Where equipment is placed often matters as much as how it is secured.
Annex A 7.8 exists to ensure organisations site and protect equipment in a way that reduces physical, environmental, and unauthorised access risks, protecting the confidentiality, integrity, and availability of information throughout its lifecycle.
This control is about preventing avoidable loss and disruption through poor placement and protection.

Annex A 7.8 of ISO 27001:2022 focuses on equipment siting and protection.
At a practical level, this means:
The control does not require specialist facilities everywhere. It expects deliberate, risk-based decisions about where equipment is located and how it is protected.
Information processing equipment is vulnerable to more than cyber attack.
Common risks include:
Poorly sited equipment increases the likelihood of:
Annex A 7.8 ensures organisations reduce exposure to these risks before technical controls are tested.
This control replaces ISO 27001:2013 Annex A 11.2.1 and adds emphasis on segregation and environmental considerations.
A pragmatic approach to Annex A 7.8 typically includes the following elements.
Organisations should identify equipment that:
This includes servers, network devices, end-user devices, printers, and removable media.
Equipment should be located to minimise exposure to:
Examples include:
Location choices often prevent incidents before controls are needed.
Environmental factors can disrupt or damage equipment.
Organisations should consider protection against:
Controls should reflect the operating environment, not generic assumptions.
Equipment should be protected against casual or deliberate interference.
This may include:
Unauthorised physical access often leads to logical compromise.
Annex A 7.8 supports positioning equipment to reduce visual exposure.
This may involve:
Observation risk is frequently overlooked but easy to reduce.
The 2022 revision emphasises segregation.
Organisations should clearly separate:
This reduces confusion, interference, and accountability gaps.
Where equipment operates in unusual environments, additional controls may be needed.
Examples include:
Controls should match environmental reality, not policy language.
Protection degrades over time.
Organisations should:
Equipment protection should evolve with the environment.
Annex A 7.8 does not require:
It does require organisations to:
Most equipment incidents are preventable with basic planning.
Poor siting creates risk that no software can fix.
Annex A 7.8 is about preventing avoidable physical exposure.
When equipment siting and protection are handled effectively:
Before attackers, accidents, or environment cause harm,
Annex A 7.8 ensures organisations remove easy opportunities for failure.
We can help you understand your actual security needs and even if we cant help we can point you in the right direction
Talk to a security expert today