ISO 27001 Security of Assets Off-Premises Explained – Control 7.9

ISO 27001 Security of Assets Off-Premises Explained – Control 7.9

The moment an asset leaves your building, your physical office controls stop working. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations invest millions in badges, security guards, and server room locks, only to hand employees unmonitored laptops and mobile devices to use in coffee shops, on trains, or in public spaces without any physical safeguards. Off-premises assets operate in untrusted environments where theft, loss, visual eavesdropping, and tampering are far more likely. Security must travel with the asset.

ISO 27001:2022 includes Annex A 7.10 to ensure you protect information assets used, transported, or permanently installed outside corporate boundaries. This control replaces the former 2013 requirement (11.2.6) and expands guidance to cover modern hybrid working, remote equipment, and external infrastructure deployments.

Quick Summary: What ISO 27001 Annex A 7.9 Requires

At a practical level, Annex A 7.9 is about extending physical security beyond the office perimeter. It does not mean banning remote work or travel; it requires deliberate, risk-proportionate safeguards so off-site assets remain protected. Here is what you need to do in plain English:

  • Establish Off-Premises Asset Rules: Define clear authorization workflows, usage policies, and custody responsibilities for hardware taken off-site.
  • Protect Hardware from Physical Theft & Damage: Train users never to leave devices unattended in public spaces, vehicle trunks, or unmonitored hotel rooms.
  • Prevent Shoulder-Surfing & Screen Exposure: Enforce the use of privacy filters, screen-locking policies, and careful positioning in public or transit areas.
  • Deploy Remote Management & Tracking: Use MDM tools to enable remote location tracking, remote locking, and cryptographic wiping if a device disappears.
  • Secure Permanently Installed Off-Premises Hardware: Lock down external equipment, telemetry sensors, and edge devices permanently deployed outside your physical perimeter.
  • Align Off-Site Controls with Remote Work Policies: Connect physical asset security directly with logical remote access rules (Annex A 6.7) and full-disk encryption (Annex A 8.24).

Why Unprotected Off-Premises Assets Are a Major Hazard

When hardware leaves controlled corporate facilities, it is exposed to theft, shoulder-surfing, physical damage, and untrusted network access. Once an asset is outside your physical walls, perimeter badges and CCTV offer zero protection.

Ignoring off-premises asset security exposes your business to severe hazards:

  • Physical Theft of Unencrypted Laptops: Hardware stolen from cars, airport terminals, or public transport exposing sensitive customer records or credentials.
  • Visual Eavesdropping (“Shoulder-Surfing”): Attackers or competitors viewing confidential financial forecasts or source code on unshielded laptop screens in public places.
  • Tampering with External Equipment: Unmonitored remote communications hardware or IoT edge sensors physically accessed, tapped, or damaged by unauthorized parties.
  • Unclear Asset Custody & Lost Inventories: Hardware disappearing during remote working transitions because asset removal was never authorized or logged.

My 8 Step Plan to Implement Annex A 7.9 Fast

You do not need to restrict staff from working on the go to satisfy an ISO 27001 auditor. Here is my pragmatic, 8-step plan to establish an audit-ready off-premises asset security framework.

1. Establish an Asset Removal Authorization Process

Ensure hardware leaves corporate facilities through a formal, trackable process rather than ad-hoc borrowing:

  • Define explicit approval workflows and policy conditions for removing corporate assets from company premises.
  • Maintain asset checkout logs tracking serial numbers, borrowing dates, user identities, and expected return dates (Annex A 8.9).
  • Require explicit management authorization before high-risk, sensitive hardware assets (like unencrypted diagnostic equipment or servers) are moved off-site.

2. Educate Staff on Physical Asset Protection in Public

Technical controls fail if user behavior in public environments is careless. Train employees on physical protection basics:

  • Enforce a strict rule prohibiting staff from leaving laptops, tablets, or phones unattended in cars, coffee shops, or public venues.
  • Require hardware stored in hotel rooms or temporary off-site locations to be locked inside safes or secured using cable locks.
  • Instruct users to protect hardware against physical hazards like extreme heat, moisture, dust, or physical impact during transit.

