ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 4. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 7.9 Security of assets off-premises

ISO 27001 Annex A 7.9 Security of assets off-premises

What is ISO 27001 Annex A 7.9 – Security of Assets Off-Premises?

ISO 27001 Annex A 7.9 focuses on protecting organizational information and associated assets when they are taken, used, stored, or operated outside the organization’s physical premises.

Organizations increasingly operate beyond traditional offices.

Employees may use company assets from:

  • Home
  • Customer locations
  • Hotels
  • Airports
  • Coworking spaces
  • Business trips
  • Conferences
  • Partner locations
  • Supplier locations
  • Other remote locations

Assets may include:

  • Laptops
  • Mobile phones
  • Tablets
  • Removable media
  • Paper documents
  • Backup media
  • Portable storage devices
  • Company equipment
  • Network equipment
  • Physical records
  • Other information-processing assets

The organization should establish appropriate controls to protect these assets from:

  • Theft
  • Loss
  • Unauthorized access
  • Damage
  • Unauthorized disclosure
  • Tampering
  • Misuse

Simple Explanation

When company assets leave the office, they should continue to receive appropriate security protection.


Why is A.7.9 Important?

An asset may be well protected inside the office but become significantly more vulnerable when taken outside.

For example:

An employee leaves a company laptop in a hotel room.

The laptop may contain:

  • Customer information
  • Business documents
  • Emails
  • Source code
  • Cached credentials
  • Security information

If the device is stolen, the organization could face:

  • Data exposure
  • Unauthorized account access
  • Loss of intellectual property
  • Regulatory consequences
  • Customer impact
  • Business disruption

The same principle applies to physical documents, mobile devices, backup media and other assets.

Simple Principle

Leaving the office should not mean leaving security controls behind.


What Does ISO 27001 A.7.9 Require?

Organizations should establish appropriate security measures for assets used outside organizational premises.

The controls should consider:

  • Type of asset
  • Information sensitivity
  • Location
  • Travel environment
  • Threat level
  • Business purpose
  • Physical security
  • Device security
  • Encryption
  • Access control
  • Remote working
  • Loss/theft reporting
  • Regulatory requirements
  • Customer requirements

The control should be risk-based.

A low-value asset may require basic protection, while a laptop containing highly sensitive information may require stronger controls.


What Does “Off-Premises” Mean?

Off-premises does not only mean working from home.

It can include any location outside the organization’s controlled premises.

LocationExample Risk
HomeFamily/visitor access
HotelTheft
AirportLoss or unattended device
CaféShoulder surfing
Coworking spaceUnauthorized viewing
Customer siteUnauthorized physical access
ConferenceDevice theft
Public transportLost laptop/phone
Supplier locationThird-party access
International travelBorder inspection, theft, local risks

What Assets Should Be Considered?

Organizations should identify assets that may leave their premises.

Electronic Assets

  • Laptops
  • Smartphones
  • Tablets
  • USB drives
  • External hard drives
  • Portable backup devices
  • Portable network equipment
  • Security tokens

Physical Information

  • Printed customer information
  • Contracts
  • Financial documents
  • Employee records
  • Audit documents
  • Security reports
  • Product information
  • Confidential meeting notes

Other Assets

  • Prototype equipment
  • Company-owned devices
  • Portable storage
  • Specialized equipment
  • Physical records

Activities Required to Implement A.7.9

1. Identify Off-Premises Assets

Start by determining which assets may leave the organization’s premises.

The asset inventory should help identify:

  • Asset owner
  • Asset type
  • Information stored
  • Classification
  • Assigned user
  • Location
  • Security requirements

2. Assess the Risk

Consider what could happen if the asset is:

  • Lost
  • Stolen
  • Viewed
  • Modified
  • Damaged
  • Destroyed
  • Accessed by an unauthorized person

For example:

Company Laptop

Potential risks:

  • Theft
  • Unauthorized access
  • Malware
  • Shoulder surfing
  • Loss of stored data

Possible controls:

  • Full-disk encryption
  • Strong authentication
  • MFA
  • Screen lock
  • EDR
  • Remote management
  • Remote wipe where appropriate
  • Incident reporting

3. Define Rules for Taking Assets Off-Premises

The organization should establish practical rules.

For example:

Employees may be required to:

  • Take only necessary assets
  • Keep devices under personal control
  • Avoid leaving devices unattended
  • Use approved bags/cases
  • Avoid leaving devices in vehicles
  • Protect screens in public places
  • Report loss immediately
  • Follow travel-security requirements

4. Protect Laptops

Laptops are among the most common off-premises assets.

Appropriate controls may include:

  • Full-disk encryption
  • Strong passwords
  • MFA
  • Automatic screen locking
  • Endpoint detection and response
  • Device management
  • Secure configuration
  • Patch management
  • Remote lock/wipe where appropriate
  • Asset identification

Physical security is important, but logical security is equally important.

