A.7.9 Security of assets off-premises
Protect assets used or held off-site.
18
artefacts
3
held by a system
6
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- GPS tracking logs for mobile assets · Endpoint management (MDM / EDR)
- Secure disposal certificates issued by approved vendor · Vendor register / contract repository
- Asset destruction logs with dates, methods, and responsible personnel · SIEM / log platform
periodic reviewEvidence produced at each review
- Quarterly reconciliation reports between register and physical count · Physical access / facilities
- Chain‑of‑custody logs signed at each handover point · SIEM / log platform
- Signed service level agreements covering offsite asset protection · Vendor register / contract repository
- Third‑party risk assessment reports approved by risk management · Vendor register / contract repository
- Cloud storage configuration screenshots showing encryption settings · Cloud console / configuration management
- Chain‑of‑custody records for items from decommission to disposal · Data governance / DLP tooling
governing documentDocuments that govern the control
- Asset register with offsite location tags · Policy repository / GRC workspace
- Vehicle security checklist used for asset transport · Policy repository / GRC workspace
- Courier service contracts specifying handling requirements · Vendor register / contract repository
- Incident reports for any transport security breaches · Policy repository / GRC workspace
- Data protection addendums attached to third‑party contracts · Vendor register / contract repository
- Encryption key management policy · Policy repository / GRC workspace
- Encrypted backup verification reports · Policy repository / GRC workspace
- Third‑party audit certificates confirming compliance with encryption standards · Policy repository / GRC workspace
- Witness statements confirming physical destruction of assets · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 3 system-held artefacts from your Endpoint management (MDM / EDR) on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Missing offsite asset register
- Inadequate transport controls
- No third‑party risk assessments
- Encryption not verified for remote storage
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.7.8 Equipment siting and protection · A.7.10 Storage media