SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.7.6Working in secure areas

Set rules for how people behave and work within secure areas, so the extra protection of those areas is not undermined by everyday activity.

Mapping at a glance

A.7.6 is covered by 2 Sekit CSF controls. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Physical access and visitor controls
How access to the premises and restricted areas is controlled (cards, keys, register), and how visitors are handled.
From the Sekit evidence catalog

In practice

For most SMEs the secure area in question is the server room or a records room, and the practical test is whether visitor and contractor rules change in practice once someone crosses that threshold. A visitor register at reception is not enough if a delivery contractor is later left alone in the server room to fix a cooling unit. Auditors ask to see the escort rule applied to that specific area, and whether anyone besides IT staff has ever been logged entering it unaccompanied.

Common gaps

The visitor policy requires an escort in restricted areas, but a maintenance contractor was left alone in the server room to service the air conditioning unit.
No log distinguishes visitors who reached only the reception area from those who entered the server or records room, so escort compliance cannot be checked for the areas that matter.
Staff routinely prop the server room door open during equipment installs, defeating the entry control the secure-area rules assume is always in effect.

Questions your auditor will ask

What rules apply once a visitor or contractor is inside a secure area rather than only the lobby?
The visitor management policy requires registration, badging and escort specifically in areas holding equipment or personal data, not only at reception.
Is the escort rule for secure areas followed in practice, not only on paper?
Every visitor is registered, badged and escorted consistently, and the physical access and visitor controls evidence shows this applied to the server or records room specifically.
How is a contractor working alone in the server room, such as for maintenance, handled?
The visitor policy treats a contractor the same as any other visitor: they are registered, badged and escorted rather than left unaccompanied in a restricted area.

Where regulation demands it

NIS2 art. 13.3 requires perimeter and physical access control for areas holding network and information systems.
ENS mp.if.2 requires identification of the people present in areas that need protection.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.7.6?”
Also via MCP, free with account