Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

N.1.08 Returning company assets after use

Control Overview

This control mandates that the organization establishes a structured offboarding procedure, supported by verifiable checklists, to ensure that all physical and digital assets (such as laptops, smartphones, key cards, and tokens) are recovered when an employee or temporary worker leaves the organization or changes roles. The primary objective is to eliminate the risk of post-employment data leaks or unauthorized system access caused by unrecovered hardware or active, stale user credentials.

note

Applicability Note: This control is fully applicable to the anDREa platform and governs all internal staff, contractors, and third-party departures.

Compliance & Strategic Approach

Our approach leverages the lifecycle controls embedded within our ISO/IEC 27001-based ISMS, treating offboarding not merely as an HR task, but as a critical technical security boundary.

When an employment contract ends or is modified, an automated offboarding ticket is generated to coordinate the physical and digital recovery processes. Physical devices are collected and verified against original usage and loan agreements. Simultaneously, digital assets are "returned" through immediate access revocation managed centrally via anDREa People HR and connected systems. To address modern working arrangements, our process explicitly requires users with authorized data access on personal devices to confirm and document the complete deletion of all anDREa-related data, creating a verifiable audit trail for every departure.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.05.11 - Return of assetsMandates that employees and external parties return all organizational assets in their possession upon termination of employment or contract.
Operational GovernanceOnboarding & Offboarding ProcessThe formal workflow used to track, execute, and verify the step-by-step return of physical equipment and data deletion.
Hardware RegistryEquipment Return ReceiptOriginal issuance receipts used during offboarding to reconcile and verify that all company-owned hardware is fully recovered.
Identity & Access ControlA.05.15 - Access controlThe central system record proving immediate de-provisioning of digital identities, corporate accounts, and environment permissions.
Data Separation RecordOnboarding & Offboarding ProcessDocumented affirmations retained within offboarding files verifying that any locally synchronized data on personal devices has been securely erased.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Physical return mechanisms, BYOD data clearing protocols, and digital access de-provisioning are fully automated and auditable. Continuous Improvement: Implementing a periodic internal sampling process of completed offboarding dossiers will further strengthen readiness for formal third-party audit cycles.