A.5.11 Organizational
Return of assets
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (7)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PS-4mostlyaligns with — Both controls require a structured termination process that ensures all organizational assets and information are returned or transferred before personnel depart.
- AC-2partialaligns with — Both require formal account and access revocation actions as part of the personnel termination workflow to prevent continued use of organizational resources.
- CM-8partialaligns with — Both emphasize maintaining accurate records of issued assets so that all equipment and information can be accounted for and recovered during termination.
- MP-6partialaligns with — Both address the secure removal of organizational information from equipment that is returned, sold, or personally owned by departing personnel.
Aligned NIST CSF 2.0 outcomes (9)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.AM-08mostlyaligns with — The ISO control ensures assets are recovered and sanitized at the end of their lifecycle with personnel, directly supporting the CSF requirement to manage hardware, software, services, and data throughout their entire life cycles.
- GV.SC-10partialaligns with — The control’s emphasis on recovering assets and knowledge from departing parties extends supply-chain risk management practices to the post-contract or post-employment phase.
- PR.AA-01partialaligns with — By mandating the return of authentication hardware and credentials when personnel depart, the control helps maintain accurate inventories of identities and credentials under organizational management.
- PR.DS-01partialaligns with — Requiring secure deletion of organizational information from personal or purchased equipment protects the confidentiality and integrity of data-at-rest that is leaving organizational control.
- PR.PS-03partialaligns with — Formal return procedures for hardware at termination constitute a hardware maintenance and removal practice that reduces risk associated with assets leaving the organization.
Related OWASP ASVS 5.0 requirements (4)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (6)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1301partialmitigates — Return-of-assets process can include verification of data removal but does not specify technical completeness.
- CWE-200partialprevents — Requiring the return of all physical and electronic assets plus secure deletion of organizational data from personal devices reduces the chance that sensitive information remains accessible to departing personnel.
- CWE-552partialmitigates — By tracing and retrieving all copies of information stored on endpoint and portable devices, the control reduces the likelihood that files remain accessible outside the organization’s security perimeter.
- CWE-284noneprevents — Formal asset-return procedures ensure that authentication hardware and access tokens are reclaimed, limiting continued unauthorized access after employment ends.
- CWE-312nonenone — Mandating secure deletion of organizational data from equipment that is purchased or personally owned prevents sensitive information from persisting in cleartext on devices no longer under organizational control.
Mitigated MITRE ATT&CK techniques (7)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1005partialmitigates — Mandatory return and secure deletion of endpoint devices prevents an adversary from retaining local copies of sensitive files that could be collected after departure.
- T1052partialmitigates — Requiring the return of portable storage devices and endpoint hardware at termination removes the physical medium an adversary could otherwise use to carry data out of the organization.
- T1078partialprevents — Collecting authentication hardware such as tokens and smartcards at off-boarding directly removes valid credentials that an adversary could continue to use for unauthorized access.
- T1552partialmitigates — Requiring the return of devices and portable storage reduces the chance that credentials or other sensitive material stored locally remain accessible to a departing insider or subsequent adversary.
- T1025nonemitigates — Reclaiming removable media at termination stops an adversary from keeping organization data on external drives for later retrieval or exfiltration.
- T1052.001nonemitigates — Formal asset-return procedures eliminate the opportunity for an insider to retain USB drives or similar media that would be used to exfiltrate data over physical channels.
- T1567nonemitigates — By ensuring all organization-owned or entrusted devices are returned and wiped, the control reduces the likelihood that an adversary can later use those devices to upload or stage data to external web services.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.