ISO27001

Equipment Security and Maintenance: ISO 27001 Controls 7.8–7.13

Equipment Security and Maintenance: ISO 27001 Controls 7.8–7.13
Loading advertisement...
14

Priya Anand had been CISO at Alderney Mutual Insurance for eleven months when the call came in at 6:40 a.m. on a Tuesday. A senior claims adjuster's laptop had been stolen from a rental car outside a downtown Denver hotel during an industry conference. The laptop wasn't unusual — a standard-issue Dell Latitude, three years old, running the same endpoint protection stack as every other machine in the fleet. What made the call different was what was on it: a local, unencrypted export of 41,000 policyholder records the adjuster had pulled two weeks earlier to build a regional loss-ratio analysis, and never deleted.

Full-disk encryption had been "in progress" as a fleet rollout for six months. The adjuster's machine, provisioned before the rollout window, had been missed. Nobody had checked. There was no asset tag linking the device to a documented off-premises use approval, no record of what data had left the building, and no remote-wipe capability configured because the device predated the mobile device management (MDM) enrollment policy.

By the time outside counsel, forensic investigators, a credit-monitoring vendor, and two state insurance regulators had finished their work, Alderney's finance team had booked $2.4 million against the incident: notification costs for 41,000 policyholders across nine states, two years of credit monitoring, forensic reconstruction of exactly which records were on the device, a six-figure regulatory settlement in the adjuster's home state, and the unbudgeted hours of Priya's own team for the ninety days that followed. None of it involved a firewall, a phishing email, or a zero-day. It was a control that ISO 27001 spells out in six numbered clauses most implementers treat as an afterthought.

That's the gap this article closes: Annex A controls 7.8 through 7.13 — equipment siting and protection, security of assets off-premises, storage media, supporting utilities, cabling security, and equipment maintenance. Together they govern the physical machines, drives, cables, and power feeds that everything else in your ISMS — access control, encryption, backup — actually depends on. Get the "boring" physical layer wrong, and it doesn't matter how good your Annex A technological controls are on paper.

Who this is for

This is for the person who owns the Statement of Applicability line items for 7.8–7.13 and has to turn six sparse Annex A sentences into policies, physical measures, and evidence an auditor will accept — typically a CISO, IT operations manager, facilities lead, or compliance manager running a first-time or renewal ISO 27001 certification. You'll walk away with a defensible equipment-siting standard, an off-premises and remote-work asset policy with encryption and tracking requirements, a removable-media lifecycle policy, a utilities and power-resilience approach that won't get flagged in Stage 2, cabling protection guidance, and a maintenance regime with the records to prove it's real. If you're building Annex A control-by-control, this article assumes you've already read the physical controls overview and are ready to go deep on the equipment layer.

The six controls at a glance

Control

Name

Core question it answers

Typical owner

7.8

Equipment siting and protection

Is equipment physically placed and protected so threats and unauthorized people can't easily reach it?

Facilities / IT Ops

7.9

Security of assets off-premises

Are laptops, phones, and field equipment protected to the same standard once they leave the building?

IT Ops / Security

7.10

Storage media

Is removable media (USB drives, tapes, external disks) controlled from issue to disposal?

Records Management / IT

7.11

Supporting utilities

Will power, HVAC, and water failures be prevented from disrupting information processing?

Facilities / Data Center Ops

7.12

Cabling security

Is power and telecom cabling protected from interception, interference, and physical damage?

Facilities / Network Engineering

7.13

Equipment maintenance

Is equipment maintained correctly to preserve availability, integrity, and confidentiality?

IT Ops / Vendor Management

These six sit inside the fourteen-control Physical theme (7.1–7.14) of Annex A, and they pick up where the perimeter and room-level controls covered in physical security perimeters and entry controls and securing offices, rooms, and facilities leave off. Those controls stop unauthorized people from reaching a room. 7.8–7.13 protect the equipment, media, and infrastructure inside that room — and, critically, outside it, once equipment leaves the building. If any of the terminology below is unfamiliar, our ISO 27001 glossary is a fast reference for the exact definitions ISO 27002:2022 uses.

Control 7.8: Equipment siting and protection

Equipment siting is the control most auditors assume is "obvious" and most organizations have never actually documented. ISO/IEC 27002:2022 frames it plainly: equipment should be sited and protected to reduce the risks from environmental threats and hazards, and opportunities for unauthorized access. That covers two very different failure modes. The first is environmental — a server rack under a bathroom on the floor above, a UPS room with no water detection sitting below a sprinkler main, a comms cabinet backed against an exterior wall that floods every spring. The second is access — a printer with cached print jobs sitting in an open reception area, a network switch in an unlocked closet visitors walk past, a workstation with an unlocked screen facing a lobby window.

