N.1.08 Returning company assets after use
Control Overview
This control mandates that the organization establishes a structured offboarding procedure, supported by verifiable checklists, to ensure that all physical and digital assets (such as laptops, smartphones, key cards, and tokens) are recovered when an employee or temporary worker leaves the organization or changes roles. The primary objective is to eliminate the risk of post-employment data leaks or unauthorized system access caused by unrecovered hardware or active, stale user credentials.
Applicability Note: This control is fully applicable to the anDREa platform and governs all internal staff, contractors, and third-party departures.
Compliance & Strategic Approach
Our approach leverages the lifecycle controls embedded within our ISO/IEC 27001-based ISMS, treating offboarding not merely as an HR task, but as a critical technical security boundary.
When an employment contract ends or is modified, an automated offboarding ticket is generated to coordinate the physical and digital recovery processes. Physical devices are collected and verified against original usage and loan agreements. Simultaneously, digital assets are "returned" through immediate access revocation managed centrally via anDREa People HR and connected systems. To address modern working arrangements, our process explicitly requires users with authorized data access on personal devices to confirm and document the complete deletion of all anDREa-related data, creating a verifiable audit trail for every departure.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.05.11 - Return of assets | Mandates that employees and external parties return all organizational assets in their possession upon termination of employment or contract. |
| Operational Governance | Onboarding & Offboarding Process | The formal workflow used to track, execute, and verify the step-by-step return of physical equipment and data deletion. |
| Hardware Registry | Equipment Return Receipt | Original issuance receipts used during offboarding to reconcile and verify that all company-owned hardware is fully recovered. |
| Identity & Access Control | A.05.15 - Access control | The central system record proving immediate de-provisioning of digital identities, corporate accounts, and environment permissions. |
| Data Separation Record | Onboarding & Offboarding Process | Documented affirmations retained within offboarding files verifying that any locally synchronized data on personal devices has been securely erased. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Physical return mechanisms, BYOD data clearing protocols, and digital access de-provisioning are fully automated and auditable. Continuous Improvement: Implementing a periodic internal sampling process of completed offboarding dossiers will further strengthen readiness for formal third-party audit cycles.