Skip to main content
Category: Technical Security Controls

Cabling Security

Also known as: Annex A 7.12 Cabling Security, Cable Security
Simply put

Cabling security is about protecting the power and communication cables that carry data and electricity to and from your systems, so they cannot be easily damaged, tampered with, or tapped into. In ISO 27001 it is one of the reference controls that helps keep information safe at the physical level, before it ever reaches software defenses. The goal is to reduce risks such as service interruptions, interference, or unauthorized interception of the information moving through those cables.

Formal definition

Cabling Security is a reference control listed in ISO/IEC 27001 Annex A (identified as control 7.12 in the 2022 revision, which organizes Annex A controls into four themes) addressing the protection of power and telecommunications cabling that carries data or supports information services. It typically involves implementing processes, procedures, and technical measures to safeguard cabling from damage, interference, interception, and unauthorized access, for example through structured cabling design, controlled and segregated pathways, secured termination points, and physical protection of routes. As an Annex A control, its applicability is determined via the Statement of Applicability and informed by the organization's risk assessment rather than being universally mandatory; the specific safeguards selected depend on scope, environment, and identified risks. This control addresses only the physical cabling layer and complements, but does not replace, other physical and technical controls within the ISMS.

Why it matters

Cabling security addresses a layer of protection that is easy to overlook because it sits beneath software and network defenses. Power and telecommunications cables physically carry data and electricity to and from systems, and if they can be damaged, interfered with, or tapped into, the confidentiality, integrity, and availability of information can be compromised before any logical control has a chance to act. A severed or degraded cable can interrupt services, while an unprotected communications route can create an opportunity for interception. Because these risks originate at the physical layer, they cannot be fully mitigated by encryption or access management alone.

Within ISO/IEC 27001, Cabling Security is one of the Annex A reference controls (identified as control 7.12 in the 2022 revision, which organizes Annex A into four themes). Its inclusion in an organization's control set is not automatic: applicability is determined through the Statement of Applicability and informed by the organization's risk assessment. For organizations whose scope includes physical data center space, on-premises infrastructure, or surveillance and communications environments, cabling protection is often a meaningful part of demonstrating that physical risks have been considered. Because the control targets only the cabling layer, it complements, rather than replaces, other physical and technical controls within the ISMS.

Who it's relevant to

ISO 27001 Compliance and GRC Managers
Those managing an ISMS need to decide whether Cabling Security (Annex A 7.12 in the 2022 revision) applies within their defined scope, document that decision in the Statement of Applicability, and ensure it is supported by the risk assessment. This is particularly relevant where the certified scope includes on-premises infrastructure or physical facilities.
Facilities and Data Center Teams
Teams responsible for physical infrastructure implement the practical safeguards, structured cabling design, segregated and controlled pathways, secured termination points, and physical protection of routes, that give effect to this control. Their work protects cabling from damage, interference, and interception at the physical layer.
Security and Surveillance Project Planners
For projects involving surveillance or communications infrastructure, beginning with a structured cabling plan that defines pathways, termination points, and equipment layout supports both operational reliability and the physical security objectives this control addresses.
Auditors and Certification Body Assessors
Those evaluating an ISMS assess whether the organization's treatment of cabling security is appropriate to its scope and risk profile, and whether the selected safeguards are consistent with what is recorded in the Statement of Applicability. They evaluate design and, where relevant, implementation rather than assuming a fixed set of required measures.

Inside Cabling Security

Physical Cable Protection
Measures to protect power and telecommunications cabling carrying data or supporting information services from interception, interference, or physical damage. In most engagements this addresses conduit, protective routing, and physical barriers around cable runs.
Power and Telecommunications Cabling Distinction
Cabling security typically covers both power cabling and data/telecommunications cabling, since disruption or compromise of either can affect availability and confidentiality of information services depending on the environment.
Segregation of Power and Data Cables
Separation of power lines from communications lines to help prevent electromagnetic interference. The degree of segregation applied depends on scope, facility design, and risk assessment outcomes.
Access Control to Cabling Infrastructure
Controls restricting physical access to patch panels, cable rooms, and distribution points, typically to reduce the risk of unauthorized tapping, patching changes, or tampering.
Labeling and Identification
Marking of cables and equipment to reduce handling errors, though labeling schemes may be balanced against the risk of disclosing sensitive routing information to unauthorized parties.
Relationship to ISO/IEC 27001 Annex A
Cabling security is addressed as a reference control within the physical security theme of ISO/IEC 27001 Annex A, which is selected via the Statement of Applicability and informed by risk assessment. Annex A control counts and groupings depend on the edition (114 controls in the 2013 version, reorganized into 93 controls across four themes in the 2022 revision). Implementation guidance is typically expanded in ISO/IEC 27002.
Relationship to SOC 2 Trust Services Criteria
Cabling and physical infrastructure protection may be evidenced under the physical access controls within the Security category (Common Criteria) of the Trust Services Criteria, and potentially the optional Availability category depending on the scope selected for the engagement.

