ISO 27001 Annex A control 7.9 requires organizations to protect assets used or stored away from their premises: “Off-site assets shall be protected.”[1] This off-site asset security guide for MSSP analysts explains how to identify those assets, apply proportionate physical and technical safeguards, and retain evidence that proves each SMB customer’s controls operate in practice. The objective is not to eliminate remote work, travel, or home use; it is to manage the associated loss, theft, unauthorized-access, and data-exposure risks consistently.
What counts as an asset used away from the customer’s premises?
For ISO 27001 control 7.9, an off-site asset is anything that contains, processes, stores, or provides access to customer information while outside a controlled business location. The scope should follow the asset and the information, not merely the device’s owner.
- Endpoint devices: laptops, tablets, smartphones, managed desktops temporarily taken home, and loaner devices.
- Storage media: encrypted USB drives, external disks, backup media, removable SSDs, and printed backup reports.
- Paper and physical items: client files, contracts, badge lists, network diagrams, hardware tokens, keys, and access cards.
- Network and infrastructure equipment: spare firewalls, switches, LTE routers, mobile hotspots, and devices carried to customer sites.
- Personally owned devices: where a customer permits BYOD to access email, SaaS applications, ticketing systems, or customer data.
- Assets in transit: equipment shipped between offices, sent to employees, moved to a repair provider, or transported to a client location.
Analysts should distinguish between an asset inventory and an off-premises exposure inventory. A laptop may appear in the CMDB, but the control needs additional information: who has custody, whether it routinely leaves a site, what data it can access, whether it is encrypted, and how it can be remotely disabled or wiped.
What protections should be applied to assets away from premises?
Protection should be risk-based. A low-value monitor transported to a home office does not need the same safeguards as an administrator laptop holding privileged access to multiple client tenants. However, every in-scope asset needs a defined baseline.
| Risk area | Expected safeguard | Operational evidence |
|---|---|---|
| Loss or theft of laptops | Full-disk encryption, screen lock, MFA, managed endpoint protection, remote lock or wipe capability | Microsoft Intune encryption-compliance report and Microsoft Defender device inventory |
| Unauthorized use by household members or travelers | Named user accounts, automatic lock after inactivity, no shared credentials, separate work profile where supported | Endpoint configuration profile, acceptable-use acknowledgement, access review records |
| Data exposure during travel | Minimal local data, approved encrypted media only, privacy screen where appropriate, secure storage in vehicles and hotels | Remote-work policy, travel guidance, encryption status, incident tickets |
| Asset transfer or shipping loss | Custody records, tracked shipping, tamper-resistant packaging, serial-number verification on receipt | PSA ticket, courier tracking number, signed handover record, asset register update |
| Compromise of privileged devices | Separate privileged account, phishing-resistant MFA, conditional access, EDR, rapid revocation process | Conditional Access export, privileged-access register, EDR alert history, incident runbook |
Technical controls must be paired with user behavior requirements. Encryption cannot compensate for an employee leaving an unlocked laptop in a car, and a policy cannot compensate for a missing recovery key or unmanaged endpoint. Effective off-site asset controls combine asset management, endpoint management, access control, awareness, and incident response.
Who is responsible for assets that employees, contractors, and suppliers take off-site?
The customer remains accountable for the control even when an MSP manages the tooling or a contractor holds the asset. The analyst’s job is to make responsibility explicit in the customer’s control design, service documentation, and evidence collection process.
At a minimum, assign an asset owner responsible for classification and lifecycle decisions, a custodian physically holding the asset, and an IT or security owner responsible for technical baseline compliance. For managed customers, the MSSP may operate Intune, Defender, Huntress, SentinelOne, or RMM alerts, but the customer should approve risk exceptions and employment-related enforcement.
For example, Northstar Managed Services supports 64 SMB customers with a 38-person team using HaloPSA, NinjaOne, Microsoft Intune, and Microsoft Defender for Business. When a new technician receives a laptop, Northstar opens a HaloPSA onboarding ticket, records the serial number and assigned custodian, confirms BitLocker escrow in Intune, verifies Defender health, and obtains an acceptable-use acknowledgement before dispatching the device. The ticket becomes evidence of both custody and baseline configuration rather than relying on a spreadsheet updated months later.
What evidence demonstrates ISO 27001 control 7.9 compliance?
Auditors generally need to see that the control is designed, applied to the appropriate population, and reviewed when exceptions occur. A policy by itself is insufficient. Build an evidence pack that ties the written requirement to actual endpoint, media, and incident records.
- An approved remote-work, mobile-device, or asset-handling policy that addresses off-site use and reporting obligations.
- An asset register showing owner, custodian, serial number, location or usage status, and encryption or management status.
- MDM, RMM, and EDR reports demonstrating in-scope endpoints are enrolled and compliant.
- Configuration records for encryption, automatic screen lock, endpoint protection, and remote wipe or lock capabilities.
- User acknowledgements, training records, and signed equipment handover forms.
- Tickets for lost devices, repairs, returns, shipping, replacements, and remote-wipe actions.
- Periodic access and asset reviews, including documented exceptions and remediation dates.
