Security of assets off-premises
Purpose
Protect assets used away from the premises to prevent loss, damage, theft, compromise or disruption.
How to meet this control
In short: Protect assets used outside the organisation’s premises.
- Step 01Require management authorisation before any device, including BYOD, is taken off-site to handle organisational information, and log removals
- Step 02Encrypt all laptops and mobile devices with full-disk encryption and enforce it through MDM so off-site loss does not expose data
- Step 03Enable location tracking and remote wipe on portable and fixed off-site equipment, and apply tamper-proofing to unattended kit
- Step 04Train staff never to leave equipment unattended in public, to use privacy screens, and to guard against shoulder-surfing in transit
- Step 05Keep a chain-of-custody record when off-site equipment passes between people
- Step 06Follow manufacturer guidance to protect equipment from heat, water, humidity and dust when travelling
Tip: Encrypt laptops and require cable locks/secure storage when travelling.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Require management authorisation for any off-site device, including BYOD, that handles information
- ›Never leave equipment or media unattended in public or unsecured places
- ›Follow manufacturers instructions to protect equipment from heat, water, humidity and dust
- ›Keep a chain-of-custody log when off-site equipment passes between people
- ›Require authorisation and keep records when removing equipment from premises
- ›Guard against shoulder surfing and viewing of screens on public transport
- ›Enable location tracking and remote wipe, and apply monitoring and tamper-proofing to fixed off-site equipment
Audit evidence to keep
- - Authorisation and removal records for off-site equipment
- - MDM reports showing encryption and remote-wipe enabled on the fleet
- - A chain-of-custody log for transferred equipment
- - The off-premises asset-security policy
- - Records of location tracking or tamper-proofing for fixed off-site assets
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.7.9. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.