By John Watt on Thursday, 24 February 2022
Category: ISO27001 Information Security Management Systems

ISO27001 and the Annex Clauses – Clause A11 Physical and Environmental Security Pt2 - Equipment

We split ISO27001 for Information Security Management Systems Annex Clause A11 into 2 parts to try and keep it a bit shorter but also to emphasis that you do need to think about both areas as two steps of the process. In Part 1 we talked about Annex Clause A11.1 – Secure Areas, here we'll talk about 11.2 Equipment.

It's easy to just think of secure areas and equipment as one thing and try saying that all your stuff is in a secure area. That's never really going to be the case, so you need to think about that second level of physical and environmental security for your equipment because your auditor certainly will.

Annex Clause 11.2 - Equipment 

Like all the ISO27001 annex clauses A.11.2 for equipment starts off with a nice clear objective, in this case: "To prevent loss, damage, theft or compromise of assets and interruption to the organisation's operations."

Now that's a broad scope when you think about it in terms of things to consider. Again, from an Information Security point of view we aren't just talking about your computers, laptops, and phones we are talking all of your equipment involved in making sure your information security management system operates correctly. It'll include servers, security key fobs, access control panels, fire suppression systems (you know those ones you installed in your server room and your secure documents area?) and much more than that. The standard thankfully has some guidance around that in terms of thing you need to check. Keep in mind the standard is always the minimum, there may well be more things specific to your organisation you need to include.

Again, from a remote working point of view all the elements outlined above need to be considered, it's not going to be exempt from your auditing or compliance requirements for your ISO27001 information security management system.

Reviews 

Review your controls on a regular basis, as both the business and technology evolve so too must your controls and systems you have put in place. Schedule these reviews on a regular basis to ensure that are working effectively. As a company we use our Mango QHSE system to document and communicate all the controls and we use the auditing function to schedule and carry out our reviews to ensure we are still meeting our requirements.

 
Leave Comments