A.7.9 Physical
Security of assets off-premises
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (19)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AC-19mostlyaligns with — Both controls require management authorization and specific safeguards for mobile and personally-owned devices that process organizational information outside controlled facilities.
- MP-5mostlycovers — A.7.9's broad requirement to prevent loss/damage/theft/compromise of any off-site devices (including media) and operational interruption accounts for the bulk of MP-5's transport protections, accountability, documentation, and authorized-personnel restrictions, but leaves a residual slice of MP-5's media-specific parameter-driven controls and explicit transport documentation uncovered.
- MP-7mostlyaligns with — Both controls restrict and log the removal of portable storage media and devices from organizational premises while requiring protection against unauthorized access or loss.
- PE-16mostlyaligns with — Both controls establish authorization, logging, and accountability procedures for equipment and media entering or leaving organizational facilities.
- MP-5partialaligns with — Both controls address protection of information on media during transport or off-site use, including chain-of-custody considerations.
- PE-3partialaligns with — Both controls apply physical and logical access controls plus tamper-resistance measures to equipment installed or used in uncontrolled external locations.
- SC-28partialaligns with — Both controls require protection of information stored on devices that operate outside the organization’s secure boundary.
- AC-19covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- MP-7covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PE-16covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- SC-28covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (17)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.AM-08mostlyaligns with — The ISO control requires lifecycle tracking and authorization for assets that leave organizational premises, directly supporting the CSF outcome of managing assets throughout their life cycles.
- PR.AA-06mostlyaligns with — By mandating authorization, physical safeguards, and tamper-proofing for off-site equipment, the ISO control fulfills the CSF requirement to manage and enforce physical access commensurate with risk.
- PR.IR-02mostlyaligns with — The guidance to protect off-premises devices against environmental threats such as water, heat, and electromagnetic fields aligns with the CSF outcome of shielding technology assets from environmental threats.
- PR.DS-01partialaligns with — Remote-wipe capability and protection against shoulder-surfing on mobile devices contribute to safeguarding the confidentiality and integrity of data-at-rest on off-site equipment.
- PR.PS-01partialaligns with — Requiring chain-of-custody logs, removal authorizations, and secure deletion before transfer implements configuration and handling practices that the CSF places under configuration management.
- ID.AM-08implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AA-06implements — A.7.9's technical measures for securing off-premises assets (protection against loss/theft/compromise while outside the facility) directly operationalize the physical-access management outcome named in PR.AA-06 when those assets leave the premises; the link is within the shared physical-protection domain but PR.AA-06 does not name off-premises handling specifically.
- PR.DS-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-02implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (6)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (6)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1263mitigates — Addresses off-premises assets rather than on-site physical access control.
- CWE-200prevents — Requiring authorization, chain-of-custody logging, and remote-wipe capability for off-site devices reduces the chance that sensitive data will be exposed when the device is lost, stolen, or transferred.
- CWE-284mitigates — Mandating management authorization and maintaining removal records limits who can take assets outside the premises, thereby decreasing the opportunity for unauthorized access to the information they contain.
- CWE-312mitigates — Secure deletion of data before device transfer prevents residual sensitive information from remaining in cleartext on storage media that leave organizational control.
- CWE-359mitigates — Guidance against shoulder-surfing and viewing data in public places directly lowers the risk that private personal information displayed on mobile or laptop screens will be observed by unauthorized individuals.
- CWE-552mitigates — Physical-security measures, tamper-proofing, and logical access controls for permanently installed off-site equipment reduce the likelihood that files or directories on those assets become accessible to external parties.
Mitigated MITRE ATT&CK techniques (97)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1011.001prevents — A.7.9 requires physical/logical protections, tracking, remote wipe, and secure handling for off-premises devices (including BYOD) that can block unauthorized Bluetooth pairing or data transfer in many scenarios, but leaves residual paths when an already-compromised device with sufficient access is in proximity and the Bluetooth channel is not itself secured.
