ISO 27001 Security Of Assets Off-Premises Explained – Annex A 7.9

Stuart Barker -271

ISO 27001 Annex A 7.9 protects equipment and data taken away from company premises. Managers must approve all removals and track device locations to keep off-site assets safe.

Key Takeaways

  • Require formal management approval: Ensure staff get explicit manager sign-off before taking any company equipment or hardware off site.
  • Track asset locations continuously: Keep an updated off-site equipment log to record who holds each device and its current physical location.
  • Enforce full drive encryption: Require strong code protection on all portable hardware to guard data if devices are lost or stolen.
  • Apply physical security rules: Teach staff never to leave off-site hardware unattended in cars, public spaces, or unsecured hotel rooms.
  • Log asset removals and returns: Use a central task system to track when equipment leaves the building and confirm its safe return.
  • Define clear usage limits: Set clear policy rules stating that off-site assets are for approved business tasks only.
  • Report missing items fast: Train workers to report lost or stolen off-site gear right away so teams can wipe data remotely.
  • Inspect returned hardware: Check returned equipment for physical damage or safety issues before issuing it to other workers.

How to Implement ISO 27001 Annex A 7.9

  • Track device locations: Update your central asset register to record the current physical location of all off-site equipment.
  • Set up approval steps: Use a central task system to require manager approval before staff take any gear off site.
  • Publish physical security rules: Write simple safety guides on your internal intranet to teach staff how to protect off-site devices.
  • Get worker sign-offs: Ensure all new employees sign physical security policy rules during their initial onboarding.
  • Run spot checks: Perform regular routine checks on equipment listed as off-site to verify locations and user details.
  • Enforce full device encryption: Mandate full code protection on all portable equipment before allowing off-site removal.
  • Define transit safety steps: Require workers to use locked bags and avoid leaving equipment unattended in vehicles or public spaces.
  • Set fast incident steps: Establish clear loss reporting steps so teams can lock or wipe missing off-site devices quickly.
  • Inspect returned equipment: Check hardware for physical harm or tampering whenever staff return off-site gear to the office.

How to Audit ISO 27001 Annex A 7.9

  • Review off-site asset policies: Inspect written rules to check that clear steps exist for taking equipment away from company premises.
  • Verify manager removal sign-offs: Sample log records to confirm staff get manager approval before taking gear off site.
  • Audit the central asset log: Sample tracking entries to confirm location details clearly show who holds each off-site item.
  • Check device code protection: Inspect sample off-site hardware to ensure full drive encryption guards data if gear is lost.
  • Inspect physical security guides: Check that staff receive clear guidance on protecting gear in vehicles, hotels, and public spaces.
  • Review worker policy sign-offs: Sample onboarding files to verify staff sign off on off-site safety rules during induction.
  • Check physical spot check logs: Inspect records of routine asset audits to confirm teams check off-site items regularly.
  • Audit loss and theft reports: Review report tickets for missing gear to confirm fast reporting and remote lock actions.
  • Check hardware return steps: Confirm teams inspect and log returned gear for physical damage or tampering before reuse.
  • Verify remote wipe tools: Confirm central system controls can lock or erase missing off-site hardware from a distance.
  • Review off-site insurance cover: Check active insurance files to ensure cover extends to company hardware used off site.
  • Check contractor safety logs: Verify external workers sign safety agreements before taking company gear off site.
  • Verify clear desk and screen rules: Check that staff lock screens and cover screens when using off-site devices in public.
  • Check safe transit controls: Verify staff use padded, locked bags or secure couriers when moving hardware between sites.

Audit Evidence Checklist

  • Central asset register: Maintain an up-to-date inventory log showing current location details and status for all portable equipment.
  • Removal sign-off logs: Keep task management approval records showing formal manager sign-off for gear issued to remote staff.
  • Security review minutes: Supply meeting notes from regular security reviews that discuss off-site risks and asset loss events.
  • Staff sign-off records: Provide signed policy receipt forms proving employees read and accepted off-site security rules.
  • Off-site insurance policies: Keep active insurance files showing complete cover for business equipment used away from the office.
  • Asset spot check records: Produce internal review logs that show regular routine checks on hardware listed as off site.
  • Incident report tickets: Supply formal incident logs for missing or damaged off-site gear showing fast remote lock actions.
  • Hardware return logs: Maintain inspection receipts confirming technical teams check returned gear for physical damage or tampering.

What to Teach Employees

  • Get approval before removal: Teach staff to request formal manager sign-off before taking any company equipment or devices off site.
  • Never leave gear unattended: Instruct workers never to leave off-site equipment in plain sight inside parked cars, hotels, or public cafes.
  • Lock screens when stepping away: Remind staff to lock device screens every time they walk away from equipment in public or home spaces.
  • Guard against shoulder surfing: Teach employees to use screen privacy filters or face away from public view when viewing sensitive files.
  • Use secure network connections: Warn staff against using open public networks and require protected connections for all remote work.
  • Report lost equipment right away: Ensure workers know to report missing hardware fast so support teams can lock or wipe data remotely.
  • Store equipment safely at home: Instruct remote workers to lock gear away when not in use to keep devices safe from guests or family.
  • Use safe transport bags: Require employees to carry portable equipment in padded, neutral bags to prevent theft and physical damage during transit.
  • Keep business items separate: Teach staff never to use unapproved personal accessories on work hardware or move work files to personal drives.
  • Hand back unused gear: Remind workers to return off-site equipment to the main office as soon as travel tasks or remote projects finish.
  • Check hardware for damage: Teach staff to inspect off-site equipment regularly for signs of physical wear, cable decay, or tampering.
  • Follow clear desk rules off site: Remind staff to clear away paper notes, printouts, and portable items at the end of every work day.
  • Verify off-site asset labels: Teach workers to check that asset tracking tags stay attached to all company equipment used away from site premises.
  • Follow physical access rules: Instruct employees to prevent unapproved visitors from accessing company hardware in remote or off-site work areas.

