c) where necessary and appropriate, assets should be recorded as being removed offsite and recorded when returned; d) the identity, role and affiliation of anyone who handles or uses assets should be documented and this documentation returned with the equipment, information or software. Spot checks, undertaken to detect unauthorized removal of assets, can also be performed to detect unauthorized recording devices, weapons, etc., and to prevent their entry into and exit from, the site. Such spot checks should be carried out in accordance with relevant legislation and regulations. Individuals should be made aware that spot checks are carried out, and the verifications should only be performed with authorization appropriate for the legal and regulatory requirements. (NL ISO/IEC, 2015) 11.6. Security of Equipment and Assets Off-Premises Security should be applied to off-site assets taking into account the different risks of working outside the organization’s premises. The use of any information storing and processing equipment outside the organization’s premises should be authorized by management. This applies to equipment owned by the organization and that equipment owned privately and used on behalf of the organization. The following guidelines should be considered for the protection of off-site equipment: a) equipment and media taken off premises should not be left unattended in public places; b) manufacturers’ instructions for protecting equipment should be observed at all times, e.g. protection against exposure to strong electromagnetic fields; c) controls for off-premises locations, such as home-working, teleworking and temporary sites should be determined by a risk assessment and suitable controls applied as appropriate, e.g. lockable filing cabinets, clear desk policy, a ccess controls for computers and secure communication with the office; d) when off-premises equipment is transferred among different individuals or external parties, a log should be maintained that defines the chain of custody for the equipment including at least names and organizations of those who are responsible for the equipment. Risks, e.g. of damage, theft or eavesdropping, may vary considerably between locations and should be taken into account in determining the most appropriate controls. Lebanese National Security Policy Guidelines v1.7 Page 39 |

Select target paragraph3