Neither failure mode requires malice to hurt you. Priya's incident above wasn't caused by 7.8, but plenty of Alderney's peers have had cleaning contractors quietly photograph screens visible through un-shaded conference-room glass, or lost a rack of switches to a slow leak nobody noticed because the equipment room doubled as janitorial storage.

What "good" looks like in practice:

  • A documented equipment placement standard covering server rooms, comms closets, printer/copier locations, and end-user workstations, tied to a risk assessment (not a gut feeling about which corner has a free outlet).

  • Physical separation of high-value or high-sensitivity equipment from general foot traffic, food and drink areas, and public-facing space.

  • Environmental controls for anything beyond standard office equipment — temperature and humidity monitoring, water detection, and clean-agent fire suppression where the risk assessment warrants it.

  • Screen positioning and privacy filters for workstations that face windows, lobbies, or shared corridors, feeding into the same discipline covered in the clear desk and clear screen policy — but 7.8 is about where the screen sits, not what's left on the desk.

  • A rule against eating, drinking, or smoking near equipment that would suffer real damage from a spill.

Requirement

What good looks like

Evidence an auditor accepts

Risk-based placement

Equipment sited using a documented risk assessment (fire, flood, dust, vibration, EMI, foot traffic)

Site risk assessment referencing specific rooms/racks, dated and owned

Restricted physical access

Server rooms, comms closets, and equipment racks locked, with access limited to a named list

Access control list for the room, correlated to badge/key logs

Environmental monitoring

Temperature, humidity, water leak, and smoke detection in server/comms rooms

Monitoring system export or facilities log showing alert thresholds and recent readings

Screen and output protection

Screens and printers positioned away from public view; sensitive output not left in trays

Site walk-through photos/checklist; printer release-code configuration

No consumables near equipment

Written rule against food/drink in server rooms and comms closets

Facilities policy plus signage; incident log showing zero related events

"The site walk is where I catch more nonconformities than anywhere else in the audit. I'll ask to see the server room, and half the time there's a case of bottled water someone's storing on top of a UPS. It's a five-minute fix, but it tells me nobody's actually looking." — Marcus Webb, Facilities & Physical Security Manager, Alderney Mutual Insurance

Equipment siting also has to account for growth. A comms closet sized correctly for the network in year one is routinely repurposed as general storage by year three once a new switch stack goes in a different room — and the labeling, environmental monitoring, and access list rarely follow it. Build a review of equipment locations into your annual asset management inventory refresh rather than treating 7.8 as a one-time site survey.

Control 7.9: Security of assets off-premises

Control 7.9 is where Priya's incident actually lives. Once equipment or the data it carries leaves a building you control, every environmental and access assumption behind 7.8 disappears. ISO 27002:2022 requires equivalent protection for off-site assets, and explicitly extends that to laptops, phones, removable media, and equipment used for home or remote working, field service, and business travel.

The practical challenge is that "off-premises" isn't one scenario — it's at least four, each with a different risk profile: the laptop that goes home every night, the laptop that goes to a client site or conference, the field technician's ruggedized tablet that lives in a vehicle, and the home-office setup that's effectively a permanent secondary site under the remote working provisions. Each needs the same underlying protections — encryption, tracking, and an approval trail — but the controls have to flex for how the device is actually used.

Requirement

What good looks like

Evidence an auditor accepts

Authorization to remove equipment

Formal approval before equipment leaves the premises, tied to the asset register

Equipment removal log or MDM enrollment record showing approver and date

Equivalent protection off-site

Same encryption, patching, and endpoint protection standard applied regardless of location

Configuration baseline report; MDM compliance dashboard

Physical protection while traveling

Guidance on not leaving devices unattended, in checked baggage, or visible in vehicles

Travel security guidance issued to staff; signed acknowledgment

Loss/theft reporting

Clear, fast reporting path feeding into incident management

Incident tickets showing time-to-report and time-to-remote-wipe

Insurance/liability coverage

Off-site equipment covered under corporate insurance, not left to the employee

Insurance policy schedule referencing IT equipment off-premises

The single highest-leverage control in this whole cluster is full-disk encryption on every device that can leave the building, enforced and verified centrally — not "enabled by default and never checked." Alderney's post-incident review found the encryption rollout dashboard had been reporting "94% compliant" for months; nobody had drilled into which 6% and why. A stale exception list is functionally the same as no policy.