Common Implementation Challenges

  • Bypassing removal sign-offs: Staff take equipment off site without asking managers first. Require system approval tasks before devices leave the office.
  • Outdated location registers: Asset logs fail to show who holds gear as hardware moves between remote workers. Run regular asset spot checks to keep location lists accurate.
  • Leaving gear in vehicles: Workers leave devices and tech bags in plain sight inside parked cars. Mandate strict policies against leaving equipment unattended in vehicles.
  • Unencrypted off-site devices: Portable gear taken off site lacks full drive protection, exposing data if stolen. Enforce mandatory code protection on all off-site equipment.
  • Delayed theft reporting: Employees wait days to report lost off-site gear out of fear or embarrassment. Build a blameless culture so staff report missing items right away.
  • Unsecured home work spaces: Remote staff leave active screens unlocked around family members or house guests. Train workers to lock screens and store gear securely at home.
  • Connecting to open public networks: Traveling staff connect to unverified public connections in cafes or airports. Require protected, encrypted connections for all off-site web access.
  • Ignoring physical damage checks: Returned off-site hardware goes back into stock without checks for physical harm or tampering. Require support teams to inspect all returned gear.
  • Overlooking contractor gear: External workers carry company hardware off site without signing clear asset agreements. Ensure third parties sign off on safety rules before taking equipment.
  • Unsafe transit methods: Workers move hardware in flimsy, unpadded bags that cause physical damage. Supply neutral, padded carrying cases for all traveling staff.
  • Lack of remote wipe tools: Support teams cannot lock or clear missing off-site equipment from a distance. Set up central management controls to wipe lost hardware remotely.
  • Unclear off-site insurance cover: Companies assume standard insurance covers equipment used abroad or at home. Review policies to ensure complete cover for off-site hardware.
  • Overlooking clear desk rules off site: Remote staff leave confidential paper notes on desks after finishing work. Enforce clean desk habits for all off-site and home work setups.
  • Long-term off-site asset hoarding: Workers keep temporary off-site gear indefinitely after travel projects end. Track removal return dates to ensure prompt return of equipment.
  • Unlabeled physical assets: Off-site gear lacks physical tracking tags, making it hard to identify lost items. Attach tamper-evident tracking labels to all portable equipment.
  • Unapproved personal device usage: Staff copy sensitive work files onto personal, unmanaged laptops or drives when working away. Enforce strict rules against using personal hardware for business data.

How to Measure Effectiveness (KPIs)

  • Off-site device encryption rate: Measure the percentage of active off-site hardware carrying mandatory full drive code protection.
  • Removal sign-off compliance rate: Track the proportion of off-site equipment removals backed by formal manager sign-offs.
  • Asset register location accuracy: Measure the percentage of off-site devices that match assigned locations during physical spot checks.
  • Off-site loss incident rate: Track the total number of lost, stolen, or misplaced off-site hardware items reported each year.
  • Off-site loss reporting speed: Monitor the average time taken by staff to report missing off-site equipment after noticing the loss.
  • Remote wipe success rate: Measure the percentage of missing off-site devices successfully locked or erased from a distance.
  • Overdue asset return rate: Track the proportion of temporary off-site devices kept past agreed return dates.
  • Returned hardware check pass rate: Measure the percentage of returned off-site items that undergo full physical inspection before reuse.
  • Policy sign-off compliance rate: Track the percentage of remote and traveling workers who sign off on off-site safety rules.
  • Off-site audit finding count: Monitor the number of security gaps flagged during internal reviews of off-site asset controls.
  • Off-site insurance coverage rate: Track the proportion of active off-site devices fully covered under valid insurance policies.
  • Unapproved connection block rate: Monitor the number of untrusted network or port connections blocked on off-site devices.
  • Off-site asset awareness rate: Track the percentage of remote staff who finish annual training on safe off-site gear handling.
  • Physical label check pass rate: Measure the proportion of off-site devices correctly carrying physical tracking tags during checks.

ISO 27001 Annex A 7.9 depends on several other ISO 27001 controls:

  • ISO 27001 Clause 8.1 (Operational Planning): Directs the management of asset security.
  • ISO 27001 Annex A 5.9 (Inventory of Information): Provides the foundation for tracking.
  • ISO 27001 Annex A 7.10 (Storage Media): Governs the data on off-site devices.
ISO 27001 Security Of Assets Off-Premises Explained – Annex A 7.9 - ISO 27001.com
ISO 27001 Security Of Assets Off-Premises Explained – Annex A 7.9
ISO 27001 Annex A 7.9