View Categories

A7.8 Equipment siting and protection

4 min read

ISO 27001 A7.8 Equipment siting and protection requires organizations to identify and protect the physical placement of IT equipment to ensure confidentiality, integrity, and availability of information. Improper placement can lead to data loss, service disruptions, and exposure of sensitive systems to unauthorized individuals.

Equipment siting and protection ensures that physical devices such as servers, network devices, and other information processing systems are placed in secure locations to reduce the risk of damage, unauthorized access, or environmental hazards.

This control helps protect against threats such as theft, natural disasters, tampering, and accidental damage by implementing suitable siting policies and physical safeguards.

Implementation Guide #

Step 1: Identify Critical Equipment

  • List all information processing equipment (servers, switches, routers, firewalls, etc.).
  • Identify equipment that supports business-critical functions or stores sensitive data.
  • Map out current locations and assess environmental risks (e.g., water leaks, heat exposure, unauthorized access).

Step 2: Define Siting Requirements

  • Designate secure rooms or areas (e.g., server rooms, communication cabinets).
  • Ensure they are away from high-traffic areas, windows, or easily accessible public spaces.
  • Consider redundancy, ventilation, and controlled access during siting decisions.

Step 3: Implement Physical Protection Measures

  • Control physical access using keys, ID cards, or biometric systems.
  • Install surveillance systems and alarm sensors where necessary.
  • Ensure cables are routed safely to avoid tampering or accidental disconnection.

Step 4: Protect Against Environmental Threats

  • Use fire suppression systems, smoke detectors, and air conditioning.
  • Implement UPS or backup power systems to avoid downtime.
  • Elevate equipment above floor level to prevent water damage.

Step 5: Maintain and Review

  • Keep a documented layout of equipment locations.
  • Regularly inspect and maintain equipment rooms.
  • Review equipment siting and risk assessments annually or during office relocations.

Templates #

  • Equipment Siting Risk Assessment Template
  • Server Room Access Log Sheet
  • Physical Security Checklist
  • Environmental Monitoring Report Template
  • Equipment Inventory Register

Example #

A mid-sized software company installed a switchboard in a storage room near a water heater due to lack of space. During a pipe leak, the room flooded, damaging the switch and resulting in network outages across all departments.

After the incident, the company relocated the switchboard to a secure, elevated area in the server room with a temperature sensor and water leak detector. They updated their siting policy and began regular inspections.

How to Comply #

To comply with ISO 27001 A.7.8, organizations should:

  • Define and document siting policies for IT equipment.
  • Place equipment in secure, restricted areas with proper environmental controls.
  • Regularly inspect and monitor for risks (e.g., heat, water, dust).
  • Ensure physical security controls are in place and maintained.
  • Document all equipment locations and maintain inventory records.

How to Pass an Audit #

Key Documents to Prepare:

  • Equipment Siting Policy
  • Physical Security Procedures
  • Environmental Risk Assessment Reports
  • Server Room Access Logs
  • Equipment Inventory Register

What the Auditor Will Check:

  • Is critical equipment placed in secure and restricted areas?
  • Are there adequate environmental protections (e.g., fire suppression, cooling)?
  • Are access controls and surveillance measures in place?
  • Are siting decisions based on documented risk assessments?
  • Is there ongoing review and maintenance of equipment siting practices?

Top 3 Mistakes People Make #

Placing sensitive IT equipment in exposed or shared areas due to convenience or space constraints.
Ignoring environmental factors like heat, moisture, and dust during equipment siting.
Failing to regularly review and update siting policies, especially after office expansions or IT upgrades.

ISO 27001 Equipment Siting FAQ #

Q1: Can regular office space be used for server installation?
Only if it is properly secured, climate-controlled, and access is restricted. Otherwise, a dedicated server room is recommended.

Q2: Is UPS required for all equipment?
Not for all, but essential equipment such as servers, firewalls, and network switches should have power backup to ensure availability.

Q3: Should equipment placement be reviewed periodically?
Yes, equipment siting must be reviewed at least annually or whenever major changes occur in the organization or infrastructure.

ISO 27001 Controls and Attribute Values #

Control Attribute Value
A.7.8 Equipment Siting and Protection Preventive, Physical, Operational
Purpose Protect information processing equipment from physical threats, unauthorized access, or environmental damage
Applicability IT Infrastructure, Network Management, Facility Operations
ISO 27001 Domains Physical and Environmental Security, Business Continuity, Asset Management

An effective siting and protection strategy minimizes the risk of downtime, data breaches, and equipment loss. Organizations that overlook physical placement of IT equipment may face service disruptions, unauthorized access, and compliance failures. By implementing simple but robust physical and environmental controls, you can ensure your systems are protected at the most fundamental level.

Leave a Reply

Your email address will not be published. Required fields are marked *

Log in

You dont have an account yet? Register Now