Off-premises and remote asset control table

Asset type

Encryption requirement

Tracking/inventory control

Travel-specific control

Corporate laptop

Full-disk encryption, centrally managed keys

MDM-enrolled, asset-tagged, tied to named user

Never left unattended in vehicles; hotel safe or carried

Mobile phone

Device encryption + remote wipe capability

MDM-enrolled, linked to identity management

Screen lock + biometric required before travel

Removable media (in transit)

Encrypted container or hardware-encrypted drive

Logged out/in against media register

Hand-carried only for classified data; no checked baggage

Field service tablet/rugged device

Full-disk encryption, offline-capable

Fleet inventory with asset tracking

Secured mount in vehicle; end-of-shift check-in

Home office workstation/monitor setup

Same corporate endpoint build as office device

Recorded in asset register as "home deployed"

Home network security baseline (separate SSID, no shared use)

"We stopped treating remote work as an edge case years ago — it's the default deployment model now. The mistake I still see is companies writing a beautiful remote-work security policy and then never checking whether the laptops actually match the policy. Encryption status has to be something you can pull a report on, not something you assume." — Renata Osei, Director of IT Operations, Kestrel Dynamics Manufacturing

Off-premises assets also intersect with asset management — specifically return of assets — and with access control, since a stolen device is only as dangerous as the access rights and cached credentials it carries. When an employee leaves or a contract ends, the off-boarding checklist has to reconcile against the off-premises asset register, not just the badge system — a gap that shows up constantly in internal audits of fast-growing companies.

Control 7.10: Storage media

Storage media control covers the full lifecycle of removable and portable media — USB drives, external hard disks, backup tapes, SD cards, and in some organizations' scope definitions, printed output — from acquisition through use, transport, storage, and disposal. ISO 27002:2022 ties the required protection level to the classification of the information the media holds, which means 7.10 can't be written as a single blanket rule; it has to flex by classification the same way your asset management and information classification scheme does.

Media control is also one of the more common areas where an organization's controls look fine on paper and fail in practice, because removable media is cheap, small, and easy to acquire outside official channels. An employee who needs to move a 20GB file to a client uses whatever USB stick is in the desk drawer, not the encrypted one IT issued eighteen months ago that's since been lost.

Requirement

What good looks like

Evidence an auditor accepts

Media inventory

All corporate-issued removable media logged and tracked to an owner

Media register with serial numbers, custodians, and classification handled

Encryption by classification

Hardware or software encryption required for media carrying confidential/restricted data

Procurement standard requiring encrypted media; sample device check

Approved acquisition channel

Only IT-procured, approved media permitted; personal USB drives blocked or restricted

Endpoint policy (USB port control/DLP configuration)

Secure transport

Media transported between sites via controlled courier or encrypted transfer, not personal carry-on for sensitive data

Courier/chain-of-custody log for physical media transfers

Secure storage when not in use

Media stored in locked cabinets/safes when not actively in use

Facilities inspection log; storage cabinet access list

Secure disposal/reuse

Media wiped or destroyed per classification before reuse or disposal

Certificate of destruction; degaussing/shredding vendor log

"Tape media is the one people forget about because it feels like a legacy problem. We still found four unencrypted backup tapes in a courier bag that had been sitting in a supply closet for over a year, unaccounted for in any register. If it can hold data and it can walk out the door, it needs an owner and a log entry." — Tom Halvorsen, Records & Information Governance Lead, Bramwell & Voss LLP

Removable media policy table

Media type

Default classification handling

Encryption

Retention/reuse rule

Corporate-issued USB drive

Confidential unless labeled otherwise

Hardware-encrypted (FIPS-validated where required)

Reissued only after certified wipe; logged in media register

External backup/portable hard disk

Restricted (bulk data)

Full-disk encryption mandatory

Rotated per backup schedule; retired disks physically destroyed

Backup tape (on-site/off-site rotation)

Restricted

Encrypted at write time

Chain-of-custody log for every off-site movement; retention aligned to information backup schedule (control 8.13)

SD card/camera media (site surveys, field work)

Internal-use unless flagged

Encrypted container where feasible

Offloaded and wiped within 24 hours of field use

Personal/unmanaged removable media

Not permitted for corporate data

N/A — blocked at endpoint

Blocked via DLP/USB control policy; exceptions require written approval

Printed output containing classified data

Per document classification

N/A

Cross-cut shredding at end of life; no general recycling bin

This lifecycle discipline mirrors requirements security teams already recognize from other frameworks — PCI DSS's media handling and destruction requirements for cardholder data are built on the same "control it from issue to destruction" logic, even though the standards use different language to get there.

The information backup control referenced above (8.13, logged as a new article below) governs how backup media specifically is retained and tested; 7.10 governs how any removable media — backup or otherwise — is handled physically. Where you decommission media entirely, the process should hand off cleanly into information deletion (control 8.10) for the data, and secure disposal or re-use of equipment (control 7.14) for the physical device — a boundary worth drawing explicitly in your policy so nobody assumes "wiped" and "destroyed" mean the same evidence.

Control 7.11: Supporting utilities

Supporting utilities control addresses the infrastructure everything else depends on and almost nobody in security thinks about day to day: electrical power, HVAC, water supply, and telecommunications feeds. ISO 27002:2022 requires protecting equipment from power failures and other disruptions caused by failures in supporting utilities — which in plain terms means: don't let a blown transformer, a failed chiller, or a burst pipe take down information processing that the rest of your ISMS assumes is always available.

