ISO 27001 Annex A 7.9 Security Of Assets Off-Premises (The Unofficial Zero BS Guide)

ISO 27001 Annex A 7.9

ISO 27001 Annex A 7.9 protects equipment and data taken away from company premises. Managers must approve all removals and track device locations to keep off-site assets safe.

Key Takeaways

  • Require formal management approval: Ensure staff get explicit manager sign-off before taking any company equipment or hardware off site.
  • Track asset locations continuously: Keep an updated off-site equipment log to record who holds each device and its current physical location.
  • Enforce full drive encryption: Require strong code protection on all portable hardware to guard data if devices are lost or stolen.
  • Apply physical security rules: Teach staff never to leave off-site hardware unattended in cars, public spaces, or unsecured hotel rooms.
  • Log asset removals and returns: Use a central task system to track when equipment leaves the building and confirm its safe return.
  • Define clear usage limits: Set clear policy rules stating that off-site assets are for approved business tasks only.
  • Report missing items fast: Train workers to report lost or stolen off-site gear right away so teams can wipe data remotely.
  • Inspect returned hardware: Check returned equipment for physical damage or safety issues before issuing it to other workers.

How to Implement ISO 27001 Annex A 7.9

  • Track device locations: Update your central asset register to record the current physical location of all off-site equipment.
  • Set up approval steps: Use a central task system to require manager approval before staff take any gear off site.
  • Publish physical security rules: Write simple safety guides on your internal intranet to teach staff how to protect off-site devices.
  • Get worker sign-offs: Ensure all new employees sign physical security policy rules during their initial onboarding.
  • Run spot checks: Perform regular routine checks on equipment listed as off-site to verify locations and user details.
  • Enforce full device encryption: Mandate full code protection on all portable equipment before allowing off-site removal.
  • Define transit safety steps: Require workers to use locked bags and avoid leaving equipment unattended in vehicles or public spaces.
  • Set fast incident steps: Establish clear loss reporting steps so teams can lock or wipe missing off-site devices quickly.
  • Inspect returned equipment: Check hardware for physical harm or tampering whenever staff return off-site gear to the office.

When you’re ready to bring compliance into one place

High Table Compliance Platform powered by hicomply
High Table Compliance Platform powered by hicomply

How to Audit ISO 27001 Annex A 7.9

  • Review off-site asset policies: Inspect written rules to check that clear steps exist for taking equipment away from company premises.
  • Verify manager removal sign-offs: Sample log records to confirm staff get manager approval before taking gear off site.
  • Audit the central asset log: Sample tracking entries to confirm location details clearly show who holds each off-site item.
  • Check device code protection: Inspect sample off-site hardware to ensure full drive encryption guards data if gear is lost.
  • Inspect physical security guides: Check that staff receive clear guidance on protecting gear in vehicles, hotels, and public spaces.
  • Review worker policy sign-offs: Sample onboarding files to verify staff sign off on off-site safety rules during induction.
  • Check physical spot check logs: Inspect records of routine asset audits to confirm teams check off-site items regularly.
  • Audit loss and theft reports: Review report tickets for missing gear to confirm fast reporting and remote lock actions.
  • Check hardware return steps: Confirm teams inspect and log returned gear for physical damage or tampering before reuse.
  • Verify remote wipe tools: Confirm central system controls can lock or erase missing off-site hardware from a distance.
  • Review off-site insurance cover: Check active insurance files to ensure cover extends to company hardware used off site.
  • Check contractor safety logs: Verify external workers sign safety agreements before taking company gear off site.
  • Verify clear desk and screen rules: Check that staff lock screens and cover screens when using off-site devices in public.
  • Check safe transit controls: Verify staff use padded, locked bags or secure couriers when moving hardware between sites.

Audit Evidence Checklist

  • Central asset register: Maintain an up-to-date inventory log showing current location details and status for all portable equipment.
  • Removal sign-off logs: Keep task management approval records showing formal manager sign-off for gear issued to remote staff.
  • Security review minutes: Supply meeting notes from regular security reviews that discuss off-site risks and asset loss events.
  • Staff sign-off records: Provide signed policy receipt forms proving employees read and accepted off-site security rules.
  • Off-site insurance policies: Keep active insurance files showing complete cover for business equipment used away from the office.
  • Asset spot check records: Produce internal review logs that show regular routine checks on hardware listed as off site.
  • Incident report tickets: Supply formal incident logs for missing or damaged off-site gear showing fast remote lock actions.
  • Hardware return logs: Maintain inspection receipts confirming technical teams check returned gear for physical damage or tampering.

