Skip to content
arrow_back
search
Annex A 7.9 verified ISO/IEC 27001:2022

Security of Off-Site Assets

Ensure assets used outside the office are protected from theft or loss.

record_voice_over

Plain language

This control is about making sure that any company devices used outside the work premises, like laptops or phones, are protected from being lost, stolen, or damaged. It matters because if these devices are not secure, sensitive company information could fall into the wrong hands or be lost, which could lead to financial loss or damage to the company's reputation.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Physical controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Off-site assets shall be protected.
verified ISO/IEC 27001:2022 Annex A 7.9
priority_high

Why it matters

Lost or stolen off-site assets can lead to significant data breaches, risking sensitive data exposure and financial loss.

settings

Operational notes

Regularly verify off-site devices have current encryption, remote wipe and tracking enabled to reduce theft or loss risk.

Mapping detail

Mapping

Direction

Controls