This control sits right next to business continuity and ICT readiness in terms of intent — control 5.30 is about your organization's ability to keep ICT services running through a disruption at a strategic and planning level; 7.11 is the physical infrastructure layer that makes that possible. You can have a beautifully documented ICT continuity plan and still lose a data hall because nobody tested the automatic transfer switch between utility power and the backup generator.

Requirement

What good looks like

Evidence an auditor accepts

Power redundancy

UPS coverage for all critical equipment; generator backup for extended outages

UPS runtime specification; generator maintenance/test log

Load testing

UPS and generator tested under load on a defined schedule

Test reports with dates, load percentages, and results

HVAC resilience

Redundant cooling (N+1 minimum) for server/comms rooms

HVAC maintenance contract and service records

Water/leak protection

Leak detection and water shut-off near critical equipment

Facilities inspection log; leak detection alert history

Utility monitoring

Real-time monitoring/alerting for power, temperature, humidity

Building management system (BMS) dashboard export

Single points of failure documented

Utility dependency map identifying single feeds/circuits

Risk register entry referencing utility SPOFs with treatment plan

Utilities and power resilience table

Element

Minimum baseline (small office)

Enterprise baseline (data center/critical site)

Test frequency

UPS

Covers safe shutdown window (15–30 min)

N+1 redundant UPS, sized for full load plus growth

Load-tested quarterly

Generator

Not always required

On-site diesel/gas generator with automatic transfer switch

Load-tested monthly; full-load test annually

HVAC

Standard office HVAC, temperature alarm

Redundant precision cooling, hot/cold aisle containment

Preventive maintenance quarterly

Water/fire

Smoke detection minimum

Water leak detection, clean-agent suppression, sub-floor sensors

Inspected per fire code plus annual test

Utility feed

Single utility feed acceptable

Dual utility feeds from separate substations where available

Reviewed annually in BC/DR test

Fuel supply (generator)

N/A

Contracted fuel resupply SLA (typically 24–72 hr runtime on-site)

Verified annually against contract

"The generator test that actually matters is the one where you cut utility power without warning and watch what happens, not the scheduled Tuesday-morning test everyone's standing around for. We found our transfer switch had a firmware issue that only showed up on an unplanned cutover — two years of clean scheduled tests had never caught it." — Chidi Nwosu, Data Center Facilities Engineer, Solace Health Partners

For most PentesterWorld readers who aren't running their own data center, 7.11 scopes down considerably — a UPS sized to give a clean shutdown window, a documented relationship with the facility's landlord or colocation provider covering their power/cooling SLAs, and evidence that you've actually read and mapped those SLAs against your recovery time objectives. Auditors calibrate expectations to your actual infrastructure; what they won't accept is silence — no UPS runtime spec, no test record, no idea what the colocation provider's power redundancy actually looks like. The same environmental and power-resilience thinking shows up in SOC 2 audits: the Availability trust services criteria examine essentially the same UPS, generator, and HVAC evidence auditors ask for under 7.11, so organizations pursuing both frameworks can usually reuse one evidence package for both.

Control 7.12: Cabling security

Cabling is the control most frequently skipped entirely in first-time ISMS builds, because it's invisible once installed and rarely fails in an obviously security-relevant way. ISO 27002:2022 requires power and telecommunications cabling carrying data or supporting information services to be protected from interception, interference, and damage. That covers three distinct threats: someone physically tapping a cable run, electromagnetic interference corrupting or exposing signal (particularly relevant for older unshielded runs near heavy electrical equipment), and simple physical damage — a cable run through a public ceiling void that a contractor nicks while running HVAC ductwork.

Requirement

What good looks like

Evidence an auditor accepts

Segregation of cable types

Power and data cabling run separately, with minimum separation distances observed

Cabling installation standard/as-built diagram

Protection from interception

Sensitive runs use conduit, locked cable trays, or shielded cable in shared/public spaces

Site inspection; cabling contractor completion certificate

Physical damage protection

Cabling routed away from high-traffic, high-risk areas; conduit used where exposed

Facilities walk-through; cable management standard

Labeling and documentation

Cable runs labeled and mapped, tied to a current network diagram

As-built cabling diagram, patch panel labeling scheme

Access to patch panels/distribution frames

Patch panels and main distribution frames in locked, access-controlled spaces

Access control list for comms rooms; patch panel photos

Periodic inspection

Scheduled inspection of exposed or externally routed cabling

Inspection log/maintenance ticket history

"Cabling security gets treated like an installation problem — something you solve once when the building's fitted out — instead of an ongoing control. I've walked into 'secure' comms rooms where the patch panel is locked but the cable tray running through the drop ceiling above the open-plan floor is completely exposed, unlabeled, and running through space three different contractors have keys to." — Dana Kowalski, Network Infrastructure Manager, Ferrous Bank

The practical fix for most organizations isn't a full rewire — it's documentation and containment. Get an as-built cabling diagram if one doesn't exist (most commercial fit-outs have one from the original contractor; ask facilities before assuming you need a full re-survey), confirm sensitive runs pass through locked or conduit-protected paths rather than open ceiling voids in shared-tenant buildings, and fold periodic cabling inspection into the same walk-through you're already doing for equipment siting. For leased space and multi-tenant buildings, this is also where landlord and property-management responsibilities need to be explicit in the lease or service agreement — you can't control what you don't have access to inspect.