What to Teach Employees

  • Get approval before removal: Teach staff to request formal manager sign-off before taking any company equipment or devices off site.
  • Never leave gear unattended: Instruct workers never to leave off-site equipment in plain sight inside parked cars, hotels, or public cafes.
  • Lock screens when stepping away: Remind staff to lock device screens every time they walk away from equipment in public or home spaces.
  • Guard against shoulder surfing: Teach employees to use screen privacy filters or face away from public view when viewing sensitive files.
  • Use secure network connections: Warn staff against using open public networks and require protected connections for all remote work.
  • Report lost equipment right away: Ensure workers know to report missing hardware fast so support teams can lock or wipe data remotely.
  • Store equipment safely at home: Instruct remote workers to lock gear away when not in use to keep devices safe from guests or family.
  • Use safe transport bags: Require employees to carry portable equipment in padded, neutral bags to prevent theft and physical damage during transit.
  • Keep business items separate: Teach staff never to use unapproved personal accessories on work hardware or move work files to personal drives.
  • Hand back unused gear: Remind workers to return off-site equipment to the main office as soon as travel tasks or remote projects finish.
  • Check hardware for damage: Teach staff to inspect off-site equipment regularly for signs of physical wear, cable decay, or tampering.
  • Follow clear desk rules off site: Remind staff to clear away paper notes, printouts, and portable items at the end of every work day.
  • Verify off-site asset labels: Teach workers to check that asset tracking tags stay attached to all company equipment used away from site premises.
  • Follow physical access rules: Instruct employees to prevent unapproved visitors from accessing company hardware in remote or off-site work areas.

Common Implementation Challenges

  • Bypassing removal sign-offs: Staff take equipment off site without asking managers first. Require system approval tasks before devices leave the office.
  • Outdated location registers: Asset logs fail to show who holds gear as hardware moves between remote workers. Run regular asset spot checks to keep location lists accurate.
  • Leaving gear in vehicles: Workers leave devices and tech bags in plain sight inside parked cars. Mandate strict policies against leaving equipment unattended in vehicles.
  • Unencrypted off-site devices: Portable gear taken off site lacks full drive protection, exposing data if stolen. Enforce mandatory code protection on all off-site equipment.
  • Delayed theft reporting: Employees wait days to report lost off-site gear out of fear or embarrassment. Build a blameless culture so staff report missing items right away.
  • Unsecured home work spaces: Remote staff leave active screens unlocked around family members or house guests. Train workers to lock screens and store gear securely at home.
  • Connecting to open public networks: Traveling staff connect to unverified public connections in cafes or airports. Require protected, encrypted connections for all off-site web access.
  • Ignoring physical damage checks: Returned off-site hardware goes back into stock without checks for physical harm or tampering. Require support teams to inspect all returned gear.
  • Overlooking contractor gear: External workers carry company hardware off site without signing clear asset agreements. Ensure third parties sign off on safety rules before taking equipment.
  • Unsafe transit methods: Workers move hardware in flimsy, unpadded bags that cause physical damage. Supply neutral, padded carrying cases for all traveling staff.
  • Lack of remote wipe tools: Support teams cannot lock or clear missing off-site equipment from a distance. Set up central management controls to wipe lost hardware remotely.
  • Unclear off-site insurance cover: Companies assume standard insurance covers equipment used abroad or at home. Review policies to ensure complete cover for off-site hardware.
  • Overlooking clear desk rules off site: Remote staff leave confidential paper notes on desks after finishing work. Enforce clean desk habits for all off-site and home work setups.
  • Long-term off-site asset hoarding: Workers keep temporary off-site gear indefinitely after travel projects end. Track removal return dates to ensure prompt return of equipment.
  • Unlabeled physical assets: Off-site gear lacks physical tracking tags, making it hard to identify lost items. Attach tamper-evident tracking labels to all portable equipment.
  • Unapproved personal device usage: Staff copy sensitive work files onto personal, unmanaged laptops or drives when working away. Enforce strict rules against using personal hardware for business data.

How to Measure Effectiveness (KPIs)

  • Off-site device encryption rate: Measure the percentage of active off-site hardware carrying mandatory full drive code protection.
  • Removal sign-off compliance rate: Track the proportion of off-site equipment removals backed by formal manager sign-offs.
  • Asset register location accuracy: Measure the percentage of off-site devices that match assigned locations during physical spot checks.
  • Off-site loss incident rate: Track the total number of lost, stolen, or misplaced off-site hardware items reported each year.
  • Off-site loss reporting speed: Monitor the average time taken by staff to report missing off-site equipment after noticing the loss.
  • Remote wipe success rate: Measure the percentage of missing off-site devices successfully locked or erased from a distance.
  • Overdue asset return rate: Track the proportion of temporary off-site devices kept past agreed return dates.
  • Returned hardware check pass rate: Measure the percentage of returned off-site items that undergo full physical inspection before reuse.
  • Policy sign-off compliance rate: Track the percentage of remote and traveling workers who sign off on off-site safety rules.
  • Off-site audit finding count: Monitor the number of security gaps flagged during internal reviews of off-site asset controls.
  • Off-site insurance coverage rate: Track the proportion of active off-site devices fully covered under valid insurance policies.
  • Unapproved connection block rate: Monitor the number of untrusted network or port connections blocked on off-site devices.
  • Off-site asset awareness rate: Track the percentage of remote staff who finish annual training on safe off-site gear handling.
  • Physical label check pass rate: Measure the proportion of off-site devices correctly carrying physical tracking tags during checks.

ISO 27001 Annex A 7.9 depends on several other ISO 27001 controls:

  • ISO 27001 Clause 8.1 (Operational Planning): Directs the management of asset security.
  • ISO 27001 Annex A 5.9 (Inventory of Information): Provides the foundation for tracking.
  • ISO 27001 Annex A 7.10 (Storage Media): Governs the data on off-site devices.
ISO 27001 Security Of Assets Off-Premises Explained - Annex A 7.9 - High Table Compliance Platform powered by hicomply
High Table Compliance Platform powered by hicomply