c) where necessary and appropriate, assets should be recorded as being removed offsite and recorded when returned;
d) the identity, role and affiliation of anyone who handles or uses assets should be
documented and this documentation returned with the equipment, information or
software.
Spot checks, undertaken to detect unauthorized removal of assets, can also be performed to
detect unauthorized recording devices, weapons, etc., and to prevent their entry into and exit
from, the site. Such spot checks should be carried out in accordance with relevant legislation
and regulations.
Individuals should be made aware that spot checks are carried out, and the verifications should
only be performed with authorization appropriate for the legal and regulatory requirements.
(NL ISO/IEC, 2015)
11.6. Security of Equipment and Assets Off-Premises
Security should be applied to off-site assets taking into account the different risks of working
outside the organization’s premises.
The use of any information storing and processing equipment outside the organization’s
premises should be authorized by management. This applies to equipment owned by the
organization and that equipment owned privately and used on behalf of the organization.
The following guidelines should be considered for the protection of off-site equipment:
a) equipment and media taken off premises should not be left unattended in public
places;
b) manufacturers’ instructions for protecting equipment should be observed at all
times, e.g. protection against exposure to strong electromagnetic fields;
c) controls for off-premises locations, such as home-working, teleworking and
temporary sites should be determined by a risk assessment and suitable controls
applied as appropriate, e.g. lockable filing cabinets, clear desk policy, a ccess controls
for computers and secure communication with the office;
d) when off-premises equipment is transferred among different individuals or external
parties, a log should be maintained that defines the chain of custody for the
equipment including at least names and organizations of those who are responsible
for the equipment.
Risks, e.g. of damage, theft or eavesdropping, may vary considerably between locations and
should be taken into account in determining the most appropriate controls.
Lebanese National Security Policy Guidelines v1.7
Page
39 |