A stolen encrypted laptop presents a different risk from a stolen unencrypted laptop.


5. Protect Mobile Devices

Company smartphones and tablets can contain significant amounts of information.

Controls may include:

  • Device encryption
  • PIN/password
  • Biometrics
  • Automatic lock
  • Mobile device management
  • Application controls
  • Remote wipe
  • Security updates
  • Approved applications

6. Protect Information in Public Places

Employees should be aware of risks such as:

Shoulder Surfing

Someone may view a laptop screen in:

  • Airport
  • Train
  • Café
  • Hotel lobby
  • Conference
  • Coworking space

Possible controls:

  • Position screen away from public view
  • Use privacy filters where appropriate
  • Avoid viewing highly sensitive information in public
  • Use secure locations for sensitive discussions

7. Protect Assets in Vehicles

Vehicles can be a major physical-security risk.

Employees should avoid leaving company equipment:

  • Visible inside a vehicle
  • Unattended for long periods
  • In unsecured locations

Where possible:

Do not leave sensitive equipment in a vehicle.

If temporary storage is unavoidable, appropriate precautions should be applied based on the risk.


8. Protect Paper Documents

Off-premises security applies to physical documents too.

Employees taking documents outside the office should consider:

  • Whether the document is actually needed
  • Information classification
  • Secure transportation
  • Secure storage
  • Preventing unauthorized viewing
  • Secure disposal
  • Return of documents

For highly sensitive information, electronic access may be preferable to carrying physical copies.


9. Secure Remote Working

A.7.9 works closely with A.6.7 Remote Working.

A.6.7 primarily addresses the security requirements for remote working.

A.7.9 focuses on the security of assets taken outside the organization’s premises.

For example:

An employee works from home using a company laptop.

A.6.7 addresses secure remote working practices.

A.7.9 addresses the protection of the company laptop and information while it is outside the office.


10. International Travel

Organizations should consider additional risks associated with international travel.

Depending on the organization’s risk and destination, considerations may include:

  • Loss or theft
  • Public Wi-Fi
  • Device inspection
  • Local legal requirements
  • Physical surveillance
  • Sensitive information exposure
  • High-risk locations
  • Restricted or sensitive information

Organizations with significant international travel may create a dedicated travel-security procedure.


11. Report Loss or Theft Immediately

Employees should know exactly what to do if an asset is:

  • Lost
  • Stolen
  • Damaged
  • Accidentally exposed

A simple process could be:

Loss/Theft → Immediate Report → Security Assessment → Account/Device Protection → Incident Response → Investigation → Recovery/Replacement → Lessons Learned

Employees should not wait until they return to the office.


Startup Example – SaaS Company

Consider a 50-person SaaS startup.

Employees regularly work:

  • From home
  • From coworking spaces
  • At customer offices
  • While travelling

Company assets include:

  • Laptops
  • Mobile phones
  • Security tokens
  • Printed documents
  • USB devices

Controls

The startup implements:

  • Full-disk encryption
  • MFA
  • Automatic screen locking
  • EDR
  • Central device management
  • Security awareness training
  • Asset inventory
  • Remote wipe where appropriate
  • Immediate lost-device reporting
  • Travel-security guidance

Employees are instructed:

Do not leave company laptops unattended in public places or vehicles.

Simple Workflow

Assign Asset → Secure Device → Take Off-Premises → Protect → Monitor → Report Loss → Respond → Recover


Off-Premises Asset Register

A simple register can help track assets.

AssetAssigned ToAsset TypeClassificationAllowed Off-Premises?Key Controls
LAP-001EmployeeLaptopConfidentialYesEncryption, EDR
MOB-012EmployeeMobileConfidentialYesMDM, PIN
USB-003Security TeamStorageRestrictedControlledEncryption
DOC-014FinanceDocumentConfidentialRestrictedSecure handling
SEC-005ITSecurity TokenRestrictedYesUser-controlled

The exact register should be adapted to the organization’s asset-management process.


Off-Premises Asset Risk Assessment

AssetRiskImpactControl
LaptopTheftHighEncryption + EDR
LaptopShoulder surfingMediumScreen positioning/privacy filter
MobileLossHighEncryption + MDM
USBLossHighEncryption
Paper recordUnauthorized viewingHighSecure transportation/storage
LaptopPublic Wi-Fi attackMediumSecure network practices + endpoint controls

Remote Working vs Off-Premises Assets

These concepts should not be treated as exactly the same.

TopicA.6.7 Remote WorkingA.7.9 Off-Premises Assets
Main focusSecurity of remote workSecurity of assets outside premises
Home working✓✓
Travel✓✓
Laptop security✓✓
Physical documentsPossible✓
Public locations✓✓
Remote work environment✓Supporting consideration

Together, they create a more complete approach to remote and mobile work.


