SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.7.4Physical security monitoring

Monitor sensitive premises for unauthorized physical access, for example with alarms or surveillance, so intrusions are detected and acted on.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Physical access and visitor controls
How access to the premises and restricted areas is controlled (cards, keys, register), and how visitors are handled.
From the Sekit evidence catalog

In practice

Small offices often stop at a doorbell camera and call that monitoring, but auditors want to see recording, retention and a review step, not only a lens pointed at the door. The company should be able to show camera coverage of entry points and the server room, a stated retention period consistent with Spanish data protection rules, and at least one example of footage being pulled and reviewed after a real event, such as a lost badge or an after-hours alarm.

Common gaps

Cameras cover the front door but not the server room, so an intrusion into the area holding the most sensitive equipment would go unrecorded.
Footage is overwritten after three days, shorter than the retention period stated in the CCTV policy, so incidents discovered later cannot be investigated.
The visitor log system produces a paper trail but no timestamped digital record, so arrivals and departures cannot be reconciled against badge access logs.

Questions your auditor will ask

How is camera footage of restricted areas retained and who can view it?
The CCTV policy states retention periods, covered areas and who may view footage, consistent with Spanish data protection requirements.
How do you know the surveillance system is recording rather than assumed to be working?
The camera infrastructure is checked for continuous recording, accurate time, non-default credentials and failure alerting, not assumed to be working.
What happens after a physical security event, such as an after-hours alarm?
Footage is retained per policy and reviewed under controlled access following the event, as part of the routine CCTV operating process.
How are visitor arrivals and departures recorded for later review?
Arrivals and departures are recorded in a system that produces a complete, reviewable log, not only a signature sheet at reception.

Where regulation demands it

NIS2 art. 13.2 requires protection against physical and environmental threats to network and information systems.
ENS op.mon.3 requires vigilancia, ongoing surveillance of the systems and areas that need protection.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.7.4?”
Also via MCP, free with account