CCTV Privacy Law Mapper
Regimes

ISO/IEC 27001 (information security management)

With ISO/IEC 27001 in scope the cameras are an asset with an owner (Annex A 5.9), who can view the footage follows the access control rules (5.15), physical security monitoring is a control of its own (7.4), and the privacy requirements that arise from law are identified and met (5.34).

Where it is placed
Placed on every site when you tick ISO/IEC 27001 as in scope. It is a management system standard you choose to hold, not a law, and it keys on no place.
Date last read
29 Sep 2026
Clauses cited
4 of 93 held
The standard itself
ISO/IEC 27001 (information security management) on compliance.theartofservice.com

Clauses cited, and the findings that cite them

ClauseTitleFindings
ISO/IEC 27001 A.5.9Inventory of information and other associated assets13
ISO/IEC 27001 A.5.15Access control13
ISO/IEC 27001 A.5.34Privacy and protection of personal identifiable information (PII)13
ISO/IEC 27001 A.7.4Physical security monitoring13
ISO/IEC 27001 A.5.9Inventory of information and other associated assets

Inventory of information and other associated assets. The organization is to build and keep current an inventory of its information and other associated assets, with their owners recorded. Purpose (stated in ISO/IEC 27002:2022): identifies the organization's information and associated assets so they can be protected and properly owned. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.9.

What a reviewer asks to see: Statement of Applicability entry for control A.5.9, showing inclusion or justified exclusion, implementation status and the risks it treats; The asset inventories (information, hardware, software, virtual, facilities and others) with owner, classification and location fields populated; Reconciliation records between inventories and discovery tooling, or evidence that installs, changes and removals update the inventory automatically; A procedure for assigning ownership on creation or acquisition and reassigning it when owners leave or change role; Records of periodic classification and access restriction reviews carried out by asset owners
Where camera lists usually fall short: The inventory covers hardware only and omits information assets, cloud services and software components; Owners listed are people who have left or generic team names with no accountable individual; The inventory drifts from reality because no reconciliation or automated update exists; Disposed assets remain in the inventory, or live assets never entered it
Source: ISO/IEC 27001 (information security management), read 29 Sep 2026
ISO/IEC 27001 A.5.15Access control

Access control. Rules that govern both physical entry and logical access to information and associated assets are to be set and applied on the basis of business and information security requirements. Purpose (stated in ISO/IEC 27002:2022): ensures access to information and associated assets is authorized and unauthorized access is prevented. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.15.

What a reviewer asks to see: Statement of Applicability entry for control A.5.15, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements; Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification; Evidence of a default-deny design in firewall rules, application roles and cloud IAM policies; Separation of request, approval and administration functions in the access management workflow
Where camera lists usually fall short: The access control policy exists but is not reflected in actual system configurations; Default-allow rules persist in network or cloud environments; Non-human entities such as service accounts are left outside the access rules; Access rights are not aligned with classification, so sensitive data is broadly accessible
Source: ISO/IEC 27001 (information security management), read 29 Sep 2026
ISO/IEC 27001 A.5.34Privacy and protection of personal identifiable information (PII)

Privacy and protection of personal identifiable information (PII). The organization is to identify, and then satisfy, the requirements for preserving privacy and protecting personally identifiable information that arise from applicable laws, regulations and contracts. Purpose (stated in ISO/IEC 27002:2022): ensures compliance with requirements on the information security aspects of protecting PII. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.34.

What a reviewer asks to see: Statement of Applicability entry for control A.5.34, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific privacy and PII protection policy and its communication to relevant parties; Privacy procedures communicated to everyone who processes PII; Appointment of a privacy officer or equivalent with documented responsibilities; A record of processing or PII inventory mapping which laws apply to each processing activity
Where camera lists usually fall short: Privacy is treated as a legal matter only, with no link to security controls; No one is formally responsible for guiding staff and providers on PII handling; Cross-border transfers of PII occur without checking applicable restrictions; Privacy impact assessments are not performed for new processing
Source: ISO/IEC 27001 (information security management), read 29 Sep 2026
ISO/IEC 27001 A.7.4Physical security monitoring

Physical security monitoring. Premises are to be watched continuously for unauthorized physical entry. Purpose (stated in ISO/IEC 27002:2022): detects and deters unauthorized physical access. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 7.4.

What a reviewer asks to see: Statement of Applicability entry for control A.7.4, showing inclusion or justified exclusion, implementation status and the risks it treats; Coverage plans for CCTV and intruder detection over sensitive areas, external doors, accessible windows and unoccupied zones; Alarm and detector installation certificates to applicable standards and periodic test records, including battery-powered components; Monitoring logs or monitoring-provider reports showing alarms raised and responses; Access restrictions and hardening of CCTV and alarm systems, including protection of video feeds and remote management
Where camera lists usually fall short: CCTV records but nobody reviews footage or responds to alerts; Detectors are installed but never tested, with flat batteries unnoticed; Video systems are exposed on the network with default credentials; Video is retained longer than local law permits
Source: ISO/IEC 27001 (information security management), read 29 Sep 2026

See the specimen list run Map your own list