Control Mapping Readerplace a control, see the map

A.11.2.6 Security of equipment and assets off-premises

A.11.2.6 in ISO 27001:2013 (ISO/IEC 27001:2013). All ISO 27001:2013 controls held. Open ISO 27001:2013 on the standards site.

The control as we hold it

Security of equipment and assets off-premises. Assets off-site are protected, with regard to the extra risks that come with working away from the organization's own sites. As an Annex A reference control it is compared with the controls chosen in risk treatment (6.1.3 c) and recorded in the Statement of Applicability, included with a reason and an implementation status or excluded with a reason (6.1.3 d). Carried into ISO/IEC 27001:2022 as A.7.9.

Reviewed and closest counterparts in the other frameworks

Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.

ISO 27001:2022

What an auditor commonly asks for

General guidance for this control area (domain: A.11 Physical and environmental security), in our words, not a statement of the standard and not binding on an assessor.

Buy the reviewed crosswalk pair Place your own control