What is ISO 27001 Annex A 7.9 – Security of Assets Off-Premises?
ISO 27001 Annex A 7.9 focuses on protecting organizational information and associated assets when they are taken, used, stored, or operated outside the organization’s physical premises.
Organizations increasingly operate beyond traditional offices.
Employees may use company assets from:
- Home
- Customer locations
- Hotels
- Airports
- Coworking spaces
- Business trips
- Conferences
- Partner locations
- Supplier locations
- Other remote locations
Assets may include:
- Laptops
- Mobile phones
- Tablets
- Removable media
- Paper documents
- Backup media
- Portable storage devices
- Company equipment
- Network equipment
- Physical records
- Other information-processing assets
The organization should establish appropriate controls to protect these assets from:
- Theft
- Loss
- Unauthorized access
- Damage
- Unauthorized disclosure
- Tampering
- Misuse
Simple Explanation
When company assets leave the office, they should continue to receive appropriate security protection.
Why is A.7.9 Important?
An asset may be well protected inside the office but become significantly more vulnerable when taken outside.
For example:
An employee leaves a company laptop in a hotel room.
The laptop may contain:
- Customer information
- Business documents
- Emails
- Source code
- Cached credentials
- Security information
If the device is stolen, the organization could face:
- Data exposure
- Unauthorized account access
- Loss of intellectual property
- Regulatory consequences
- Customer impact
- Business disruption
The same principle applies to physical documents, mobile devices, backup media and other assets.
Simple Principle
Leaving the office should not mean leaving security controls behind.
What Does ISO 27001 A.7.9 Require?
Organizations should establish appropriate security measures for assets used outside organizational premises.
The controls should consider:
- Type of asset
- Information sensitivity
- Location
- Travel environment
- Threat level
- Business purpose
- Physical security
- Device security
- Encryption
- Access control
- Remote working
- Loss/theft reporting
- Regulatory requirements
- Customer requirements
The control should be risk-based.
A low-value asset may require basic protection, while a laptop containing highly sensitive information may require stronger controls.
What Does “Off-Premises” Mean?
Off-premises does not only mean working from home.
It can include any location outside the organization’s controlled premises.
| Location | Example Risk |
|---|---|
| Home | Family/visitor access |
| Hotel | Theft |
| Airport | Loss or unattended device |
| Café | Shoulder surfing |
| Coworking space | Unauthorized viewing |
| Customer site | Unauthorized physical access |
| Conference | Device theft |
| Public transport | Lost laptop/phone |
| Supplier location | Third-party access |
| International travel | Border inspection, theft, local risks |
What Assets Should Be Considered?
Organizations should identify assets that may leave their premises.
Electronic Assets
- Laptops
- Smartphones
- Tablets
- USB drives
- External hard drives
- Portable backup devices
- Portable network equipment
- Security tokens
Physical Information
- Printed customer information
- Contracts
- Financial documents
- Employee records
- Audit documents
- Security reports
- Product information
- Confidential meeting notes
Other Assets
- Prototype equipment
- Company-owned devices
- Portable storage
- Specialized equipment
- Physical records
Activities Required to Implement A.7.9
1. Identify Off-Premises Assets
Start by determining which assets may leave the organization’s premises.
The asset inventory should help identify:
- Asset owner
- Asset type
- Information stored
- Classification
- Assigned user
- Location
- Security requirements
2. Assess the Risk
Consider what could happen if the asset is:
- Lost
- Stolen
- Viewed
- Modified
- Damaged
- Destroyed
- Accessed by an unauthorized person
For example:
Company Laptop
Potential risks:
- Theft
- Unauthorized access
- Malware
- Shoulder surfing
- Loss of stored data
Possible controls:
- Full-disk encryption
- Strong authentication
- MFA
- Screen lock
- EDR
- Remote management
- Remote wipe where appropriate
- Incident reporting
3. Define Rules for Taking Assets Off-Premises
The organization should establish practical rules.
For example:
Employees may be required to:
- Take only necessary assets
- Keep devices under personal control
- Avoid leaving devices unattended
- Use approved bags/cases
- Avoid leaving devices in vehicles
- Protect screens in public places
- Report loss immediately
- Follow travel-security requirements
4. Protect Laptops
Laptops are among the most common off-premises assets.
Appropriate controls may include:
- Full-disk encryption
- Strong passwords
- MFA
- Automatic screen locking
- Endpoint detection and response
- Device management
- Secure configuration
- Patch management
- Remote lock/wipe where appropriate
- Asset identification
Physical security is important, but logical security is equally important.
A stolen encrypted laptop presents a different risk from a stolen unencrypted laptop.
5. Protect Mobile Devices
Company smartphones and tablets can contain significant amounts of information.
