ISO 27001 and Technical Surveillance Risk

ISO/IEC 27001:2022 does not say the word TSCM — but its risk assessment clause and Annex A physical controls leave certified organisations little room to ignore covert surveillance of the rooms where sensitive information is spoken.

Framework: International standardLast reviewed: 2026-09-03

Surveillance risk belongs in your clause 6.1.2 assessment

ISO/IEC 27001:2022 clause 6.1.2 requires a risk assessment process that identifies risks to the confidentiality, integrity and availability of information within the ISMS scope. Information discussed in boardrooms, negotiation rooms and R&D spaces is in scope whether or not it ever touches a server. If covert interception of that information is plausible in your threat environment, it belongs on the risk register with an owner and a treatment decision.

Certification auditors increasingly probe exactly this: not whether every conceivable risk is treated, but whether the assessment considered the organisation's real information flows — including the spoken ones.

The Annex A controls that carry the weight

The 2022 revision groups physical controls under Annex A section 7. Control 7.1 requires physical security perimeters around areas containing sensitive information; 7.2 governs physical entry; 7.3 requires securing offices, rooms and facilities; 7.4 requires physical security monitoring; and 7.6 addresses working in secure areas. Together these define the expectation that spaces holding sensitive information are protected against unauthorised access and interference — which is what covert device placement is.

A periodic technical surveillance countermeasures inspection is a natural verification activity for these controls: it tests whether the perimeter, entry and monitoring controls actually kept unauthorised equipment out of the secure area. That framing — TSCM as effectiveness verification, echoing clause 9.1 performance evaluation — is the cleanest way to place it in an ISMS.

Statement of Applicability and audit evidence

If your risk assessment identifies eavesdropping risk in defined spaces, your Statement of Applicability should reflect how the section 7 controls treat it, and your operating evidence should include the inspection records. Auditors read dated reports, defined scope, and a named control owner as an operating control; they read a one-off sweep with no cadence and no records as theatre.

For organisations pursuing certification, this is also an easy differentiator: most ISMS implementations are thin on the physical-acoustic vector, and a documented, proportionate counter-surveillance control is visible maturity at very modest cost.

Primary sources

This guidance is general information, not legal advice. Regulatory obligations depend on your entity classification, jurisdiction and facts — confirm specifics with your counsel or compliance function.

Scope an assessment

A short conversation establishes scope and a fixed price. Assessments run across the UK, Europe and the US.

Speak to a specialist