A.7.9 Physical
Security of assets off-premises
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (12)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AC-19mostlyaligns with — Both controls require management authorization and specific safeguards for mobile and personally-owned devices that process organizational information outside controlled facilities.
- MP-7mostlyaligns with — Both controls restrict and log the removal of portable storage media and devices from organizational premises while requiring protection against unauthorized access or loss.
- PE-16mostlyaligns with — Both controls establish authorization, logging, and accountability procedures for equipment and media entering or leaving organizational facilities.
- MP-5partialaligns with — Both controls address protection of information on media during transport or off-site use, including chain-of-custody considerations.
- PE-3partialaligns with — Both controls apply physical and logical access controls plus tamper-resistance measures to equipment installed or used in uncontrolled external locations.
- SC-28partialaligns with — Both controls require protection of information stored on devices that operate outside the organization’s secure boundary.
Aligned NIST CSF 2.0 outcomes (10)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.AM-08mostlyaligns with — The ISO control requires lifecycle tracking and authorization for assets that leave organizational premises, directly supporting the CSF outcome of managing assets throughout their life cycles.
- PR.AA-06mostlyaligns with — By mandating authorization, physical safeguards, and tamper-proofing for off-site equipment, the ISO control fulfills the CSF requirement to manage and enforce physical access commensurate with risk.
- PR.IR-02mostlyaligns with — The guidance to protect off-premises devices against environmental threats such as water, heat, and electromagnetic fields aligns with the CSF outcome of shielding technology assets from environmental threats.
- PR.DS-01partialaligns with — Remote-wipe capability and protection against shoulder-surfing on mobile devices contribute to safeguarding the confidentiality and integrity of data-at-rest on off-site equipment.
- PR.PS-01partialaligns with — Requiring chain-of-custody logs, removal authorizations, and secure deletion before transfer implements configuration and handling practices that the CSF places under configuration management.
Related OWASP ASVS 5.0 requirements (6)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (6)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1263partialmitigates — Addresses off-premises assets rather than on-site physical access control.
- CWE-200partialprevents — Requiring authorization, chain-of-custody logging, and remote-wipe capability for off-site devices reduces the chance that sensitive data will be exposed when the device is lost, stolen, or transferred.
- CWE-284partialmitigates — Mandating management authorization and maintaining removal records limits who can take assets outside the premises, thereby decreasing the opportunity for unauthorized access to the information they contain.
- CWE-312partialmitigates — Secure deletion of data before device transfer prevents residual sensitive information from remaining in cleartext on storage media that leave organizational control.
- CWE-359partialmitigates — Guidance against shoulder-surfing and viewing data in public places directly lowers the risk that private personal information displayed on mobile or laptop screens will be observed by unauthorized individuals.
- CWE-552partialmitigates — Physical-security measures, tamper-proofing, and logical access controls for permanently installed off-site equipment reduce the likelihood that files or directories on those assets become accessible to external parties.
Mitigated MITRE ATT&CK techniques (5)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1005partialmitigates — Remote-wipe and location-tracking capabilities on mobile devices reduce the window during which an adversary can collect files stored locally on a stolen or lost system.
- T1052partialmitigates — Requiring authorization and maintaining a chain-of-custody log for off-premises devices reduces the opportunity for an adversary to physically remove media or equipment containing sensitive data for later exfiltration.
- T1025nonemitigates — Authorization, logging, and secure-deletion requirements for removable media taken off-site decrease the likelihood that an attacker can obtain data directly from physical media left unattended.
- T1052.001nonemitigates — Mandating secure deletion of information before transferring off-premises equipment limits the amount of usable data an attacker can obtain via USB or other removable media.
- T1564.001nonemitigates — Physical-security and tamper-proofing measures for permanently installed off-premises equipment make it harder for an attacker to hide malicious files or configuration changes on that hardware.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.