Where equipment is placed often matters as much as how it is secured. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations deploy state-of-the-art encryption and firewall rules, only to place core network switches in unlocked utility closets under leaky water pipes, or locate reception printers right where visitors can casually read confidential output. Poor physical siting creates avoidable vulnerabilities that no software patch can fix.
ISO 27001:2022 includes Annex A 7.8 to ensure you site and protect equipment deliberately against physical, environmental, and visual threats throughout its operational lifecycle. This control replaces the former 2013 requirement (11.2.1) and adds strong emphasis on environmental shielding, screen positioning, and segregating corporate equipment from non-organisational assets.
Quick Summary: What ISO 27001 Annex A 7.8 Requires
At a practical level, Annex A 7.8 is about placing hardware where it is safe from physical interference, theft, environmental degradation, and casual observation. It does not require building an enterprise tier-4 data centre for a small office; it expects deliberate, risk-based siting decisions. Here is what you need to do in plain English:
- Site High-Risk Hardware Securely: Locate servers, network switches, and storage arrays inside locked, access-controlled rooms or server cabinets (Annex A 7.10).
- Protect Against Environmental Hazards: Avoid placing equipment directly beneath water pipes, next to exterior windows, or in unventilated areas prone to dust and overheating.
- Prevent Unauthorised Visual Exposure: Position monitors and workstations away from public view or fit privacy filters to prevent shoulder-surfing.
- Segregate Corporate vs Non-Corporate Assets: Physically or logically separate company-managed equipment from contractor, guest, or personal devices.
- Secure Output Devices: Locate printers, plotters, and fax machines in secure zones or enforce PIN-authenticated print release (Annex A 7.7).
- Apply Surge & Power Protection: Protect critical hardware against power fluctuations, electrical spikes, and static buildup.
Why Poor Equipment Siting Is a Major Physical Risk
Hardware left in high-traffic hallways, near unsealed windows, or in damp basements is exposed to physical theft, accidental liquid spills, overheating, and shoulder-surfing. Physical or environmental compromise bypasses logical network firewalls completely.
Ignoring equipment siting and protection controls exposes your business to severe hazards:
- Physical Tampering and Data Extraction: Malicious visitors or unauthorized staff plugging rogue USB drives or keyloggers into exposed physical ports.
- Environmental Outages: Servers overheating or crashing due to poor ventilation, direct sunlight, or overhead water pipe leaks (Annex A 7.11).
- Visual Eavesdropping: Visitors or unauthorized personnel observing sensitive customer records or credentials on poorly positioned screens.
- Interference from Non-Corporate Devices: Unvetted guest or contractor hardware physically plugged into internal network ports alongside corporate assets (Annex A 8.20).
My 8 Step Plan to Implement Annex A 7.8 Fast
You do not need to redesign your office layout overnight to satisfy an ISO 27001 auditor. Here is my pragmatic, 8-step plan to establish an audit-ready equipment siting and protection framework.
1. Identify Hardware Assets Requiring Physical Protection
Audit your facility to catalog all physical hardware processing, storing, or transmitting information (Annex A 8.9):
- On-premises servers, storage arrays (SAN/NAS), and backup units (Annex A 8.13).
- Network switches, routers, firewalls, and patch panels (Annex A 7.12).
- Employee workstations, laptops, and administrative terminals (Annex A 8.1).
- Multi-function printers, copiers, and local physical media archives.
2. Site High-Value Equipment in Restricted Physical Zones
Keep core information processing hardware out of public and high-traffic areas:
- Locate servers and central network appliances inside dedicated, locked server rooms or locked floor-standing cabinets.
- Restrict physical access to server enclosures strictly to authorized IT and facility personnel via keycard or physical key (Annex A 7.10).
- Avoid placing critical hardware in shared storage rooms, kitchens, or multi-tenant utility closets.
3. Mitigate Environmental and Physical Hazards
Protect hardware against physical wear, extreme climate exposure, and accidental damage:
- Position equipment away from overhead water pipes, AC condensation drains, radiators, and exterior windows.
- Ensure adequate airflow and ventilation around server racks to prevent thermal halts and hardware degradation.
- Use raised flooring, cable trays, or elevated equipment mounts to keep hardware off floors prone to flooding.
4. Position Screens to Eliminate Visual Exposure
Prevent casual observation and shoulder-surfing across open office spaces, reception areas, and ground-floor windows:
- Angle workstation monitors away from public walkways, waiting areas, and external windows.
- Equip laptops and workstations in high-traffic zones with polarising privacy screen filters.
- Enforce automated 5–10 minute screen lockouts to blank displays when unattended (Annex A 8.1).
5. Secure Printers and Output Infrastructure
Printers and copiers are frequent sources of physical paper leaks if output sits unattended in tray bins:
- Place multi-function printers in secure internal zones rather than public corridors.
- Configure “Follow-Me” print management, requiring users to authenticate with a badge or PIN at the printer before documents are released.
- Provide cross-cut shredding bins directly next to print stations for immediate document disposal (Annex A 7.10).
6. Segregate Organisational and Non-Organisational Gear
ISO 27001:2022 explicitly expects clear separation between corporate assets and external hardware:
- House company-owned servers and managed network switches inside separate, locked rack units away from third-party or multi-tenant gear.
- Designate separate physical charging and usage zones for employee personal devices (BYOD) and guest hardware.
- Ensure non-corporate devices connect exclusively to isolated guest Wi-Fi networks (Annex A 8.22).
7. Protect Equipment Power and Grounding Infrastructure
Electrical instability can cause physical component failure and silent data corruption:
- Connect critical servers and network appliances to Uninterruptible Power Supply (UPS) units and surge protectors (Annex A 7.11).
- Ensure clean electrical grounding to prevent static electricity build-up or voltage spikes.
- Route power cables safely inside protective conduit to prevent tripping hazards or accidental disconnections (Annex A 7.12).
8. Inspect Siting Controls and Layout Changes Periodically
Physical security degrades over time as office layouts change and new desks are added:
- Conduct bi-annual physical walk-throughs to inspect equipment placement, cable routing, and cabinet locks.
- Re-assess screen angles and printer security following office refurbishments or team desk reshuffles.
- Document physical inspection findings as audit evidence for your annual ISMS management review.
Common Implementation Pitfalls and How to Fix Them
When preparing clients for ISO 27001 audits, I frequently spot the same equipment siting mistakes. Here are the main traps and how to solve them:
- Problem: Network Switches Left Sitting in an Unlocked Office Cupboard
Ninja Solution: Install a wall-mounted, lockable network cabinet and restrict key access strictly to designated IT leads. - Problem: Financial or HR Screens Visible from Public Reception Area Windows
Ninja Solution: Re-angle desks, apply privacy window film, or fit glare/privacy filters onto affected monitors. - Problem: Confidential Printouts Left Accumulating in Open Printer Trays
Ninja Solution: Implement badge/PIN-authenticated print release software (e.g., PaperCut) so jobs print only when the user is physically present. - Problem: Server Hardware Placed directly on the Carpet Under an AC Cooling Unit
Ninja Solution: Mount servers inside a raised server rack away from condensation lines and off floor surfaces.
The ISO 27001 Ninja Bottom Line
ISO 27001 Annex A 7.8 is about removing easy physical and environmental opportunities for failure before your technical software security controls are ever tested. Where equipment is placed matters as much as how it is logically configured.
By placing critical hardware in locked rooms, shielding assets from environmental threats, angling screens away from public view, securing printer outputs, segregating corporate gear, and conducting routine physical audits, you eliminate preventable physical exposure, maintain service availability, and satisfy your ISO 27001 auditor with complete confidence.