3. Prevent Public Visual Exposure (Shoulder-Surfing)

Information displayed on screens in public or transit environments is easily observed by onlookers or recorded by cameras:

  • Issue privacy screen filters to staff who routinely work in public spaces, on trains, or during travel.
  • Instruct staff to position screens away from open walkways, glass windows, and public viewing angles.
  • Require staff to lock workstation screens immediately whenever stepping away, even for a few seconds (Annex A 8.1).

4. Deploy Location Tracking and Remote Protection

Ensure your IT and security teams maintain remote visibility and control over mobile computing hardware:

  • Enable device-location tracking features inside your central Mobile Device Management (MDM) platform.
  • Configure automatic, remote-locking triggers when a device is reported lost, stolen, or misses central check-ins.
  • Test remote wipe workflows regularly to ensure corporate application data can be scrubbed instantly over external networks (Annex A 8.1).

5. Secure Permanently Installed External Equipment

Annex A 7.9 explicitly covers hardware permanently deployed outside your primary office walls (e.g., cell towers, remote sensors, edge routers):

  • Enclose external hardware inside tamper-evident, weather-proof, locked physical enclosures (Annex A 7.5).
  • Deploy physical intrusion sensors, door-open alerts, or CCTV monitoring for external equipment locations (Annex A 7.4).
  • Disable physical management ports (console, USB) on external appliances to prevent direct hardware hacking.

6. Mandatory Full-Disk Encryption for Off-Site Media

Physical protection must always be backed up by mathematical protection in case physical theft occurs:

  • Enforce mandatory full-disk encryption (BitLocker, FileVault) across all off-premises laptops, smartphones, and storage media (Annex A 8.24).
  • Ensure master recovery keys are managed centrally and never stored on the local device.
  • Block local data saving to unencrypted external USB drives (Annex A 7.10).

7. Secure Physical Transport and Courier Handover

When shipping or moving hardware between corporate offices, remote workers, or third-party facilities, manage transit risks:

  • Use trackable, reputable courier services requiring signature sign-offs for off-site equipment deliveries.
  • Pack hardware in padded, tamper-evident protective transit cases to prevent physical damage.
  • Verify equipment serial numbers upon delivery before activating network access rights.

8. Align Off-Premises Asset Rules with Remote Working Governance

Ensure physical asset controls link seamlessly with your wider remote working and network security policies:

  • Align Annex A 7.9 physical asset requirements with your formal Remote Working Policy (Annex A 6.7).
  • Mandate secure, encrypted network connections (VPN / ZTNA) whenever accessing internal platforms off-site (Annex A 8.20).
  • Feed lost or stolen off-premises asset reports directly into your formal security incident management workflow (Annex A 5.24).

Common Implementation Pitfalls and How to Fix Them

When preparing clients for ISO 27001 audits, I frequently spot the same off-premises asset mistakes. Here are the main traps and how to solve them:

  • Problem: Laptops Left Stolen from Unattended Vehicle Trunks
    Ninja Solution: Train staff that vehicle trunks are not secure storage; mandate that laptops remain in the user’s direct custody during travel.
  • Problem: Confidential Client Spreadsheets Viewed Unshielded on Busy Trains
    Ninja Solution: Supply privacy screens globally to traveling staff and enforce acceptable use rules regarding public screen visibility.
  • Problem: No Checkout Records for Borrowed Laptops or Testing Equipment
    Ninja Solution: Implement a simple digital checkout log requiring manager approval before hardware leaves company premises.
  • Problem: Unmonitored Edge Routers Installed at Remote Sites Without Physical Enclosures
    Ninja Solution: Lock external equipment inside tamper-evident, weather-proof cabinets and restrict console port access.

The ISO 27001 Ninja Bottom Line

ISO 27001 Annex A 7.9 is about extending your physical security boundary directly to wherever your hardware operates. Office locks and security guards offer zero protection once a device leaves the building, but applying practical off-premises controls ensures your information assets stay protected anywhere in the world.

By defining asset removal authorization, training staff on public physical security, enforcing privacy screen use, deploying remote wipe and location tracking via MDM, locking down permanently installed external gear, and enforcing full-disk encryption, you protect your mobile workforce, eliminate lost-device exposure risks, and satisfy your ISO 27001 auditor with complete confidence.