Controls may include:
- Device encryption
- PIN/password
- Biometrics
- Automatic lock
- Mobile device management
- Application controls
- Remote wipe
- Security updates
- Approved applications
6. Protect Information in Public Places
Employees should be aware of risks such as:
Shoulder Surfing
Someone may view a laptop screen in:
- Airport
- Train
- Café
- Hotel lobby
- Conference
- Coworking space
Possible controls:
- Position screen away from public view
- Use privacy filters where appropriate
- Avoid viewing highly sensitive information in public
- Use secure locations for sensitive discussions
7. Protect Assets in Vehicles
Vehicles can be a major physical-security risk.
Employees should avoid leaving company equipment:
- Visible inside a vehicle
- Unattended for long periods
- In unsecured locations
Where possible:
Do not leave sensitive equipment in a vehicle.
If temporary storage is unavoidable, appropriate precautions should be applied based on the risk.
8. Protect Paper Documents
Off-premises security applies to physical documents too.
Employees taking documents outside the office should consider:
- Whether the document is actually needed
- Information classification
- Secure transportation
- Secure storage
- Preventing unauthorized viewing
- Secure disposal
- Return of documents
For highly sensitive information, electronic access may be preferable to carrying physical copies.
9. Secure Remote Working
A.7.9 works closely with A.6.7 Remote Working.
A.6.7 primarily addresses the security requirements for remote working.
A.7.9 focuses on the security of assets taken outside the organization’s premises.
For example:
An employee works from home using a company laptop.
A.6.7 addresses secure remote working practices.
A.7.9 addresses the protection of the company laptop and information while it is outside the office.
10. International Travel
Organizations should consider additional risks associated with international travel.
Depending on the organization’s risk and destination, considerations may include:
- Loss or theft
- Public Wi-Fi
- Device inspection
- Local legal requirements
- Physical surveillance
- Sensitive information exposure
- High-risk locations
- Restricted or sensitive information
Organizations with significant international travel may create a dedicated travel-security procedure.
11. Report Loss or Theft Immediately
Employees should know exactly what to do if an asset is:
- Lost
- Stolen
- Damaged
- Accidentally exposed
A simple process could be:
Loss/Theft → Immediate Report → Security Assessment → Account/Device Protection → Incident Response → Investigation → Recovery/Replacement → Lessons Learned
Employees should not wait until they return to the office.
Startup Example – SaaS Company
Consider a 50-person SaaS startup.
Employees regularly work:
- From home
- From coworking spaces
- At customer offices
- While travelling
Company assets include:
- Laptops
- Mobile phones
- Security tokens
- Printed documents
- USB devices
Controls
The startup implements:
- Full-disk encryption
- MFA
- Automatic screen locking
- EDR
- Central device management
- Security awareness training
- Asset inventory
- Remote wipe where appropriate
- Immediate lost-device reporting
- Travel-security guidance
Employees are instructed:
Do not leave company laptops unattended in public places or vehicles.
Simple Workflow
Assign Asset → Secure Device → Take Off-Premises → Protect → Monitor → Report Loss → Respond → Recover
Off-Premises Asset Register
A simple register can help track assets.
| Asset | Assigned To | Asset Type | Classification | Allowed Off-Premises? | Key Controls |
|---|---|---|---|---|---|
| LAP-001 | Employee | Laptop | Confidential | Yes | Encryption, EDR |
| MOB-012 | Employee | Mobile | Confidential | Yes | MDM, PIN |
| USB-003 | Security Team | Storage | Restricted | Controlled | Encryption |
| DOC-014 | Finance | Document | Confidential | Restricted | Secure handling |
| SEC-005 | IT | Security Token | Restricted | Yes | User-controlled |
The exact register should be adapted to the organization’s asset-management process.
Off-Premises Asset Risk Assessment
| Asset | Risk | Impact | Control |
|---|---|---|---|
| Laptop | Theft | High | Encryption + EDR |
| Laptop | Shoulder surfing | Medium | Screen positioning/privacy filter |
| Mobile | Loss | High | Encryption + MDM |
| USB | Loss | High | Encryption |
| Paper record | Unauthorized viewing | High | Secure transportation/storage |
| Laptop | Public Wi-Fi attack | Medium | Secure network practices + endpoint controls |
Remote Working vs Off-Premises Assets
These concepts should not be treated as exactly the same.
| Topic | A.6.7 Remote Working | A.7.9 Off-Premises Assets |
|---|---|---|
| Main focus | Security of remote work | Security of assets outside premises |
| Home working | ✓ | ✓ |
| Travel | ✓ | ✓ |
| Laptop security | ✓ | ✓ |
| Physical documents | Possible | ✓ |
| Public locations | ✓ | ✓ |
| Remote work environment | ✓ | Supporting consideration |
Together, they create a more complete approach to remote and mobile work.
