediumHighHighEscort/supervision; two-person rule
Lone after-hours work, no oversightMediumHighHighNo unsupervised work; monitoring
Vacant server room left unlockedMediumHighHighLock when vacant; periodic inspection
Personal USB used on secure floorMediumMediumMediumDevice control; USB restriction
Sensitive activity overheard/observedLowMediumLowNeed-to-know; area design
Emergency mishandled (safety)LowHighMediumPosted emergency procedures; drills

Audit and Compliance Checklist

#Audit QuestionExpected EvidenceRed Flag
1Are secure areas designated with documented rules?Policy + area listNo defined rules
2Are rules posted/visible in secure areas?SignageNo signage
3Is awareness of secure areas need-to-know?Briefing approachWidely advertised
4Is unsupervised work prohibited in sensitive areas?Policy + practiceLone work observed
5Is a two-person rule applied where warranted?Procedure for data hallNone for critical work
6Are vacant secure areas locked and inspected?Inspection recordsUnlocked vacant room
7Are recording devices prohibited/controlled?No-camera rule + lockersPhones/cameras in data hall
8Are endpoint devices controlled in secure areas?Device control; USB rulesPersonal devices/USB used
9Are authorised recording exceptions logged?Authorisation + logAd-hoc recording
10Are emergency procedures posted?Visible proceduresNone posted
11Are third parties supervised in secure areas?Escort/supervision recordsUnsupervised contractors
12Is maintenance work authorised, restricted, logged?Work authorisation + logsUnlogged maintenance
13Is the area inspected after third-party work?Post-work inspectionNo inspection
14Are personnel trained on the rules?Training recordsNo awareness
15Is compliance monitored (CCTV/spot checks)?Monitoring + incident recordsNo enforcement

(Full 25-question version in the toolkit 04-audit-evidence-checklist.md.)


Metrics and KPIs

Figure · Measures

The measures that show A.7.6 is working

  • Unauthorised recording-device incidents0Monthly
  • Unsupervised-work incidents0Monthly
  • Vacant-area inspection compliance100%Monthly
  • Vacant-area lock compliance100%Monthly
  • Third-party supervision compliance100%Monthly
Targets and reporting cadence as defined in the table below, where the formula for each is given.
#KPIFormulaTargetFrequency
1Unauthorised recording-device incidentsCount in secure areas0Monthly
2Unsupervised-work incidentsCount detected0Monthly
3Vacant-area inspection compliance% scheduled inspections done100%Monthly
4Vacant-area lock compliance% checks finding area secured100%Monthly
5Third-party supervision compliance% secure-area work supervised100%Monthly
6Device-control compliance% secure-area entries compliant100%Monthly
7Signage/emergency-procedure currency% areas with current postings100%Quarterly
8Secure-area awareness coverage% relevant personnel trained100%Annually
9Post-maintenance inspection rate% maintenance jobs inspected100%Per event
10Secure-area rule violationsCount reportedTrend ↓Monthly
11Authorised-recording exceptions logged% logged100%Per event
12Physical-security test findings (secure-area conduct)CountTrend ↓Per test

Common Pitfalls and Audit Failures

PitfallRoot CauseFix
Phones/cameras in data hallNo device/recording ruleNo-camera rule + lockers + signage
Unsupervised contractor in secure roomWeak third-party controlEscort/supervise; restrict; log
Lone after-hours workNo supervision ruleProhibit unsupervised work; two-person rule
Vacant server room unlockedNo lock/inspection routineLock when vacant + periodic inspection
Rules exist but unknownNo signage/awarenessPost rules; train; reinforce
No emergency procedures postedOverlookedPost visibly; run drills
Maintenance unlogged/uninspectedInformal vendor handlingAuthorise, supervise, log, inspect after
Clean-floor rule not enforcedCultural laxitySpot checks + CCTV + challenge culture

Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1, Indian BPO Secure Delivery Floor (Gurugram, 1,800 seats): Clean-Floor Enforcement

Challenge. A BPO processing a UK bank's customer data was contractually required to run a no-phone, no-camera, no-paper "clean floor" with supervised access. A client audit found agents carrying personal phones onto the floor, no device lockers, and vacant secure rooms left unlocked at shift change, putting the contract at risk and breaching the client's data-protection requirements.

Solution (Singahi-guided, 6 weeks).

  1. Established the floor as a designated secure area with posted rules and device lockers at entry; personal devices prohibited inside (27002 (d), (e)).
  2. Implemented shift-change lock and inspection of secure rooms with recorded checks (27002 (c)).
  3. Mandated supervision for any maintenance/third-party work on the floor, with logging and post-work inspection.
  4. Ran a challenge-culture awareness campaign and added CCTV spot-check monitoring (A.7.4).

Results. Personal devices on the floor reduced to 0 in follow-up checks; vacant-room lock compliance reached 100%; the client audit passed and the engagement was renewed and expanded.