Audit Evidence for A.7.9

An auditor may ask for evidence that off-premises assets are actually protected.

Policies and Procedures

  • Asset Management Policy
  • Security of Assets Off-Premises Procedure
  • Remote Working Policy
  • Acceptable Use Policy
  • Mobile Device Policy
  • Travel Security Policy
  • Lost or Stolen Asset Procedure

Asset Evidence

  • Asset register
  • Laptop inventory
  • Mobile device inventory
  • Asset assignment records
  • Asset return records
  • Encryption status
  • Device management records

Technical Evidence

Where applicable:

  • Endpoint management
  • MDM
  • EDR
  • Disk encryption
  • Screen-lock configuration
  • Remote wipe capability
  • MFA
  • Device compliance reports

Operational Evidence

  • Security awareness training
  • Travel-security communications
  • Lost-device reports
  • Incident records
  • Device recovery records
  • Security investigations

Audit Checklist

An ISO 27001 auditor may ask:

Asset Identification

  • Have off-premises assets been identified?
  • Are laptops and mobile devices included in the asset inventory?
  • Are physical documents considered where relevant?

Authorization

  • Who is allowed to take assets off-premises?
  • Are there restrictions on certain assets?

Protection

  • Are laptops encrypted?
  • Are mobile devices protected?
  • Are screens protected in public environments?
  • Are physical documents protected?

Remote Working

  • Are remote-working requirements documented?
  • Are employees trained?

Travel

  • Are travel-security risks considered?
  • Are additional controls applied for higher-risk travel?

Loss and Theft

  • Do employees know how to report lost or stolen assets?
  • Is there an established response process?
  • Can compromised devices/accounts be secured quickly?

Monitoring

  • Can the organization determine which employee has a particular asset?
  • Are asset records maintained?
  • Are security incidents involving off-premises assets reviewed?

Common Mistakes in Implementing A.7.9

1. Treating Encryption as the Entire Solution

Encryption is extremely useful, but it does not physically prevent:

  • Theft
  • Damage
  • Unauthorized use
  • Shoulder surfing

Better approach:

Use layered physical and technical controls.


2. No Lost Device Process

Some organizations say:

“Employees must report lost devices.”

But employees do not know:

  • Who to contact
  • How quickly to report
  • What information to provide
  • What happens next

Better approach:

Define a simple lost-device reporting procedure.


3. Allowing Devices to Be Left in Vehicles

A laptop may be encrypted, but theft still creates:

  • Business disruption
  • Replacement costs
  • Potential security concerns
  • Incident-response workload

Better approach:

Tell employees not to leave company equipment unattended in vehicles wherever possible.


4. Ignoring Mobile Phones

Organizations sometimes protect laptops but forget smartphones.

Modern phones may contain:

  • Email
  • Slack/Teams
  • Customer applications
  • Authentication applications
  • MFA tokens
  • Business documents

Better approach:

Include mobile devices in the off-premises security program.


5. Ignoring Paper

Digital transformation does not eliminate physical information.

Printed:

  • Contracts
  • Customer records
  • Reports
  • Employee information

can still create significant risks.


6. No Asset Ownership

If a laptop disappears, the organization should know:

  • Who was assigned the laptop
  • Asset ID
  • Device details
  • Information classification
  • Security controls

Better approach:

Maintain an accurate asset inventory.


7. Same Rules for Every Location

Working from home is different from working in an airport.

A customer site may be different from a hotel.

Better approach:

Use risk-based guidance rather than one unrealistic rule for every environment.


Practical Startup Implementation Model

A startup can implement A.7.9 using the following model:

1. Identify

Identify assets that can leave organizational premises.

2. Classify

Understand the sensitivity and criticality of the assets.

3. Authorize

Define who may take assets off-premises.

4. Protect

Apply appropriate physical and technical controls.

5. Educate

Train employees about travel, remote work and physical security.

6. Monitor

Maintain asset ownership and device-security visibility.

7. Report

Make loss or theft reporting simple and immediate.

8. Respond

Protect accounts, devices and information following an incident.

9. Review

Review recurring incidents and improve controls.

Simple Model

Identify → Classify → Authorize → Protect → Educate → Monitor → Report → Respond → Review


Policy vs. Process vs. Evidence

ElementExample
PolicyOrganizational assets must be appropriately protected when used outside organizational premises.
ProcessEmployees protect, monitor and report loss or theft of off-premises assets.
Technical ControlsEncryption, EDR, MDM, MFA, screen lock
EvidenceAsset register, device compliance records, training, incident reports and recovery records

Remember:

The objective is not simply to issue secure laptops. The organization should also control how those assets are used and protected outside the office.


Relationship With Other ISO 27001 Controls

A.7.9 connects with many other controls.

