7.9 Security of assets off-premises
Requires assets located away from the organisation's premises to be protected.
5
artefacts
0
held by a system
4
at each review
hard
to go live
Physical access / facilities
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Records of assets held off premises, covering laptops, mobile devices, removable media and physical records · Physical access / facilities
- Evidence of protection appropriate to the location, such as encryption, tracking, remote wipe capability and rules for leaving equipment unattended · Physical access / facilities
- Evidence covering assets at home working locations and at third party sites · Physical access / facilities
- Records of loss or theft off site and the response taken · Physical access / facilities
governing documentDocuments that govern the control
- Rules covering assets taken off site, including authorisation, permitted use and the protection required · Policy repository / GRC workspace
First move
This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.
Common gaps auditors find
- Register of what is off site does not exist, so exposure after a theft cannot be determined
- Encryption assumed present but never verified as enabled on the specific device
- Rules covering laptops while paper records, backup media and portable storage taken off site are unaddressed
- Loss reporting slow or absent because there is no clear route and people fear blame
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet