Cabling Security
Cabling security is about protecting the power and communication cables that carry data and electricity to and from your systems, so they cannot be easily damaged, tampered with, or tapped into. In ISO 27001 it is one of the reference controls that helps keep information safe at the physical level, before it ever reaches software defenses. The goal is to reduce risks such as service interruptions, interference, or unauthorized interception of the information moving through those cables.
Cabling Security is a reference control listed in ISO/IEC 27001 Annex A (identified as control 7.12 in the 2022 revision, which organizes Annex A controls into four themes) addressing the protection of power and telecommunications cabling that carries data or supports information services. It typically involves implementing processes, procedures, and technical measures to safeguard cabling from damage, interference, interception, and unauthorized access, for example through structured cabling design, controlled and segregated pathways, secured termination points, and physical protection of routes. As an Annex A control, its applicability is determined via the Statement of Applicability and informed by the organization's risk assessment rather than being universally mandatory; the specific safeguards selected depend on scope, environment, and identified risks. This control addresses only the physical cabling layer and complements, but does not replace, other physical and technical controls within the ISMS.
Why it matters
Cabling security addresses a layer of protection that is easy to overlook because it sits beneath software and network defenses. Power and telecommunications cables physically carry data and electricity to and from systems, and if they can be damaged, interfered with, or tapped into, the confidentiality, integrity, and availability of information can be compromised before any logical control has a chance to act. A severed or degraded cable can interrupt services, while an unprotected communications route can create an opportunity for interception. Because these risks originate at the physical layer, they cannot be fully mitigated by encryption or access management alone.
Within ISO/IEC 27001, Cabling Security is one of the Annex A reference controls (identified as control 7.12 in the 2022 revision, which organizes Annex A into four themes). Its inclusion in an organization's control set is not automatic: applicability is determined through the Statement of Applicability and informed by the organization's risk assessment. For organizations whose scope includes physical data center space, on-premises infrastructure, or surveillance and communications environments, cabling protection is often a meaningful part of demonstrating that physical risks have been considered. Because the control targets only the cabling layer, it complements, rather than replaces, other physical and technical controls within the ISMS.
Who it's relevant to
Inside Cabling Security
Common questions
Answers to the questions practitioners most commonly ask about Cabling Security.