Illustrative Scenario 2, Indian Bank Data Hall (Bengaluru): Supervised Work and No-Recording Regime

Challenge. The bank's data hall allowed lone vendor engineers to perform maintenance and had no rule against recording; an internal review worried that a single unsupervised visit could enable tampering or photography of sensitive infrastructure, an RBI and ISO concern.

Solution (Singahi-guided, 5 weeks).

  1. Introduced a two-person/supervised-work rule for all data-hall activity; no unsupervised vendor work (27002 (b)).
  2. Implemented a no-recording policy with authorised, logged, supervised exceptions only (27002 (d)).
  3. Posted emergency procedures and secure-area rules at the entrance (27002 (f)).
  4. Added post-maintenance inspection and tied data-hall entry to authorised work orders (link A.7.2, A.7.13).

Results. All data-hall work now supervised and recording-controlled; the practice satisfied the RBI examiner and the ISO 27001 auditor, and became the template for the bank's other critical facilities.


16A. Advanced Implementation Guidance

Figure · Tiers

Maturity levels for working in secure areas

  1. Fully enforcedmonitored audited secure-area
  2. Clean-floor/devicetwo-person rule for critical work
  3. Rules + signage +supervision device control vacant-area
  4. Basic rules postedsome supervision
  5. No conduct rulesad-hoc behaviour in secure areas
Where most organisations sit, and what the next level asks for. Full characteristics per level are in the table below.

16A.1 Running a "Clean-Floor" Programme

Many Indian IT/ITeS and BPO engagements are contractually required to run a clean floor, no personal devices, no cameras, no paper, on secure delivery floors handling client data. Operating it well requires: device lockers at the entrance (phones/wearables deposited before entry); clear, posted rules and signage; entry checks (and, in the highest-security contexts, mobile-detection); paper controls (clear desk A.7.7, controlled printing, locked disposal); and continuous reinforcement so the rule survives day-to-day convenience pressure. The clean floor is as much a cultural programme as a control, it only holds if supervisors enforce it consistently and staff accept it as normal.

16A.2 Device-Locker and Endpoint-Device Operations

Operationalise the device controls (27002 (e)): provide enough lockers that depositing a phone is frictionless; define what may be carried (e.g. an approved, managed work laptop) versus prohibited (personal devices, personal USB); pair with endpoint/USB controls (A.8.1, A.7.10) so removable media cannot be used to exfiltrate; and define an authorised-exception process (e.g. a vendor needs a laptop for maintenance) that is approved, logged and supervised. The goal is to make the secure thing the easy thing.

16A.3 The Two-Person Rule and Supervision

For the most sensitive work, changes in the data hall, access to a records vault, handling of bulk sensitive data, require two authorised people present (27002 (b)). This reduces both safety risk (someone present in an emergency) and the chance of undetected malicious activity (a second pair of eyes). Where a strict two-person rule is impractical, require supervision/escort and monitoring as compensating controls. Define which areas/activities trigger the rule, and evidence it (sign-in showing two names, CCTV).

16A.4 Maintenance and Vendor Work, End to End

Maintenance staff are inside, near critical equipment, often with tools and devices, a classic blind spot. Run the full cycle: authorise the specific work order and personnel; brief them on secure-area rules (no recording, device limits); escort/supervise throughout; restrict them to the equipment/area required; log entry, work performed, and exit; and inspect afterwards (nothing left behind, nothing taken, area re-secured, no recording occurred). Tie this to the equipment-maintenance control (A.7.13) and physical entry (A.7.2).

16A.5 Monitoring and Enforcement

Conduct rules need enforcement to be real. Use CCTV spot-checks (A.7.4) to detect recording, unsupervised work, or prohibited devices; run periodic inspections of vacant secure areas (locked, secure, nothing amiss) with recorded results; and maintain a challenge culture (A.6.3) where staff report violations. Track violations and feed them into awareness and, where warranted, the disciplinary process (A.6.4). A posted rule that is never checked is not a control.

16A.6 OT, Labs and Special Environments

Secure-area conduct extends beyond server rooms. R&D/design labs (IP-theft risk) warrant no-camera and supervised-access rules. OT/plant control rooms require conduct rules adapted to safety constraints, where individual logins or strict device bans are impractical on legacy systems, compensate with supervision, physical access control (A.7.2), and segregation (A.8.22). The principle is constant: define and enforce measures for all personnel and all activities in the secure area, proportionate to its sensitivity.

16A.7 Working-in-Secure-Areas Maturity Model (L1–L5)

LevelCharacteristics
L1No conduct rules; ad-hoc behaviour in secure areas
L2Basic rules posted; some supervision
L3Rules + signage + emergency procedures; supervision; device control; vacant-area lock & inspection
L4Clean-floor/device lockers; two-person rule for critical work; supervised maintenance; CCTV-backed enforcement
L5Fully enforced, monitored, audited secure-area governance; strong challenge culture

Target L3 for certification; secure delivery floors and data halls are typically expected at L4.