ControlRelationship
A.5.9 Inventory of AssetsIdentifies assets and ownership
A.5.10 Acceptable UseDefines acceptable use
A.5.11 Return of AssetsAddresses return of assets
A.5.12 ClassificationDetermines protection requirements
A.5.15 Access ControlProtects access to information
A.5.18 Access RightsManages user access
A.5.33 Protection of RecordsProtects physical records
A.5.34 Privacy and PIIProtects personal information
A.6.3 Awareness and TrainingEducates employees
A.6.5 Termination/ChangeEnsures assets are recovered
A.6.7 Remote WorkingAddresses secure remote work
A.6.8 Event ReportingSupports reporting of loss/theft
A.7.6 Working in Secure AreasProtects work inside secure areas
A.7.7 Clear Desk/Clear ScreenPrevents information exposure
A.7.8 Equipment Siting and ProtectionProtects equipment at organizational premises
A.8.1 User Endpoint DevicesProvides technical protection for endpoints
A.8.7 Protection Against MalwareProtects devices against malicious software
A.8.15 LoggingSupports security monitoring where applicable

A.7.8 vs A.7.9 – What is the Difference?

A.7.8 – Equipment Siting and Protection

Focuses primarily on:

Where equipment is located and how it is protected physically.

Example:

A network switch is installed in a locked network room.

A.7.9 – Security of Assets Off-Premises

Focuses on:

How assets are protected when they are outside organizational premises.

Example:

An employee takes a company laptop to a customer meeting.

Simple Difference

A.7.8 = Protect equipment where it is located.

A.7.9 = Protect assets when they are outside the premises.


Useful Resources and Draft Documents

Organizations implementing A.7.9 may create:

  1. Security of Assets Off-Premises Policy
    [Insert Draft Document Link]
  2. Asset Management Policy
    [Insert Draft Document Link]
  3. Asset Register
    [Insert Draft Document Link]
  4. Off-Premises Asset Register
    [Insert Draft Document Link]
  5. Remote Working Security Policy
    [Insert Draft Document Link]
  6. Mobile Device Security Policy
    [Insert Draft Document Link]
  7. Travel Security Procedure
    [Insert Draft Document Link]
  8. Lost or Stolen Asset Procedure
    [Insert Draft Document Link]
  9. Laptop Security Checklist
    [Insert Draft Document Link]
  10. Mobile Device Security Checklist
    [Insert Draft Document Link]
  11. Asset Handover and Return Form
    [Insert Draft Document Link]
  12. Security Incident Report Form
    [Insert Draft Document Link]

Questions an Auditor May Ask

“Which assets are allowed to leave your premises?”

Show the asset policy and relevant asset records.

“How do you protect laptops outside the office?”

Explain:

  • Encryption
  • EDR
  • MFA
  • Screen locking
  • Device management
  • Physical security requirements

“What happens if an employee loses a laptop?”

Explain the reporting and incident-response process.

“How quickly must a lost device be reported?”

Show the documented requirement and demonstrate employee awareness.

“How do you know who has each laptop?”

Show the asset register and assignment records.

“How do you protect information when employees travel?”

Explain travel-security requirements and relevant awareness training.

“What about remote workers?”

Explain the relationship between A.7.9 and the organization’s remote-working controls under A.6.7.


Startup-Focused Quick Summary

A startup can implement A.7.9 with a practical set of controls.

Protect laptops

  • Full-disk encryption
  • MFA
  • EDR
  • Screen lock
  • Device management

Protect mobile devices

  • PIN/biometric authentication
  • Encryption
  • MDM where appropriate
  • Remote wipe where appropriate

Protect physical assets

  • Do not leave equipment unattended
  • Avoid leaving devices in vehicles
  • Secure documents during travel
  • Protect equipment in public locations

Protect information

  • Avoid displaying sensitive information publicly
  • Use privacy screens where appropriate
  • Avoid discussing confidential information where others can overhear

Prepare for incidents

  • Make lost-device reporting simple
  • Respond immediately
  • Revoke or protect access where necessary
  • Record and learn from incidents

Startup-Focused Final Takeaway

Modern organizations are increasingly distributed.

Employees work from:

  • Home
  • Customer locations
  • Coworking spaces
  • Hotels
  • Airports
  • Conferences
  • Different countries

As a result, information-security controls cannot stop at the office entrance.

ISO 27001 Annex A 7.9 ensures that organizational assets continue to receive appropriate protection when they leave controlled premises.

The practical objective is:

Know which assets leave the office, who has them, what risks they face, and how those risks are controlled.

For a startup, the implementation sequence is:

Identify → Classify → Authorize → Protect → Educate → Monitor → Report → Respond → Review

The goal is not to prevent employees from working flexibly.

The goal is to ensure:

Work from anywhere — without taking security risks everywhere.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *