In this guide you will learn how to implement ISO 27001 Annex A 7.9 and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 7.9 Security of assets off-premises is an ISO 27001 control that is about the protection of those assets when not in an environment you control.
Table of contents
Purpose & Definition
The purpose of ISO 27001 Security Of Assets Off-Premises is to prevent loss, damage, theft or compromise of off-site devices and interruption to the organisations operations.
The ISO 27001 standard defines ISO 27001 Annex A 7.9 as:
Off-site assets should be protected.
ISO 27001:2022 Annex A 7.9 Security of assets off-premises
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 7.9 Training Video
In this free training video you will learn How to implement ISO 27001 Security of Assets Off Premises (Annex A 7.9) and Pass Your Audit.
Implementation Guide
General Guidance
Well in this modern world people take their equipment of site. This used to be a massive thing a few years ago when everyone was chained to an office and all the equipment stayed at the office. Taking things off site was such a palaver, with forms and authorisation and massive forklift trucks to move those ‘laptops’. Things have moved on but the control remains now with a more general focus on the protection of assets off site. Rather than the process of authorising it.
Education and Training
Like much of the standard we are looking at common sense really when it comes to this control. There is a combination of telling people what is expected, training them, educating them and also where possible putting some technical controls in place if they help reduce risk.
Off Site Protection
We always want to protect what is important to us so in this situation we are looking at what are the threats that can be posed by having assets in an environment that we do not control and therefore what are things we can do to address those threats.
Public Areas
Simple things like not having assets left unattended in public areas. Seems to make sense but we have all seen people leave laptops open in bars, restaurants and on trains whilst they go and ‘use the facilities’.
Shoulder Surfing
There is a lot of shoulder surfing that goes on as well. People reading over your shoulder or between the gaps in train and aeroplane seats. We all like to be nosey, am I right? We can do things like be conscious of it and position ourselves so as not to facilitate it and we can consider the use of privacy screens and screen protectors. What ever works for you.
How to implement ISO 27001 Annex A 7.9
Implementing ISO 27001 Annex A 7.9 requires a rigorous framework to ensure that organisational equipment and information remain protected when removed from secure perimeters.
1. Formalise Asset Removal Authorisation and Accountability
Establish a documented approval process for any asset leaving the secure site to ensure all movements are tracked and assigned to a responsible individual.
- Update the central Asset Register to reflect the current location and temporary owner of the hardware.
- Define clear time limits for off-site usage to prevent assets from remaining outside the secure perimeter indefinitely.
- Require users to sign an Acceptable Use Policy (AUP) that specifically addresses off-site security responsibilities.
- Implement a digital sign-out workflow to maintain a timestamped audit trail for compliance reviews.
2. Provision Technical Safeguards and Data Encryption
Apply robust technical controls to the hardware to ensure that data remains inaccessible even if the physical device is compromised.
- Enforce Full Disk Encryption (FDE) using AES-256 standards on all laptops and portable storage devices.
- Configure Multi-Factor Authentication (MFA) for all system logins to prevent unauthorised access via stolen credentials.
- Deploy a Virtual Private Network (VPN) or Zero Trust Network Access (ZTNA) to secure data in transit over public Wi-Fi.
- Verify that endpoint protection and antivirus definitions are updated automatically regardless of the device location.
3. Establish Physical Handling and Transit Protocols
Implement strict physical security rules to protect assets from opportunistic theft or damage during travel and usage in public spaces.
- Prohibit the storage of organisational equipment in unattended vehicles or unsecured hotel rooms.
- Issue privacy filters for screens to mitigate the risk of visual eavesdropping or shoulder surfing in public environments.
- Mandate the use of padded, non-descript carrying cases to reduce the visibility of high-value equipment and prevent transit damage.
- Establish a “Line of Sight” rule requiring users to maintain physical control of assets in high-risk areas like airports or cafes.
4. Log and Monitor via Mobile Device Management
Utilise centralised management software to maintain visibility and control over equipment that is no longer within the local network.
- Enrol all off-site assets into a Mobile Device Management (MDM) or Unified Endpoint Management (UEM) solution.
- Configure remote wipe capabilities to delete all sensitive data immediately upon report of loss or theft.
