SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.7.12Cabling security

Protect power and network cabling from interception, interference and damage, since exposed cabling can quietly undermine otherwise strong controls.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Facility resilience and media controls
The protections against power or climate failures affecting critical systems, and the control of cabling and facility security zones.
From the Sekit evidence catalog

In practice

Cabling security is easy to overlook because it hides in walls and under floors, but auditors specifically ask to see the patch cabinet and check whether it is locked, whether cable runs are labeled, and whether an unused network port in a public area is live or disabled. The realistic small-office version is a documented zone standard naming who can access the comms room, a recurring inspection that checks the boundary has not been breached, and switch-level protections such as port security or disabling unused ports so a stray cable in reception cannot join the internal network.

Common gaps

An unused network port in the reception area was found to be live during testing, allowing a device to be plugged in and reach the internal network without authorization.
The comms room lock works, but the key is kept on an unlocked hook in the open-plan office, defeating the access control the zone standard describes.
No inspection record exists for the cabling and patch cabinet boundary, so the auditor cannot confirm the recurring check described in the standard happens on schedule.

Questions your auditor will ask

Who is allowed to access network cabling and the patch cabinet?
A written standard defines the office's security zones, including the server or comms room and patch cabinets, and states who may access cabling and equipment.
What controls stop someone from plugging into an idle port in a public area?
Unused ports in public areas are disabled or protected with switch-level port security, so plugging in a rogue device does not reach the internal network.
How do you know cabling has not been tampered with?
Cabling, patch cabinets and security zone boundaries are inspected on a recurring schedule, with what was checked and any tampering found recorded.

Where regulation demands it

NIS2 art. 13.3 requires perimeter and physical access control extending to the cabling infrastructure inside protected zones.
ENS mp.if.1 requires áreas separadas y con control de acceso for equipment such as patch cabinets and comms rooms.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.7.12?”
Also via MCP, free with account