Control 7.13: Equipment maintenance

Equipment maintenance is deceptively broad in ISO 27002:2022's framing: equipment must be maintained correctly to ensure the availability, integrity, and confidentiality of information. Availability is the obvious one — a server that fails because a fan filter was never cleaned is an availability incident. Integrity and confidentiality are less obvious but just as real: a third-party maintenance technician with unsupervised access to a device that still has cached credentials or unencrypted data on it is a confidentiality risk dressed up as a routine service call.

This control covers scheduled preventive maintenance, break-fix repairs, vendor and manufacturer service visits, and the decision points around when equipment gets patched, repaired, or retired. It's also one of the more evidence-rich controls to demonstrate, because maintenance activity naturally generates records — the challenge is usually consolidating scattered vendor tickets and warranty paperwork into something an auditor can actually review in one sitting.

Requirement

What good looks like

Evidence an auditor accepts

Maintenance schedule

Documented preventive maintenance schedule by equipment type/criticality

Maintenance calendar/CMMS export with completed vs. scheduled

Authorized maintenance personnel

Only approved internal staff or vetted vendors perform maintenance

Approved vendor list; NDA/contract on file

Supervision of external technicians

Vendor technicians escorted/logged in sensitive areas

Visitor/escort log cross-referenced to maintenance tickets

Data protection during maintenance

Data sanitized or encrypted before equipment leaves custody for repair

Data removal/encryption confirmation prior to RMA/repair shipment

Maintenance records retained

Records of all maintenance activity, including remedial/emergency work

Maintenance log with date, technician, work performed, parts used

Manufacturer recommendations followed

Maintenance intervals follow manufacturer/vendor specification

Vendor maintenance contract referencing specified intervals

Warranty and support tracking

Equipment tracked against warranty/support expiry to avoid unsupported gaps

Asset register field for warranty/support end date

Maintenance regime and records

Equipment category

Maintenance frequency

Who performs it

Record required

Server/network hardware (critical)

Per manufacturer spec, minimum quarterly review

Internal IT plus vendor support contract

Ticket/CMMS record, firmware/patch level noted

UPS/generator

Monthly visual, quarterly load test, annual full service

Certified electrical/facilities vendor

Signed service report retained 3+ years

HVAC (server/comms rooms)

Quarterly filter/service, annual full inspection

HVAC contractor

Service report; temperature log correlation

End-user laptops/desktops

As-needed break-fix; annual health check

Internal IT / authorized repair vendor

Repair ticket; data sanitization confirmation if off-site

Printers/copiers (with local storage)

Per manufacturer schedule

Vendor under service contract

Service log; confirmation of storage wipe at contract end

Physical security equipment (badge readers, CCTV)

Per manufacturer schedule, minimum semi-annual

Security systems vendor

Test/inspection log with functional confirmation

"The maintenance record most companies are missing isn't the routine stuff — it's proof of what happened when a vendor technician had physical access to a device that still had data on it. If you can't show me the device was sanitized, escorted, or under an NDA before it left your custody for repair, I have to treat that as an open confidentiality question, not a maintenance question." — Yusuf Rahman, Maintenance & Vendor Manager, Alderney Mutual Insurance

Maintenance also has a lifecycle dimension: equipment past its supportable maintenance window (end-of-life hardware, unsupported firmware) is a growing and frequently underweighted risk. If your asset register doesn't flag warranty and support expiry dates, you'll find out equipment is unmaintainable at the worst possible moment — during an incident, not during a planning cycle.

The equipment lifecycle, end to end

Controls 7.8 through 7.13 aren't six independent checklists — they're checkpoints along a single asset lifecycle that starts at procurement and ends at disposal. Mapping them this way is also the fastest way to explain the cluster to an auditor or a skeptical budget owner: each control owns a specific stage, and gaps between stages — not within a single control — are where most real incidents originate. That's exactly what happened to Priya's stolen laptop, which fell through the crack between "asset provisioned" and "off-premises use approved."

Read left to right: equipment is procured, sited and protected under 7.8, then enters an operate-and-maintain loop under 7.13 that depends on the utilities (7.11) and cabling (7.12) around it staying healthy. Any time that equipment or its media leaves the building, 7.9 and 7.10 take over protection, then the asset returns to the maintain loop or proceeds to disposal. Control 7.14 — secure disposal or re-use of equipment — sits just outside this article's scope but is the natural next read once you've got 7.8–7.13 in place.