16A.8 Anatomy of a Secure-Area Conduct Failure

A vendor engineer is admitted to the data hall (valid entry under A.7.2) to service a unit, unsupervised. While there, they photograph rack labelling and a screen showing system details, and connect a personal USB to copy a configuration file, none of which the entry control could prevent, because the failure is one of conduct, not access. Each link is an A.7.6 measure: no unsupervised work, no recording devices, endpoint-device control, and post-work inspection. A.7.6 is the behavioural layer that ensures legitimately-present people cannot quietly exfiltrate or tamper.

Key Takeaways

  • A.7.2 controls who gets in; A.7.6 controls what they do once inside, the behavioural layer of physical security.
  • The six measures: need-to-know awareness, no unsupervised work, lock & inspect vacant areas, no recording devices, control endpoint devices, post emergency procedures.
  • Device/camera control (lockers, no-camera rules) is the highest-use measure against data exfiltration.
  • Supervise third parties and maintenance end-to-end, and inspect afterwards.
  • Enforcement is the control, posted rules need CCTV spot-checks, inspections, and a challenge culture.
  • In India, A.7.6 underpins client clean-floor mandates and DPDP physical safeguards.

Multi-Framework Mapping

FrameworkReferenceMapping to A.7.6
ISO/IEC 27002:20227.6Working in secure areas
NIST SP 800-53 Rev 5PE-3, PE-5 (output/device), PE-18 (asset location), PE-6 (monitoring)Conduct/supervision in secure areas
NIST CSF 2.0PR.AA-06Physical access/conduct managed
PCI DSS v4.0Req 9.2, 9.3 (visitor/personnel control)Controlling personnel/visitors in sensitive areas
SOC 2 (TSC 2017)CC6.4Restricting/controlling activity in facilities
COBIT 2019DSS05.05Manage physical access and environment
DPDP Act 2023Section 8(5)Physical safeguards against interference

Implementation Roadmap

Phase 1, Define (Weeks 1–2)

  • Designate secure areas; draft the working-in-secure-areas rules (the six measures).
  • Post rules and emergency procedures; brief relevant personnel.

Phase 2, Control (Weeks 2–3)

  • Implement device/camera controls (lockers, no-camera signage, USB rules).
  • Establish supervision/two-person rules and vacant-area lock+inspection routine.

Phase 3, Govern Third Parties (Week 3)

  • Implement supervised, authorised, logged maintenance/vendor work + post-work inspection.

Phase 4, Assure (Week 4+)

  • Awareness/challenge-culture campaign; CCTV spot-check monitoring.
  • KPI dashboard; physical-security test; internal audit dry-run.

FAQ

Q1: Is A.7.6 mandatory for certification? If you have secure areas (server rooms, data halls, secure floors), yes. Auditors physically check posted rules, device/recording controls, supervision, and inspection records.

Q2: How is A.7.6 different from A.7.2 and A.7.3? 7.2 controls entry (who gets in); 7.3 secures the rooms/facilities; 7.6 governs conduct of people once inside a secure area.

Q3: Do we really have to ban phones in the server room? Recording equipment (including phone cameras) should be prohibited unless authorised, proportionate to sensitivity. For a data hall or client secure floor, a no-camera rule (with lockers) is standard; for a small server cupboard, a "phones away during access" rule may suffice.

Q4: What's the most common finding? Unsupervised contractor/maintenance work in secure areas and phones/cameras where they shouldn't be. Fix with supervision/escort and device controls.

Q5: What is the "two-person rule"? Requiring two authorised people present for work in the most sensitive areas, reducing both safety risk and the chance of undetected malicious activity. Apply it to data-hall and critical-equipment work.

Q6: How does A.7.6 relate to clear desk/clear screen (A.7.7)? They are complementary conduct controls: 7.7 prevents leaving information exposed; 7.6 governs broader behaviour (recording, supervision, devices) within secure areas.


References and Further Reading

Primary standards

  • ISO/IEC 27001:2022, Annex A control 7.6.
  • ISO/IEC 27002:2022, Clause 7.6 (measures (a)–(f)); related §7.2, §7.3, §7.4, §7.7, §8.1.

Supporting frameworks

  • NIST SP 800-53 Rev 5, PE-3, PE-5, PE-6, PE-18.
  • NIST CSF 2.0, PR.AA-06.
  • PCI DSS v4.0, Requirement 9.
  • SOC 2 (TSC 2017), CC6.4.
  • COBIT 2019, DSS05.05.

Indian regulations

  • Digital Personal Data Protection Act, 2023, Section 8(5).
  • RBI, data-centre/secure-area expectations.
  • Client/contractual clean-floor requirements (IT/ITeS/BPO).

Singahi resources: the A.7.6 toolkit and related guides for A.7.2 Physical entry, A.7.3 Securing offices, rooms and facilities, A.7.4 Physical security monitoring, and A.7.7 Clear desk and clear screen.

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.