Once someone is inside the building, security failure becomes a proximity problem.
Annex A 7.3 exists to ensure organisations secure offices, rooms, and facilities that contain information or information processing assets, reducing the risk of unauthorised access, damage, or interference.
This control goes beyond perimeter and entry controls. It focuses on what happens inside the boundary.

Annex A 7.3 of ISO 27001:2022 focuses on securing offices, rooms, and facilities.
At a practical level, this means:
The control does not require uniform security across all spaces. It expects proportionate protection based on sensitivity and risk.
Not all areas inside a building carry the same risk.
Higher-risk areas often include:
If these spaces are not secured:
Annex A 7.3 ensures organisations identify and protect internal spaces deliberately, rather than assuming perimeter controls are sufficient.
A pragmatic approach to Annex A 7.3 typically includes the following elements.
Organisations should identify which internal areas require additional protection, based on:
This assessment drives the level of control required.
Access to sensitive areas should be restricted.
This may involve:
Access should be granted based on role and need, not convenience.
Where appropriate, organisations should limit how easily sensitive activities can be observed.
This may include:
Security improves when sensitive areas are discreet.
Annex A 7.3 supports protecting information from being:
Controls may include:
The risk depends on context, not paranoia.
Some areas may justify additional monitoring.
This could include:
Monitoring should be proportionate, lawful, and clearly governed.
Securing a room is not enough if assets inside are exposed.
Organisations should consider:
Layered protection reduces single-point failure.
Physical layouts and usage change over time.
Organisations should:
Degraded controls create a false sense of security.
Annex A 7.3 does not require:
It does require organisations to:
Internal security fails most often through familiarity and assumption.
Internal access is rarely forced — it is usually allowed by design.
Annex A 7.3 is about protecting information where it is actually used.
When offices, rooms, and facilities are secured effectively:
Perimeters stop people getting in.
Annex A 7.3 ensures the right protection exists once they are inside.
We can help you understand your actual security needs and even if we cant help we can point you in the right direction
Talk to a security expert today