Roles and responsibilities across 7.8–7.13

No single role owns all six controls, and pretending otherwise is how gaps open up between IT, facilities, and records management. A typical RACI split:

Activity

Facilities

IT Operations

Security/Compliance

Records Management

Equipment siting decisions (7.8)

Responsible

Consulted

Accountable

Informed

Off-premises asset policy (7.9)

Informed

Responsible

Accountable

Informed

Media register and handling (7.10)

Informed

Consulted

Accountable

Responsible

UPS/generator/HVAC (7.11)

Responsible

Consulted

Accountable

Informed

Cabling security (7.12)

Responsible

Responsible

Accountable

Informed

Maintenance scheduling and records (7.13)

Consulted

Responsible

Accountable

Informed

Security or compliance typically holds accountability for the control existing and being evidenced, without necessarily performing the day-to-day work — that stays with facilities, IT operations, or records management depending on the control. Write this split into your ISMS roles documentation explicitly; "everyone assumes someone else logs the UPS test" is a more common finding than any single technical gap in this cluster.

Implementation roadmap: sequencing 7.8–7.13

Organizations building this cluster from zero rarely need to do all six simultaneously. A practical sequencing, drawn from how most PentesterWorld clients actually get through it:

Phase

Focus

Typical duration

Key output

1

Inventory and risk baseline

2–4 weeks

Asset register updated with location, classification, off-premises status

2

Off-premises and media policy (7.9, 7.10)

3–5 weeks

Policies published; encryption/MDM compliance verified, not assumed

3

Equipment siting and cabling review (7.8, 7.12)

3–6 weeks

Site walk-throughs completed; as-built cabling diagram obtained or created

4

Utilities resilience (7.11)

4–8 weeks

UPS/generator test schedule established; provider SLAs mapped

5

Maintenance regime (7.13)

Ongoing from month 2

Maintenance calendar/CMMS live; vendor sanitization checkpoint added

6

Evidence consolidation and internal audit dry run

2 weeks

Evidence pack assembled per control, ready for Stage 1/2 or surveillance

Phases 2 and 5 tend to run longest in practice because they depend on behavior change — people actually logging media, vendors actually following a new sanitization step — rather than a one-time technical fix. Budget extra follow-up time there rather than treating "policy published" as "control implemented."

Common mistakes I see across 7.8–7.13

After walking this cluster of controls through dozens of certification and surveillance audits, the failure patterns repeat more than people expect:

  • Treating "off-premises" as an edge case. Once more than a handful of staff work remotely or travel regularly, off-premises is the default operating mode, not the exception — and the policy needs to be written that way, not bolted on as a footnote to an office-centric security policy.

  • Encryption dashboards nobody drills into. A "94% compliant" MDM report feels reassuring until you ask what's in the 6% and why it's been there for eight months.

  • No media register, or one that's stopped being updated. Media registers decay fast because issuing media is a five-second favor and logging it is a separate step people skip under deadline pressure.

  • UPS and generator tests that are too gentle to find real problems. A scheduled, announced test rarely replicates the failure conditions of a real outage — Chidi Nwosu's unplanned-cutover example above is the pattern to copy.

  • Cabling assumed "someone else's problem" in leased space. Multi-tenant buildings blur responsibility for cable pathway security; without an explicit clause in the lease or facilities agreement, nobody owns it.

  • Maintenance vendor access with no data sanitization step. Sending a failed drive back under warranty without first destroying or sanitizing it is one of the most common — and most avoidable — confidentiality gaps in this whole cluster.

  • Asset registers that don't track warranty/support expiry. Equipment quietly becomes unsupported and unpatchable, and nobody notices until an incident forces the question.

Mistake

Why it happens

Fastest fix

Off-premises policy written as an exception, not the default

Legacy office-centric security thinking

Rewrite policy assuming remote/travel use is normal, not exceptional

Stale encryption compliance dashboard

Nobody owns investigating the non-compliant tail

Assign named owner to chase every exception weekly until closed

Media register not maintained

Issuing is fast; logging is a separate, skippable step

Bundle logging into the issuance workflow (e.g., ticketing system) itself

UPS/generator tests too predictable

Scheduled, low-stress test windows

Run at least one unannounced load-shed test annually

Cabling pathway ownership unclear in leased space

No explicit lease clause

Add cabling/pathway security responsibility to lease or facilities SLA

No sanitization step before vendor repair/RMA

Treated as a logistics task, not a security task

Add mandatory sanitization checkpoint to the RMA/repair workflow

Warranty/support expiry untracked

Asset register missing the field

Add warranty/support-end date as a mandatory asset register field

Audit evidence checklist across the cluster

Control

Minimum evidence to have ready before an audit

7.8

Site risk assessment, room access list, environmental monitoring export

7.9

Off-premises authorization log, MDM/encryption compliance report, travel security guidance

7.10

Media register, encryption confirmation, chain-of-custody logs, destruction certificates

7.11

UPS/generator test reports, HVAC service records, utility single-point-of-failure risk register entry

7.12

As-built cabling diagram, comms room access list, cabling inspection log

7.13

Maintenance calendar/CMMS export, vendor NDA/contract, data sanitization confirmations

Keep these six evidence sets in a single, clearly labeled folder structure mapped to control numbers — auditors move faster, ask fewer clarifying questions, and form a better impression of your ISMS maturity when evidence retrieval doesn't require five people and three systems to assemble on the spot.

