EvidenceSheet

7.9 Security of assets off-premises

Requires assets located away from the organisation's premises to be protected.

5
artefacts
0
held by a system
4
at each review
hard
to go live
Physical access / facilities
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

none for this control

periodic reviewEvidence produced at each review

  • Records of assets held off premises, covering laptops, mobile devices, removable media and physical records · Physical access / facilities
  • Evidence of protection appropriate to the location, such as encryption, tracking, remote wipe capability and rules for leaving equipment unattended · Physical access / facilities
  • Evidence covering assets at home working locations and at third party sites · Physical access / facilities
  • Records of loss or theft off site and the response taken · Physical access / facilities

governing documentDocuments that govern the control

  • Rules covering assets taken off site, including authorisation, permitted use and the protection required · Policy repository / GRC workspace

First move

This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

7.8 Equipment siting and protection · 7.10 Storage media