Audit Evidence for A.7.9
An auditor may ask for evidence that off-premises assets are actually protected.
Policies and Procedures
- Asset Management Policy
- Security of Assets Off-Premises Procedure
- Remote Working Policy
- Acceptable Use Policy
- Mobile Device Policy
- Travel Security Policy
- Lost or Stolen Asset Procedure
Asset Evidence
- Asset register
- Laptop inventory
- Mobile device inventory
- Asset assignment records
- Asset return records
- Encryption status
- Device management records
Technical Evidence
Where applicable:
- Endpoint management
- MDM
- EDR
- Disk encryption
- Screen-lock configuration
- Remote wipe capability
- MFA
- Device compliance reports
Operational Evidence
- Security awareness training
- Travel-security communications
- Lost-device reports
- Incident records
- Device recovery records
- Security investigations
Audit Checklist
An ISO 27001 auditor may ask:
Asset Identification
- Have off-premises assets been identified?
- Are laptops and mobile devices included in the asset inventory?
- Are physical documents considered where relevant?
Authorization
- Who is allowed to take assets off-premises?
- Are there restrictions on certain assets?
Protection
- Are laptops encrypted?
- Are mobile devices protected?
- Are screens protected in public environments?
- Are physical documents protected?
Remote Working
- Are remote-working requirements documented?
- Are employees trained?
Travel
- Are travel-security risks considered?
- Are additional controls applied for higher-risk travel?
Loss and Theft
- Do employees know how to report lost or stolen assets?
- Is there an established response process?
- Can compromised devices/accounts be secured quickly?
Monitoring
- Can the organization determine which employee has a particular asset?
- Are asset records maintained?
- Are security incidents involving off-premises assets reviewed?
Common Mistakes in Implementing A.7.9
1. Treating Encryption as the Entire Solution
Encryption is extremely useful, but it does not physically prevent:
- Theft
- Damage
- Unauthorized use
- Shoulder surfing
Better approach:
Use layered physical and technical controls.
2. No Lost Device Process
Some organizations say:
“Employees must report lost devices.”
But employees do not know:
- Who to contact
- How quickly to report
- What information to provide
- What happens next
Better approach:
Define a simple lost-device reporting procedure.
3. Allowing Devices to Be Left in Vehicles
A laptop may be encrypted, but theft still creates:
- Business disruption
- Replacement costs
- Potential security concerns
- Incident-response workload
Better approach:
Tell employees not to leave company equipment unattended in vehicles wherever possible.
4. Ignoring Mobile Phones
Organizations sometimes protect laptops but forget smartphones.
Modern phones may contain:
- Slack/Teams
- Customer applications
- Authentication applications
- MFA tokens
- Business documents
Better approach:
Include mobile devices in the off-premises security program.
5. Ignoring Paper
Digital transformation does not eliminate physical information.
Printed:
- Contracts
- Customer records
- Reports
- Employee information
can still create significant risks.
6. No Asset Ownership
If a laptop disappears, the organization should know:
- Who was assigned the laptop
- Asset ID
- Device details
- Information classification
- Security controls
Better approach:
Maintain an accurate asset inventory.
7. Same Rules for Every Location
Working from home is different from working in an airport.
A customer site may be different from a hotel.
Better approach:
Use risk-based guidance rather than one unrealistic rule for every environment.
Practical Startup Implementation Model
A startup can implement A.7.9 using the following model:
1. Identify
Identify assets that can leave organizational premises.
2. Classify
Understand the sensitivity and criticality of the assets.
3. Authorize
Define who may take assets off-premises.
4. Protect
Apply appropriate physical and technical controls.
5. Educate
Train employees about travel, remote work and physical security.
6. Monitor
Maintain asset ownership and device-security visibility.
7. Report
Make loss or theft reporting simple and immediate.
8. Respond
Protect accounts, devices and information following an incident.
9. Review
Review recurring incidents and improve controls.
Simple Model
Identify → Classify → Authorize → Protect → Educate → Monitor → Report → Respond → Review
Policy vs. Process vs. Evidence
| Element | Example |
|---|---|
| Policy | Organizational assets must be appropriately protected when used outside organizational premises. |
| Process | Employees protect, monitor and report loss or theft of off-premises assets. |
| Technical Controls | Encryption, EDR, MDM, MFA, screen lock |
| Evidence | Asset register, device compliance records, training, incident reports and recovery records |
Remember:
The objective is not simply to issue secure laptops. The organization should also control how those assets are used and protected outside the office.