Case study: the laptop that never made the encryption rollout

Alderney Mutual Insurance's $2.4 million lesson, introduced at the top of this article, became the forcing function for a full rebuild of controls 7.9 and 7.10. Within four months of the incident, Priya Anand's team had closed the encryption rollout gap entirely, moving from "94% compliant, unverified" to 100% verified full-disk encryption with automated weekly compliance reporting; implemented a formal off-premises equipment authorization workflow tied to the asset register, so no device leaves the building without a logged approval; and rebuilt the media register from scratch, reconciling it against procurement records to account for every removable drive issued in the prior three years. Fourteen were unaccounted for and presumed retired without a disposal record — each one became its own micro-investigation.

The regulatory settlement required an independent audit of remediation within twelve months. Alderney passed it, and used the same evidence package to sail through its next ISO 27001 surveillance audit with zero nonconformities against the physical controls theme — a notable turnaround for an organization that had, eleven months earlier, no documented equipment-siting standard at all. Priya's own framing of the turnaround, in a debrief with her audit committee, was blunt: the incident cost more than the entire three-year ISMS budget that preceded it, and every dollar of remediation was money that a properly resourced 7.9 and 7.10 implementation would have spent anyway — just without the forensic investigators and regulators watching.

Case study: the UPS that passed every test except the one that mattered

A regional healthcare network's data center — Solace Health Partners, where Chidi Nwosu leads facilities engineering — had passed eleven consecutive quarterly UPS load tests before a genuine utility outage during a summer storm took down primary power for fourteen minutes. The automatic transfer switch to backup generator failed to engage. Server infrastructure ran on UPS battery alone, which was sized for a clean shutdown window, not sustained operation, and began shedding non-critical load automatically at the nine-minute mark — including, briefly, one clinical scheduling system that clinicians needed during the outage window.

No patient data was lost or exposed, but the near-miss triggered a root-cause review that found the transfer switch firmware had a known defect requiring a manual override under certain fault conditions — a defect invisible to every scheduled test because scheduled tests didn't replicate the specific fault signature of the real outage. Solace's facilities team redesigned its test program around unannounced load-shed drills, upgraded the transfer switch firmware, and added the drill results as a standing agenda item in quarterly business continuity reviews tied to their broader ICT readiness planning. The estimated cost of the redesigned testing program was roughly $38,000 annually in vendor time and after-hours testing premiums — against an internal estimate that the near-miss, had it fully cascaded, would have cost several times that in a single clinical-system outage.

Case study: the media mishandling that surfaced during a routine audit

Bramwell & Voss, a mid-sized litigation support firm, discovered its exposure during what should have been a routine internal audit walk-through, not an incident. Tom Halvorsen's records governance team, preparing evidence for an ISO 27001 surveillance audit, went looking for the chain-of-custody log for a set of backup tapes rotated to off-site storage monthly. The log existed for the prior eighteen months — but four tapes from an eleven-month-old rotation cycle had no corresponding "received at off-site facility" confirmation. After two weeks of investigation involving the courier vendor and the off-site storage provider, the tapes were located, misfiled at the storage facility under an incorrect client code, unopened and with no evidence of unauthorized access.

No breach occurred, but the near-miss was treated as seriously as one internally, because it revealed the real gap: chain-of-custody confirmation had never been a hard gate, just an assumption that "the courier usually confirms." The firm rebuilt its removable media policy to require signed, time-stamped confirmation at every custody transfer point, with any unconfirmed transfer automatically escalating to records management within 24 hours rather than being caught, if at all, at the next audit cycle. The fix cost essentially nothing beyond a workflow change and roughly $6,000 in courier-side confirmation service fees annually — a rounding error next to what a genuine breach notification exercise across the firm's client base would have cost.

Turning equipment controls into a business advantage

It's tempting to file 7.8–7.13 under "facilities housekeeping" and move on to the controls that feel more strategically interesting. That's a mistake, and not just because auditors will find the gaps. Equipment and media controls are where physical security and information security visibly intersect for people outside the security team — the sales prospect touring your office, the client asking how their data is protected when your staff travel, the cyber-insurance underwriter pricing your policy after a site questionnaire. A well-run equipment protection program is one of the easiest parts of ISO 27001 to actually show someone, and showing it builds trust faster than describing a firewall rule ever will.

