Surveillance risk belongs in your clause 6.1.2 assessment
ISO/IEC 27001:2022 clause 6.1.2 requires a risk assessment process that identifies risks to the confidentiality, integrity and availability of information within the ISMS scope. Information discussed in boardrooms, negotiation rooms and R&D spaces is in scope whether or not it ever touches a server. If covert interception of that information is plausible in your threat environment, it belongs on the risk register with an owner and a treatment decision.
Certification auditors increasingly probe exactly this: not whether every conceivable risk is treated, but whether the assessment considered the organisation's real information flows — including the spoken ones.
The Annex A controls that carry the weight
The 2022 revision groups physical controls under Annex A section 7. Control 7.1 requires physical security perimeters around areas containing sensitive information; 7.2 governs physical entry; 7.3 requires securing offices, rooms and facilities; 7.4 requires physical security monitoring; and 7.6 addresses working in secure areas. Together these define the expectation that spaces holding sensitive information are protected against unauthorised access and interference — which is what covert device placement is.
A periodic technical surveillance countermeasures inspection is a natural verification activity for these controls: it tests whether the perimeter, entry and monitoring controls actually kept unauthorised equipment out of the secure area. That framing — TSCM as effectiveness verification, echoing clause 9.1 performance evaluation — is the cleanest way to place it in an ISMS.
Statement of Applicability and audit evidence
If your risk assessment identifies eavesdropping risk in defined spaces, your Statement of Applicability should reflect how the section 7 controls treat it, and your operating evidence should include the inspection records. Auditors read dated reports, defined scope, and a named control owner as an operating control; they read a one-off sweep with no cadence and no records as theatre.
For organisations pursuing certification, this is also an easy differentiator: most ISMS implementations are thin on the physical-acoustic vector, and a documented, proportionate counter-surveillance control is visible maturity at very modest cost.