A.7.9A.7 Physical controls

Security of assets off-premises

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.7.9 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Protect assets used away from the premises to prevent loss, damage, theft, compromise or disruption.

How to meet this control

In short: Protect assets used outside the organisation’s premises.

  1. Step 01Require management authorisation before any device, including BYOD, is taken off-site to handle organisational information, and log removals
  2. Step 02Encrypt all laptops and mobile devices with full-disk encryption and enforce it through MDM so off-site loss does not expose data
  3. Step 03Enable location tracking and remote wipe on portable and fixed off-site equipment, and apply tamper-proofing to unattended kit
  4. Step 04Train staff never to leave equipment unattended in public, to use privacy screens, and to guard against shoulder-surfing in transit
  5. Step 05Keep a chain-of-custody record when off-site equipment passes between people
  6. Step 06Follow manufacturer guidance to protect equipment from heat, water, humidity and dust when travelling

Tip: Encrypt laptops and require cable locks/secure storage when travelling.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Require management authorisation for any off-site device, including BYOD, that handles information
  • ›Never leave equipment or media unattended in public or unsecured places
  • ›Follow manufacturers instructions to protect equipment from heat, water, humidity and dust
  • ›Keep a chain-of-custody log when off-site equipment passes between people
  • ›Require authorisation and keep records when removing equipment from premises
  • ›Guard against shoulder surfing and viewing of screens on public transport
  • ›Enable location tracking and remote wipe, and apply monitoring and tamper-proofing to fixed off-site equipment

Audit evidence to keep

  • - Authorisation and removal records for off-site equipment
  • - MDM reports showing encryption and remote-wipe enabled on the fleet
  • - A chain-of-custody log for transferred equipment
  • - The off-premises asset-security policy
  • - Records of location tracking or tamper-proofing for fixed off-site assets

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.7.9. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all physical controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.