It's also cheaper to get right proactively than reactively. Every dollar figure in the case studies above — Alderney's $2.4 million, Solace's near-miss, Bramwell & Voss's near-breach — dwarfs the cost of the fix that would have prevented it. Encryption rollout verification, an unannounced UPS test, a chain-of-custody confirmation gate: none of these are expensive controls. They're controls that are easy to skip until the day they aren't.

If you're building or refreshing your Statement of Applicability, don't treat 7.8–7.13 as a box-ticking pass through six short Annex A sentences. Walk the actual site. Pull the actual encryption compliance report and look at the non-compliant tail. Ask facilities what the last unannounced generator test found. The gap between a paper policy and a real, evidenced control is exactly where these six controls tend to live — and it's exactly where an experienced auditor will look first.

For teams building this evidence base from scratch, PentesterWorld's Annex A — All 93 Controls at a Glance cheat sheet is a fast way to see where 7.8–7.13 sits against your full control set, and the ISO 27001 Mandatory Documents Checklist will confirm which policies from this article — equipment protection standard, off-premises asset policy, media handling policy — need to exist as named documents versus embedded procedure. If you're starting your equipment and media policies from a blank page, our Information Security Policy Template gives you a structured starting point, and the Complete ISO 27001 Implementation Guide eBook walks the full physical controls theme in sequence. Not sure where your current gaps sit across 7.8–7.13? Run our ISO 27001 Gap Analysis Tool against your current equipment, media, and utilities controls before your next internal audit — it's a faster way to find the "94% compliant, nobody checked the 6%" problem than waiting for an auditor to find it for you.

Frequently asked questions

Do controls 7.8–7.13 apply if we don't own our office building?

Yes. ISO 27001 doesn't care whether you lease, own, or colocate — it cares whether the risk is managed. In leased or colocation environments, you typically satisfy these controls through a combination of your own measures (asset registers, encryption, media policy) and contractual assurance from the landlord or provider (utilities SLAs, cabling pathway responsibility, physical access logs you can request).

How does 7.9 differ from control 6.7 on remote working?

Control 6.7 governs the broader remote-working arrangement — who's authorized to work remotely, under what conditions, covered in disciplinary process and remote working security. Control 7.9 governs the physical protection of the specific assets — laptops, phones, media — while they're off-premises, regardless of whether "off-premises" means a home office, a client site, or a conference hotel room. They're complementary, not overlapping.

Do we need a full data center-grade UPS and generator setup for a small office?

No. Auditors scale expectations to your actual infrastructure and risk profile. A small office with cloud-hosted infrastructure typically needs a UPS sized for a clean shutdown of on-site equipment plus documented understanding of your cloud or colocation provider's power resilience — not an on-site generator.

What counts as "storage media" under control 7.10?

Any removable or portable media capable of storing information — USB drives, external hard disks, backup tapes, SD/memory cards, CDs/DVDs, and in some interpretations, removable storage in cameras or recording equipment. Printed output is sometimes included depending on your organization's scope definition; state your interpretation explicitly in your media policy so there's no ambiguity during audit.

How is 7.10 different from control 7.14 on secure disposal?

Control 7.10 governs media throughout its active lifecycle — issuance, use, transport, storage. Control 7.14 (secure disposal or re-use of equipment) governs the end-of-life step specifically: sanitization, destruction, or secure re-use once equipment or media is retired. Your policy should draw an explicit handoff point between the two rather than leaving "who wipes what, when" ambiguous.

Does encryption satisfy control 7.9 on its own?

Encryption is necessary but not sufficient. Control 7.9 also expects an authorization trail for equipment leaving the premises, physical protection guidance (not leaving devices unattended, secure transport), loss/theft reporting integrated with incident management, and appropriate insurance coverage. An auditor who sees encryption alone, with no policy or process around it, will still raise a finding.

How often should equipment maintenance records be reviewed?

At minimum, align maintenance record review with your internal audit cycle (commonly annual) and your management review cycle. High-criticality infrastructure — UPS, generators, HVAC serving server rooms — warrants a quarterly review of test and service records so gaps surface before a surveillance audit, not during one.

Can a third-party colocation or cloud provider's controls cover 7.8, 7.11, and 7.12 for us?

Largely yes for infrastructure you don't physically control, provided you can produce assurance evidence — SOC 2 reports, ISO 27001 certificates, or contractual SLAs from the provider covering siting, utilities, and cabling. Your Statement of Applicability should note the control as applicable but satisfied via supplier assurance, referenced back to your supplier relationship security process, rather than duplicating controls you have no physical ability to implement yourself.

14

About the author

Cybersecurity Expert

Satish Kumar writes about cybersecurity, offensive security, and practical defense strategies on PentesterWorld.

Related Articles

Comments (0)

No comments yet. Be the first to share your thoughts!