Relationship With Other ISO 27001 Controls
A.7.9 connects with many other controls.
| Control | Relationship |
|---|---|
| A.5.9 Inventory of Assets | Identifies assets and ownership |
| A.5.10 Acceptable Use | Defines acceptable use |
| A.5.11 Return of Assets | Addresses return of assets |
| A.5.12 Classification | Determines protection requirements |
| A.5.15 Access Control | Protects access to information |
| A.5.18 Access Rights | Manages user access |
| A.5.33 Protection of Records | Protects physical records |
| A.5.34 Privacy and PII | Protects personal information |
| A.6.3 Awareness and Training | Educates employees |
| A.6.5 Termination/Change | Ensures assets are recovered |
| A.6.7 Remote Working | Addresses secure remote work |
| A.6.8 Event Reporting | Supports reporting of loss/theft |
| A.7.6 Working in Secure Areas | Protects work inside secure areas |
| A.7.7 Clear Desk/Clear Screen | Prevents information exposure |
| A.7.8 Equipment Siting and Protection | Protects equipment at organizational premises |
| A.8.1 User Endpoint Devices | Provides technical protection for endpoints |
| A.8.7 Protection Against Malware | Protects devices against malicious software |
| A.8.15 Logging | Supports security monitoring where applicable |
A.7.8 vs A.7.9 – What is the Difference?
A.7.8 – Equipment Siting and Protection
Focuses primarily on:
Where equipment is located and how it is protected physically.
Example:
A network switch is installed in a locked network room.
A.7.9 – Security of Assets Off-Premises
Focuses on:
How assets are protected when they are outside organizational premises.
Example:
An employee takes a company laptop to a customer meeting.
Simple Difference
A.7.8 = Protect equipment where it is located.
A.7.9 = Protect assets when they are outside the premises.
Useful Resources and Draft Documents
Organizations implementing A.7.9 may create:
- Security of Assets Off-Premises Policy
[Insert Draft Document Link] - Asset Management Policy
[Insert Draft Document Link] - Asset Register
[Insert Draft Document Link] - Off-Premises Asset Register
[Insert Draft Document Link] - Remote Working Security Policy
[Insert Draft Document Link] - Mobile Device Security Policy
[Insert Draft Document Link] - Travel Security Procedure
[Insert Draft Document Link] - Lost or Stolen Asset Procedure
[Insert Draft Document Link] - Laptop Security Checklist
[Insert Draft Document Link] - Mobile Device Security Checklist
[Insert Draft Document Link] - Asset Handover and Return Form
[Insert Draft Document Link] - Security Incident Report Form
[Insert Draft Document Link]
Questions an Auditor May Ask
“Which assets are allowed to leave your premises?”
Show the asset policy and relevant asset records.
“How do you protect laptops outside the office?”
Explain:
- Encryption
- EDR
- MFA
- Screen locking
- Device management
- Physical security requirements
“What happens if an employee loses a laptop?”
Explain the reporting and incident-response process.
“How quickly must a lost device be reported?”
Show the documented requirement and demonstrate employee awareness.
“How do you know who has each laptop?”
Show the asset register and assignment records.
“How do you protect information when employees travel?”
Explain travel-security requirements and relevant awareness training.
“What about remote workers?”
Explain the relationship between A.7.9 and the organization’s remote-working controls under A.6.7.
Startup-Focused Quick Summary
A startup can implement A.7.9 with a practical set of controls.
Protect laptops
- Full-disk encryption
- MFA
- EDR
- Screen lock
- Device management
Protect mobile devices
- PIN/biometric authentication
- Encryption
- MDM where appropriate
- Remote wipe where appropriate
Protect physical assets
- Do not leave equipment unattended
- Avoid leaving devices in vehicles
- Secure documents during travel
- Protect equipment in public locations
Protect information
- Avoid displaying sensitive information publicly
- Use privacy screens where appropriate
- Avoid discussing confidential information where others can overhear
Prepare for incidents
- Make lost-device reporting simple
- Respond immediately
- Revoke or protect access where necessary
- Record and learn from incidents
Startup-Focused Final Takeaway
Modern organizations are increasingly distributed.
Employees work from:
- Home
- Customer locations
- Coworking spaces
- Hotels
- Airports
- Conferences
- Different countries
As a result, information-security controls cannot stop at the office entrance.
ISO 27001 Annex A 7.9 ensures that organizational assets continue to receive appropriate protection when they leave controlled premises.
The practical objective is:
Know which assets leave the office, who has them, what risks they face, and how those risks are controlled.
For a startup, the implementation sequence is:
Identify → Classify → Authorize → Protect → Educate → Monitor → Report → Respond → Review
The goal is not to prevent employees from working flexibly.
The goal is to ensure:
Work from anywhere — without taking security risks everywhere.
