ISO 27001 Annex A 7.9 protects equipment and data taken away from company premises. Managers must approve all removals and track device locations to keep off-site assets safe.
Table of contents
Key Takeaways
- Require formal management approval: Ensure staff get explicit manager sign-off before taking any company equipment or hardware off site.
- Track asset locations continuously: Keep an updated off-site equipment log to record who holds each device and its current physical location.
- Enforce full drive encryption: Require strong code protection on all portable hardware to guard data if devices are lost or stolen.
- Apply physical security rules: Teach staff never to leave off-site hardware unattended in cars, public spaces, or unsecured hotel rooms.
- Log asset removals and returns: Use a central task system to track when equipment leaves the building and confirm its safe return.
- Define clear usage limits: Set clear policy rules stating that off-site assets are for approved business tasks only.
- Report missing items fast: Train workers to report lost or stolen off-site gear right away so teams can wipe data remotely.
- Inspect returned hardware: Check returned equipment for physical damage or safety issues before issuing it to other workers.
How to Implement ISO 27001 Annex A 7.9
- Track device locations: Update your central asset register to record the current physical location of all off-site equipment.
- Set up approval steps: Use a central task system to require manager approval before staff take any gear off site.
- Publish physical security rules: Write simple safety guides on your internal intranet to teach staff how to protect off-site devices.
- Get worker sign-offs: Ensure all new employees sign physical security policy rules during their initial onboarding.
- Run spot checks: Perform regular routine checks on equipment listed as off-site to verify locations and user details.
- Enforce full device encryption: Mandate full code protection on all portable equipment before allowing off-site removal.
- Define transit safety steps: Require workers to use locked bags and avoid leaving equipment unattended in vehicles or public spaces.
- Set fast incident steps: Establish clear loss reporting steps so teams can lock or wipe missing off-site devices quickly.
- Inspect returned equipment: Check hardware for physical harm or tampering whenever staff return off-site gear to the office.
How to Audit ISO 27001 Annex A 7.9
- Review off-site asset policies: Inspect written rules to check that clear steps exist for taking equipment away from company premises.
- Verify manager removal sign-offs: Sample log records to confirm staff get manager approval before taking gear off site.
- Audit the central asset log: Sample tracking entries to confirm location details clearly show who holds each off-site item.
- Check device code protection: Inspect sample off-site hardware to ensure full drive encryption guards data if gear is lost.
- Inspect physical security guides: Check that staff receive clear guidance on protecting gear in vehicles, hotels, and public spaces.
- Review worker policy sign-offs: Sample onboarding files to verify staff sign off on off-site safety rules during induction.
- Check physical spot check logs: Inspect records of routine asset audits to confirm teams check off-site items regularly.
- Audit loss and theft reports: Review report tickets for missing gear to confirm fast reporting and remote lock actions.
- Check hardware return steps: Confirm teams inspect and log returned gear for physical damage or tampering before reuse.
- Verify remote wipe tools: Confirm central system controls can lock or erase missing off-site hardware from a distance.
- Review off-site insurance cover: Check active insurance files to ensure cover extends to company hardware used off site.
- Check contractor safety logs: Verify external workers sign safety agreements before taking company gear off site.
- Verify clear desk and screen rules: Check that staff lock screens and cover screens when using off-site devices in public.
- Check safe transit controls: Verify staff use padded, locked bags or secure couriers when moving hardware between sites.
Audit Evidence Checklist
- Central asset register: Maintain an up-to-date inventory log showing current location details and status for all portable equipment.
- Removal sign-off logs: Keep task management approval records showing formal manager sign-off for gear issued to remote staff.
- Security review minutes: Supply meeting notes from regular security reviews that discuss off-site risks and asset loss events.
- Staff sign-off records: Provide signed policy receipt forms proving employees read and accepted off-site security rules.
- Off-site insurance policies: Keep active insurance files showing complete cover for business equipment used away from the office.
- Asset spot check records: Produce internal review logs that show regular routine checks on hardware listed as off site.
- Incident report tickets: Supply formal incident logs for missing or damaged off-site gear showing fast remote lock actions.
- Hardware return logs: Maintain inspection receipts confirming technical teams check returned gear for physical damage or tampering.
What to Teach Employees
- Get approval before removal: Teach staff to request formal manager sign-off before taking any company equipment or devices off site.
- Never leave gear unattended: Instruct workers never to leave off-site equipment in plain sight inside parked cars, hotels, or public cafes.
- Lock screens when stepping away: Remind staff to lock device screens every time they walk away from equipment in public or home spaces.
- Guard against shoulder surfing: Teach employees to use screen privacy filters or face away from public view when viewing sensitive files.
- Use secure network connections: Warn staff against using open public networks and require protected connections for all remote work.
- Report lost equipment right away: Ensure workers know to report missing hardware fast so support teams can lock or wipe data remotely.
- Store equipment safely at home: Instruct remote workers to lock gear away when not in use to keep devices safe from guests or family.
