View Categories

A7.9 Security of assets off-premises

4 min read

ISO 27001 A7.9 Security of assets off-premises requires organizations to define and enforce rules for using and storing assets outside company facilities. As remote work, travel, and mobile operations become more common, the risk of data exposure grows significantly. Laptops, mobile devices, USB drives, and paper documents are especially vulnerable in public or uncontrolled environments.

The security of assets off-premises ensures that information, devices, and equipment taken outside the organization’s physical boundaries remain protected against loss, theft, or unauthorized access.

This control helps maintain the confidentiality, integrity, and availability of organizational information—no matter where it is accessed or stored.

Implementation Guide #

Step 1: Identify Off-Premises Scenarios

  • List all situations where assets may be taken off-site (e.g., remote work, client visits, work from home).
  • Include digital assets (laptops, USBs, phones) and physical assets (documents, hard drives).

Step 2: Define Acceptable Use and Handling Policies

  • Develop an Off-Premises Asset Handling Policy.
  • Specify how to transport, use, and store assets securely when outside the office.
  • Set clear rules on encryption, locking devices, and avoiding public Wi-Fi.

Step 3: Enforce Technical Security Controls

  • Require full-disk encryption on laptops and mobile devices.
  • Implement remote wipe capabilities and tracking tools for portable devices.
  • Use VPNs for secure remote access to internal systems.
  • Disable USB ports or use secure USB devices where applicable.

Step 4: Train Employees

  • Explain risks related to using company assets outside the office.
  • Conduct training on securely handling devices and data in public places.
  • Emphasize the importance of not leaving devices unattended or visible in cars, cafes, or hotels.

Step 5: Monitor and Respond to Incidents

  • Have a clear reporting process for lost or stolen assets.
  • Review and update off-premises security controls based on reported incidents or changes in remote work practices.

Templates #

  • Off-Premises Asset Handling Policy
  • Remote Work Security Guidelines
  • Asset Tracking Log
  • Lost or Stolen Asset Reporting Form
  • Mobile Device Management (MDM) Configuration Checklist

Example #

An employee takes a company-issued laptop to a client meeting and leaves it unattended in the car. The laptop is stolen, and it contains sensitive project data.

However, due to full-disk encryption, remote wipe capability, and enforced password policies, the data remains protected. The employee reports the theft immediately, and the IT team initiates a remote wipe and files an incident report, avoiding a potential data breach.

How to Comply #

To comply with ISO 27001 A.7.9, organizations should:

  • Establish and enforce an Off-Premises Asset Handling Policy.
  • Implement technical controls such as encryption, VPNs, and remote wipe features.
  • Provide staff with training on secure off-premises behavior.
  • Maintain a record of portable devices and assign accountability.
  • Review security risks for off-premises activities regularly.

How to Pass an Audit #

Key Documents to Prepare:

  • Off-Premises Asset Handling Policy
  • Device Inventory and Assignment Records
  • Remote Work Security Procedures
  • Training Records and Awareness Sessions
  • Incident Reports (if applicable)

What the Auditor Will Check:

  • Are there defined procedures for using company assets off-site?
  • Are laptops and mobile devices encrypted and secured?
  • Can lost or stolen devices be remotely disabled or wiped?
  • Are employees trained on how to protect information when working remotely or in public areas?

Top 3 Mistakes People Make #

  • Allowing employees to take sensitive data off-premises without encryption or controls.
  • Not maintaining an inventory or assignment log for portable assets.
  • Failing to provide regular awareness training for off-premises security risks.

ISO 27001 Security of Assets Off-Premises FAQ #

Q1: Do personal devices fall under this control if used for work?
Yes, any device used to access or process organizational data must follow off-premises security rules, even if personally owned (BYOD).

Q2: Is VPN usage mandatory for remote access?
VPNs are strongly recommended to protect data in transit when connecting to internal systems from public or unsecured networks.

Q3: What should be done if a device is lost or stolen?
Employees must report it immediately, and the organization should initiate a response plan, including device tracking, remote wipe, and risk assessment.

ISO 27001 Controls and Attribute Values #

Control

Attribute Value

A.7.9 Security of Assets Off-Premises

Preventive, Risk-Based, Operational

Purpose

Ensure information remains protected when accessed or stored outside the organization

Applicability

Remote Workers, Traveling Staff, BYOD Environments

ISO 27001 Domains

Asset Management, Operations Security, Access Control

 

A clear and enforced off-premises security policy helps organizations adapt to remote and mobile work environments without sacrificing data protection. Without these controls, assets outside the office become vulnerable to theft, loss, and compromise—leading to costly breaches or compliance failures.

Leave a Reply

Your email address will not be published. Required fields are marked *

Log in

You dont have an account yet? Register Now