isms.coach
← All controls

A.7.9 · Physical

Security of assets off-premises

Why it matters

Laptops and phones leave the office constantly — this is where most physical-asset risk actually lives for a remote team.

How a self-led small team implements it

Full-disk encryption plus a remote-wipe capability on all company devices is the practical baseline here.

What auditors expect to see

Device encryption status, MDM enrollment.

Track A.7.9 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.

Start your ISMS

More physical controls