- Use safe transport bags: Require employees to carry portable equipment in padded, neutral bags to prevent theft and physical damage during transit.
- Keep business items separate: Teach staff never to use unapproved personal accessories on work hardware or move work files to personal drives.
- Hand back unused gear: Remind workers to return off-site equipment to the main office as soon as travel tasks or remote projects finish.
- Check hardware for damage: Teach staff to inspect off-site equipment regularly for signs of physical wear, cable decay, or tampering.
- Follow clear desk rules off site: Remind staff to clear away paper notes, printouts, and portable items at the end of every work day.
- Verify off-site asset labels: Teach workers to check that asset tracking tags stay attached to all company equipment used away from site premises.
- Follow physical access rules: Instruct employees to prevent unapproved visitors from accessing company hardware in remote or off-site work areas.
Common Implementation Challenges
- Bypassing removal sign-offs: Staff take equipment off site without asking managers first. Require system approval tasks before devices leave the office.
- Outdated location registers: Asset logs fail to show who holds gear as hardware moves between remote workers. Run regular asset spot checks to keep location lists accurate.
- Leaving gear in vehicles: Workers leave devices and tech bags in plain sight inside parked cars. Mandate strict policies against leaving equipment unattended in vehicles.
- Unencrypted off-site devices: Portable gear taken off site lacks full drive protection, exposing data if stolen. Enforce mandatory code protection on all off-site equipment.
- Delayed theft reporting: Employees wait days to report lost off-site gear out of fear or embarrassment. Build a blameless culture so staff report missing items right away.
- Unsecured home work spaces: Remote staff leave active screens unlocked around family members or house guests. Train workers to lock screens and store gear securely at home.
- Connecting to open public networks: Traveling staff connect to unverified public connections in cafes or airports. Require protected, encrypted connections for all off-site web access.
- Ignoring physical damage checks: Returned off-site hardware goes back into stock without checks for physical harm or tampering. Require support teams to inspect all returned gear.
- Overlooking contractor gear: External workers carry company hardware off site without signing clear asset agreements. Ensure third parties sign off on safety rules before taking equipment.
- Unsafe transit methods: Workers move hardware in flimsy, unpadded bags that cause physical damage. Supply neutral, padded carrying cases for all traveling staff.
- Lack of remote wipe tools: Support teams cannot lock or clear missing off-site equipment from a distance. Set up central management controls to wipe lost hardware remotely.
- Unclear off-site insurance cover: Companies assume standard insurance covers equipment used abroad or at home. Review policies to ensure complete cover for off-site hardware.
- Overlooking clear desk rules off site: Remote staff leave confidential paper notes on desks after finishing work. Enforce clean desk habits for all off-site and home work setups.
- Long-term off-site asset hoarding: Workers keep temporary off-site gear indefinitely after travel projects end. Track removal return dates to ensure prompt return of equipment.
- Unlabeled physical assets: Off-site gear lacks physical tracking tags, making it hard to identify lost items. Attach tamper-evident tracking labels to all portable equipment.
- Unapproved personal device usage: Staff copy sensitive work files onto personal, unmanaged laptops or drives when working away. Enforce strict rules against using personal hardware for business data.
How to Measure Effectiveness (KPIs)
- Off-site device encryption rate: Measure the percentage of active off-site hardware carrying mandatory full drive code protection.
- Removal sign-off compliance rate: Track the proportion of off-site equipment removals backed by formal manager sign-offs.
- Asset register location accuracy: Measure the percentage of off-site devices that match assigned locations during physical spot checks.
- Off-site loss incident rate: Track the total number of lost, stolen, or misplaced off-site hardware items reported each year.
- Off-site loss reporting speed: Monitor the average time taken by staff to report missing off-site equipment after noticing the loss.
- Remote wipe success rate: Measure the percentage of missing off-site devices successfully locked or erased from a distance.
- Overdue asset return rate: Track the proportion of temporary off-site devices kept past agreed return dates.
- Returned hardware check pass rate: Measure the percentage of returned off-site items that undergo full physical inspection before reuse.
- Policy sign-off compliance rate: Track the percentage of remote and traveling workers who sign off on off-site safety rules.
- Off-site audit finding count: Monitor the number of security gaps flagged during internal reviews of off-site asset controls.
- Off-site insurance coverage rate: Track the proportion of active off-site devices fully covered under valid insurance policies.
- Unapproved connection block rate: Monitor the number of untrusted network or port connections blocked on off-site devices.
- Off-site asset awareness rate: Track the percentage of remote staff who finish annual training on safe off-site gear handling.
- Physical label check pass rate: Measure the proportion of off-site devices correctly carrying physical tracking tags during checks.
Related ISO 27001 Controls
ISO 27001 Annex A 7.9 depends on several other ISO 27001 controls:
- ISO 27001 Clause 8.1 (Operational Planning): Directs the management of asset security.
- ISO 27001 Annex A 5.9 (Inventory of Information): Provides the foundation for tracking.
- ISO 27001 Annex A 7.10 (Storage Media): Governs the data on off-site devices.


