ISO 27001A.7 — Security of assets off-premises
A.7.9
Security of assets off-premises
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Protect information processing assets when used outside the organization's premises.
Points of focus
- Inventory off-premises assets
- Encrypt portable devices
- Report loss/theft quickly
- Limit sensitive data on portable media
Implementation notes
Company devices only for production access. Full-disk encryption mandatory. Ban production data on USB. Lost-device playbook triggers wipe + credential rotation. Assign a named owner in the SoA, tie operating evidence to asset inventory with assigned users, and sample the control during internal audit before Stage 2 fieldwork.
Audit tip: Sample five laptops for encryption status and show one lost-device ticket through wipe confirmation.
Evidence auditors typically request:
- Asset inventory with assigned users
- MDM encryption compliance
- Lost device incident tickets
- USB/portable media policy
Common gaps
- Unknown personal devices with Slack + VPN
- Unencrypted USB with database dumps
- Lost laptop reported weeks late
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.7.9 | This control |
| SOC 2 | CC6.1, CC6.5 | Related SOC 2 themes (CC6.1, CC6.5) — map in your crosswalk; not identical requirements. |
| HIPAA | §164.310(d) | Related HIPAA themes (§164.310(d)) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.7.9)
Frequently Asked Questions
Yes if they access corporate email or production admin apps.
Only if inventoried, encrypted, and approved — prefer cloud sandboxes.
A.6.7 is remote working practices; A.7.9 focuses on the physical assets themselves.
Even without owned data centers, security of assets off-premises still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with asset inventory with assigned users, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.