A practical device baseline can be represented in a customer’s configuration standard as follows:
Windows mobile endpoint baseline
- BitLocker: Required on OS and fixed data drives
- BitLocker recovery keys: Escrowed to Microsoft Entra ID
- Screen lock: Required after 10 minutes of inactivity
- Microsoft Defender Antivirus: Real-time protection enabled
- Microsoft Defender for Endpoint: Device onboarded and healthy
- Microsoft Intune compliance: Encryption required; minimum OS version enforced
- Conditional Access: Block access from non-compliant devices
- Local administrator rights: Removed unless approved through a time-bound exception
How do MSSP analysts implement off-site asset security step by step?
- Define the customer scope. Identify locations, remote workers, traveling personnel, contractors, loan equipment, removable media, and shipped hardware. Document whether BYOD is allowed and under what conditions.
- Build the off-premises asset population. Reconcile the CMDB or asset register with Intune, RMM, EDR, Entra ID, and PSA records. Investigate devices visible in a tool but missing an assigned owner or status.
- Classify risk. Flag administrator endpoints, finance devices, systems with customer personal data, portable storage, and devices with access to production environments as higher-risk assets.
- Set a minimum technical baseline. Enforce encryption, supported operating systems, endpoint protection, MFA, screen locking, patching, and remote response capability. Use compliance policies to prevent unmanaged devices from reaching sensitive SaaS services.
- Document physical and behavioral rules. Define secure storage, transport, prohibited locations, public Wi-Fi expectations, approved media, family-member access restrictions, and the deadline for reporting loss or theft.
- Operationalize handover and return. Use a PSA workflow for issuance, transfer, repair, return, and disposal. Require custody confirmation and serial-number validation at each handoff.
- Monitor and remediate. Review non-compliant endpoints at least monthly, create tickets for remediation, and escalate devices that cannot be verified. Record justified exceptions with an owner, risk acceptance, and expiry date.
- Test incident readiness. Periodically test a lost-laptop scenario: disable the user session, revoke tokens, locate or remotely wipe the device where appropriate, assess data exposure, and retain the ticket timeline.
For a 75-user IT services customer with technicians who travel between client sites, an analyst might use an Intune device-compliance export each month and compare it to the NinjaOne device list. A device appearing in NinjaOne but not Intune is treated as an exception: the analyst opens a HaloPSA ticket, confirms whether it is a server, retired device, or unmanaged mobile endpoint, then records the resolution. This makes the review repeatable and defensible.
What is the off-site asset security guide for MSSP analysts checklist?
- Confirm the customer has defined “off-site assets” within its ISO 27001 scope and asset-management process.
- Identify laptops, mobile devices, removable media, paper records, tokens, loaners, shipped equipment, and permitted BYOD.
- Assign an asset owner and a current custodian for every portable or remotely used asset.
- Verify the asset register includes serial number, user, status, and management or encryption information.
- Enforce disk encryption and securely escrow recovery keys for supported endpoint platforms.
- Verify EDR or antivirus, patching, screen-lock, MFA, and remote response capabilities are active.
- Restrict sensitive SaaS access from non-compliant or unmanaged devices where the customer’s licensing supports it.
- Document requirements for home working, travel, vehicle storage, public spaces, and approved removable media.
- Use tracked, documented workflows for asset issuance, shipment, repair, transfer, return, and disposal.
- Provide a simple loss-or-theft reporting route and test the response process.
- Review compliance reports, open remediation tickets, and preserve evidence at the customer’s defined review interval.
- Record risk-accepted exceptions with approving authority, compensating controls, and an expiry date.
Frequently asked questions about protecting assets off premises
Does ISO 27001 control 7.9 apply to employee home offices?
Yes. A customer-managed laptop, mobile device, document, token, or other information asset used at an employee home is off-premises and should be protected according to its risk. Controls should address both device security and physical handling, such as preventing unauthorized household access and securely storing devices when not in use.
Are personally owned phones included in off-site asset security?
They are included when they access, store, or process organizational information and are permitted by the customer’s policy. The control approach may be different from corporate-owned devices, using application protection policies, managed work profiles, conditional access, or a prohibition on local data storage.
What should happen when an employee loses a company laptop?
The user should report it immediately through the documented incident route. The MSSP or customer IT team should verify the device’s encryption and last check-in, revoke active sessions as needed, disable or wipe the device where appropriate, assess whether information may have been exposed, and retain the incident record and corrective actions.
Is full-disk encryption enough to satisfy ISO 27001 Annex A 7.9?
No. Encryption is an important safeguard against data exposure after theft or loss, but control 7.9 also requires a broader protection process. The organization needs asset ownership, secure handling rules, access controls, monitoring, reporting procedures, and evidence that these measures are operating.
How often should an MSSP review off-site asset compliance?
Monthly is a practical operating cadence for most SMB customers, particularly where MDM and RMM reports can be reconciled efficiently. Higher-risk customers or those with frequent onboarding, travel, and contractor activity may need weekly exception review, while formal control effectiveness reviews can occur quarterly or during internal audit cycles.
Next step: Build a customer-by-customer off-premises asset report from your MDM, RMM, and PSA data, then use the checklist above to turn every gap into an assigned remediation ticket.