ISO 27002:2022 7.9: Security of assets off-premises
Assets taken or located off-site are to be protected. Purpose: stop devices used away from the premises from being lost, stolen, damaged or compromised, and avoid the operational disruption that would cause. Guidance: any device used outside the premises that stores or processes information, whether owned by the organization or privately owned and used for its work (BYOD), needs protection, and its use is authorized by management. For such devices consider: never leaving equipment or media unattended in public or insecure places; following manufacturers' protection instructions, for example against strong electromagnetic fields, water, heat, humidity and dust; keeping a chain-of-custody log naming the people and organizations responsible when off-site equipment passes between parties, and securely deleting information that need not travel with it; requiring authorization, where needed and practical, for removing equipment and media from the premises and recording removals as an audit trail (5.14); guarding against others viewing screens on public transport and against shoulder surfing; and location tracking with remote wipe. Equipment permanently installed off-site, such as antennas or cash machines, faces higher and location-dependent risk of damage, theft or eavesdropping, so consider physical security monitoring (7.4), protection against physical and environmental threats (7.5), physical access and tamper-proofing controls, and logical access controls. Other information: 8.1 and 6.7 cover further aspects of endpoint and remote equipment protection.
This control maps to 61 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 7.9 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.