- Enable “Find My Device” tracking features to assist in asset recovery or to verify the device’s last known location.
- Monitor device compliance status to ensure that security patches and encryption remain active while off-site.
5. Formalise Incident Reporting and Access Revocation
Prepare a rapid response protocol to minimise the impact of a lost or stolen off-premises asset.
- Define a maximum time window for users to report lost or stolen equipment to the security team.
- Revoke logical access and IAM roles immediately upon notification of a lost device to prevent secondary network breaches.
- Document every off-site asset incident within the ISMS incident log for trend analysis and audit evidence.
- Instruct users to change all personal and professional passwords if a device containing saved credentials is compromised.
Related Controls
There are a couple of other controls worth reading up here as well being ISO 27001 Annex A 6.7 Remote Working and ISO 27001 Annex A 8.1 User End Point Devices.
ISO 27001 Templates
For Annex A 7.9 Security Of Assets Off-Premises you need a topic specific Physical and Environmental Security Policy Template.
Having ISO 27001 templates can help fast track your ISO 27001 implementation. The ISO 27001 Toolkit is the ultimate resource for your ISO 27001 certification.
How to comply
To comply with ISO 27001 Annex A 7.9 Security Of Assets Off-Premises you are going to
- Train, educate, tell and communicate to people what is expected of them
- Assess you assets and perform a risk assessment
- Implement controls proportionate to the risk posed
- Test the controls that you have to make sure they are working
Top 3 mistakes and how to avoid them
The top 3 mistakes people make for ISO 27001 Annex A 7.9 Security Of Assets Off-Premises are
- You haven’t told people what is expected: It is really hard to control assets when you don’t control the environment that they are in. You cannot account for every situation and variable but you can equip people with the knowledge to make the right choices and the tools to reduce the risks. If you don’t communicate and educate and inform then this control will fail.
- One or more members of your team haven’t done what they should have done: Prior to the audit check that all members of the team have done what they should have. Do they know where the policies are? Have they acknowledged them? Have you checked a sample of off site workers and offsite workers to see if the controls are being followed? Check!
- Your document and version control is wrong: Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
ISO 27001 Annex A 7.9 FAQ
Securing assets off-premises involves a combination of formal authorisation, technical safeguards, and strict physical handling procedures to prevent unauthorised access.
Authorisation: Log every asset taken off-site in an asset register.
Encryption: Enforce Full Disk Encryption (FDE) on all portable devices.
Supervision: Maintain physical control of the device in public spaces at all times.
Insurance: Ensure the organisation’s insurance covers off-site usage and transit.
Yes, while ISO 27001 is technology-neutral, encryption is considered a mandatory technical control to protect data confidentiality on assets located off-premises.
Prevents data access if a laptop or phone is stolen.
Supports compliance with data protection laws like GDPR.
Allows for secure remote wipes if the device is lost.
Protects both internal storage and removable media.
No, leaving company assets unattended in a vehicle is generally prohibited under ISO 27001 policies due to the high risk of opportunistic theft.
Assets should never be left in a car overnight.
If temporary storage is unavoidable, assets must be locked in the boot and out of sight.
Physical control must be prioritised during transit.
Hotel safes should be used instead of vehicles during travel.
The primary risks of using assets in public environments include visual eavesdropping (shoulder surfing), physical theft, and interception via insecure networks.
Shoulder Surfing: Unauthorised viewing of sensitive data on the screen.
Theft: High risk of snatch-and-grab theft in cafes or transport hubs.
Insecure Wi-Fi: Interception of data via “Man-in-the-Middle” attacks.
Distraction: Loss of situational awareness leading to equipment misplacement.
The individual user is primarily responsible for the physical security and correct usage of an asset once it has been authorised for removal from company premises.
Users must follow the Acceptable Use Policy (AUP).
Immediate reporting of loss or theft to the IT/Security team is required.
Users must ensure assets are not used by family members or unauthorised persons.
Adherence to transport and storage guidelines is a condition of authorisation.
ISO 27001 Controls and Attribute Values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Confidentiality | Protect | Physical Security | Protection |
| Integrity | Asset management | |||
| Availability |
Stuart Barker
I am the ISO 27001 Ninja.
I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.
If you want to pass your audit the first time, book a call.


