Skip to content
compliancebase
ISO 27001A.7 — Security of assets off-premises

A.7.9

Security of assets off-premises

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Protect information processing assets when used outside the organization's premises.

Points of focus

  • Inventory off-premises assets
  • Encrypt portable devices
  • Report loss/theft quickly
  • Limit sensitive data on portable media

Implementation notes

Company devices only for production access. Full-disk encryption mandatory. Ban production data on USB. Lost-device playbook triggers wipe + credential rotation. Assign a named owner in the SoA, tie operating evidence to asset inventory with assigned users, and sample the control during internal audit before Stage 2 fieldwork.

Audit tip: Sample five laptops for encryption status and show one lost-device ticket through wipe confirmation.

Evidence auditors typically request:

  • Asset inventory with assigned users
  • MDM encryption compliance
  • Lost device incident tickets
  • USB/portable media policy

Common gaps

  • Unknown personal devices with Slack + VPN
  • Unencrypted USB with database dumps
  • Lost laptop reported weeks late

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.7.9This control
SOC 2CC6.1, CC6.5Related SOC 2 themes (CC6.1, CC6.5) — map in your crosswalk; not identical requirements.
HIPAA§164.310(d)Related HIPAA themes (§164.310(d)) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Yes if they access corporate email or production admin apps.

Only if inventoried, encrypted, and approved — prefer cloud sandboxes.

A.6.7 is remote working practices; A.7.9 focuses on the physical assets themselves.

Even without owned data centers, security of assets off-premises still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with asset inventory with assigned users, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above