Common questions

Answers to the questions practitioners most commonly ask about Cabling Security.

Is cabling security a mandatory control that every organization must implement to achieve ISO 27001 certification?
No. Cabling security appears among the Annex A reference controls, which are not blanket mandates. Annex A controls are selected through the Statement of Applicability and informed by the organization's risk assessment, so a control may be justifiably excluded where it does not apply to the defined scope of the ISMS. The certifiable requirements are found in clauses 4 through 10; Annex A provides reference controls to consider rather than a fixed checklist. Whether cabling security applies typically depends on the organization's physical environment, its risk profile, and scoping decisions.
Does addressing cabling security in a SOC 2 examination mean it maps directly to an ISO 27001 Annex A control?
Not directly. The Trust Services Criteria used in a SOC 2 examination and the ISO 27001 Annex A reference controls are separate frameworks and should not be conflated. Physical and environmental protections may be relevant to the SOC 2 Common Criteria depending on scope, and cabling protections appear in ISO 27001 Annex A, but the two are structured differently. Mapping between SOC 2 and ISO 27001 is possible but partial, and satisfying one does not automatically satisfy the other.
How do organizations typically decide whether cabling security is in scope?
The decision usually flows from the risk assessment and scoping process. In an ISO 27001 context, applicability is documented in the Statement of Applicability with justification for inclusion or exclusion. In a SOC 2 context, relevance depends on the criteria selected and the boundaries of the system described. Organizations that rely primarily on third-party data centers may treat certain physical controls as inherited from a service provider, while those operating their own facilities are more likely to address cabling protections directly. Outcomes depend on the environment, the auditor or certification body, and the defined scope.
What kinds of evidence might an auditor or certification body look for regarding cabling security?
Evidence expectations vary by engagement, but organizations commonly maintain documentation and observable practices demonstrating that cabling is protected against interception, interference, or damage. This can include physical safeguards, access restrictions to areas where cabling runs, and records showing the control operates as designed. For a SOC 2 Type II, operating effectiveness would be assessed over the defined review period, whereas a Type I assesses suitability of design at a point in time. The specific evidence sought depends on the auditor, the framework, and the scope.
How is cabling security handled when physical infrastructure is outsourced to a data center or cloud provider?
Where physical infrastructure is outsourced, cabling protections are often managed by the service provider rather than the customer. Organizations frequently rely on the provider's own assurance documentation to address these physical controls and may reference that reliance in their scoping and Statement of Applicability. It is important to note that a SOC 2 report or an ISO 27001 certificate covers only the defined scope of the provider's system or ISMS, so organizations should confirm that the relevant physical protections fall within the provider's covered scope.
What are the limitations of treating cabling security as fully addressed once a control is in place?
Implementing a cabling security control does not by itself guarantee the absence of physical compromise or interference. A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from incidents, and an ISO 27001 certificate covers only the defined scope of the ISMS. Effectiveness typically depends on ongoing operation, periodic review, and alignment with the current risk assessment rather than a one-time deployment.

Common misconceptions

Cabling security is a mandatory control that every organization must implement identically.
In ISO/IEC 27001, Annex A controls including cabling security are reference controls selected through the Statement of Applicability and informed by risk assessment; applicability and depth depend on scope and the environment. Under SOC 2, relevant physical controls are assessed against the criteria the service organization has scoped in, so approaches vary by engagement.
Addressing cabling security in a SOC 2 report or ISO 27001 certificate guarantees the infrastructure cannot be tapped or disrupted.
A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from interception or breaches. An ISO 27001 certificate covers only the defined scope of the ISMS. Neither outcome is an absolute assurance against cable compromise.
Satisfying cabling security expectations under one framework automatically satisfies the other.
Mapping between SOC 2 and ISO 27001 is possible but partial. SOC 2 is an attestation examination performed by a licensed CPA firm resulting in a report, while ISO 27001 is a certification issued by an accredited certification body. Meeting the physical control expectations of one does not automatically satisfy the other.

Best practices

Route power and telecommunications cabling through protective conduit or otherwise shield cable runs where the risk assessment indicates a need to reduce interception or damage.
Segregate power cabling from data cabling where feasible to reduce electromagnetic interference, tailoring the degree of separation to facility design and scope.
Restrict and monitor physical access to cable rooms, patch panels, and distribution points to limit opportunities for unauthorized tapping or tampering.
Adopt a labeling scheme for cables and equipment that supports accurate handling while balancing the risk of disclosing sensitive routing details.
Document cabling controls in the Statement of Applicability for ISO 27001 engagements, referencing the specific Annex A edition, and align evidence to the applicable Trust Services Criteria for SOC 2 engagements.
Retain records and evidence demonstrating that cabling protections operated as intended, particularly for a SOC 2 Type II examination that assesses operating effectiveness over the defined review period.