The moment an asset leaves the building, your physical controls stop working.
Annex A 7.9 exists to ensure organisations protect information assets when they are taken or installed outside organisational premises, where loss, theft, damage, and unauthorised access are more likely.
This control is about extending physical security beyond the office — not assuming it still applies.

Annex A 7.9 of ISO 27001:2022 focuses on securing information assets used or located off-premises.
At a practical level, this means:
The control does not prohibit off-site use. It expects organisations to recognise the increased risk and apply appropriate safeguards.
Once assets leave controlled premises:
Common examples include:
Annex A 7.9 ensures organisations do not rely on office-based controls for off-site assets, where those controls are ineffective.
This control replaces ISO 27001:2013 Annex A 11.2.6 and significantly expands expectations around modern working practices.
A pragmatic approach to Annex A 7.9 typically includes the following elements.
Organisations should define:
Where appropriate, authorisation and recording of asset removal helps maintain accountability and auditability.
Assets taken off-premises should be protected against common risks.
This may include:
Manufacturer guidance should be considered when defining physical protection requirements.
Off-premises use increases the risk of shoulder-surfing and casual observation.
Organisations should take steps to:
Visual exposure is one of the most common off-site weaknesses.
Where risk justifies it, organisations may:
Clear ownership reduces loss and dispute.
For some devices, particularly mobile computing equipment, organisations may consider:
These controls reduce impact when assets are lost or stolen.
Annex A 7.9 also applies to equipment installed outside organisational premises on a permanent basis.
Examples include:
For these assets, organisations should consider:
Permanent off-site installation typically carries higher and more sustained risk.
Annex A 7.9 should be aligned with:
Off-site security fails when controls operate in isolation.
Annex A 7.9 does not require:
It does require organisations to:
Off-site exposure is not hypothetical — it is routine.
Most off-site incidents are preventable with basic discipline.
Annex A 7.9 is about protecting information when it leaves controlled space.
When off-premises assets are managed effectively:
Assets move.
Annex A 7.9 ensures security moves with them.
We can help you understand your actual security needs and even if we cant help we can point you in the right direction
Talk to a security expert today