- T1052prevents — A.7.9's rules on authorizing, logging, not leaving unattended, physical protections, remote wipe, and siting controls for off-premises devices/media directly stop many (but not all) user-introduced removable drives from being the exfiltration vector in air-gapped or similar scenarios
- T1052.001detects — A.7.9 requires physical security monitoring, audit trails for removable media removals, chain-of-custody logs, and location tracking on off-premises devices, which can surface anomalous USB usage or transfers in some scenarios but does not broadly instrument or detect the exfiltration technique itself.
- T1052.001prevents — A.7.9's rules on authorizing, logging, not leaving unattended, physical protections, remote wipe, and siting controls for off-premises devices directly stop many user-introduced USB exfiltration vectors (especially in air-gapped or BYOD scenarios), but leave open vectors such as authorized/approved removable media that an adversary can still abuse.
- T1091prevents — A.7.9 requires authorization, physical protections, chain-of-custody logging, secure deletion before transfer, shoulder-surfing awareness, remote wipe, and siting controls for off-premises devices and media; these stop malware from being placed on or carried by removable media/mobile devices in many (but not all) scenarios, especially air-gapped lateral movement via USB.
- T1110.001prevents — A.7.9 requires authorization, physical/logical protections, tracking, remote wipe and anti-shoulder-surfing measures for off-premises devices that could be used to run password-guessing tools (laptops, mobiles, BYOD, network devices); this stops many (but not all) guessing vectors that rely on stolen or compromised endpoint access.
- T1125prevents — A.7.9's physical protections, authorization, tracking, remote wipe, and anti-viewing rules for off-premises devices (including BYOD) can stop an adversary from physically accessing or using a webcam on a portable device taken outside the premises, but do not address malware/scripts using OS APIs on any platform once the device is in use.
- T1200prevents — A.7.9 requires authorization, logging/chain-of-custody, physical protections, and remote-wipe capability for off-premises devices and equipment, which stops many unauthorized hardware additions from ever being introduced or persisting; it does not address on-premises insider additions, permanent external plant (ATMs), or all supply-chain vectors, leaving a genuine minority slice prevented.
- T1486recovers — A.7.9 addresses physical protection, tracking, remote wipe, and siting of off-premises devices to avoid loss/theft; it does not restore availability or decrypt data after ransomware encryption has occurred
- T1552.004prevents — A.7.9 requires authorization, physical protections, chain-of-custody logging, shoulder-surfing awareness, remote wipe, and tamper-proofing for off-premises devices (including BYOD and permanent installs), which stops many scenarios where private keys on mobile/laptop/network devices could be searched for or exported after loss/theft/compromise, but leaves on-premises storage, endpoint search after initial access, passphrase brute-force, and non-device vectors untouched.
- T1561recovers — A.7.9 explicitly requires implementing remote wiping capability for off-premises devices and maintaining chain-of-custody/audit records that support post-incident recovery of wiped or lost assets, directly addressing restoration after a disk-wipe availability event on mobile/laptop/endpoint assets (the bulk of the technique's platform surface).
- T1561.001recovers — A.7.9 explicitly requires implementing remote wiping of devices (and chain-of-custody/secure-delete practices for transferred media), which can restore availability after a partial or targeted disk-content wipe on off-premises assets; this is a genuine but minority slice of the technique (most network-scale or non-device wipes sit outside its scope).
- T1561.002recovers — A.7.9 explicitly requires implementing location tracking and remote wiping for off-premises devices plus secure deletion/chain-of-custody practices that enable restoration of wiped or corrupted assets, directly addressing post-impact recovery of availability after a disk-structure wipe on mobile/BYOD endpoints (the named remainder being non-mobile or permanently-installed assets such as ATMs).
- T1669prevents — A.7.9 requires physical protections, tracking, remote wipe, and siting controls for off-premises devices (including those using Wi-Fi), which can stop an adversary from physically approaching or stealing a device to exploit open/nearby Wi-Fi but leaves the bulk of the technique (credential use on secured nets, dual-homed bridging, sniffing after connection) untouched.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.