ISO/IEC 27001 (information security management)
With ISO/IEC 27001 in scope the cameras are an asset with an owner (Annex A 5.9), who can view the footage follows the access control rules (5.15), physical security monitoring is a control of its own (7.4), and the privacy requirements that arise from law are identified and met (5.34).
- Where it is placed
- Placed on every site when you tick ISO/IEC 27001 as in scope. It is a management system standard you choose to hold, not a law, and it keys on no place.
- Date last read
- 29 Sep 2026
- Clauses cited
- 4 of 93 held
- The standard itself
- ISO/IEC 27001 (information security management) on compliance.theartofservice.com
Clauses cited, and the findings that cite them
| Clause | Title | Findings |
|---|---|---|
| ISO/IEC 27001 A.5.9 | Inventory of information and other associated assets | 13 |
| ISO/IEC 27001 A.5.15 | Access control | 13 |
| ISO/IEC 27001 A.5.34 | Privacy and protection of personal identifiable information (PII) | 13 |
| ISO/IEC 27001 A.7.4 | Physical security monitoring | 13 |
ISO/IEC 27001 A.5.9Inventory of information and other associated assetsInventory of information and other associated assets. The organization is to build and keep current an inventory of its information and other associated assets, with their owners recorded. Purpose (stated in ISO/IEC 27002:2022): identifies the organization's information and associated assets so they can be protected and properly owned. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.9.
ISO/IEC 27001 A.5.15Access controlAccess control. Rules that govern both physical entry and logical access to information and associated assets are to be set and applied on the basis of business and information security requirements. Purpose (stated in ISO/IEC 27002:2022): ensures access to information and associated assets is authorized and unauthorized access is prevented. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.15.
ISO/IEC 27001 A.5.34Privacy and protection of personal identifiable information (PII)Privacy and protection of personal identifiable information (PII). The organization is to identify, and then satisfy, the requirements for preserving privacy and protecting personally identifiable information that arise from applicable laws, regulations and contracts. Purpose (stated in ISO/IEC 27002:2022): ensures compliance with requirements on the information security aspects of protecting PII. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.34.
ISO/IEC 27001 A.7.4Physical security monitoringPhysical security monitoring. Premises are to be watched continuously for unauthorized physical entry. Purpose (stated in ISO/IEC 27002:2022): detects and deters unauthorized physical access. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 7.4.