What is ISO 27001 Annex A 6.7 – Remote Working?
ISO 27001 Annex A 6.7 requires organizations to implement security measures when personnel work remotely.
Remote working means performing organizational work outside the organization’s controlled physical premises.
This can include:
- Working from home
- Working from a coworking space
- Working from a customer location
- Working while travelling
- Working from hotels or temporary locations
- Working from another office
- Working internationally
- Using company-managed or approved personal devices for remote work
The objective is to ensure that information remains protected even when employees are working outside the organization’s normal physical environment.
Simple Explanation
Security should not disappear when employees leave the office.
Remote work changes the security environment. The organization may no longer control the physical location, network, people nearby, or environmental conditions.
Therefore, additional or adapted security measures may be required.
Why is Annex A 6.7 Important?
When employees work remotely, company information may be accessed through:
- Home Wi-Fi
- Public Wi-Fi
- Personal networks
- Laptops
- Mobile phones
- Cloud applications
- VPNs
- Collaboration platforms
- Remote administration tools
- Video conferencing systems
- Shared physical environments
This can introduce additional risks.
Common Remote Working Risks
- Lost or stolen laptops
- Shoulder surfing
- Unsecured home Wi-Fi
- Public Wi-Fi attacks
- Unauthorized family or third-party access
- Malware
- Phishing
- Device theft
- Screen exposure
- Printing confidential information at home
- Use of unauthorized cloud storage
- Local storage of sensitive information
- Unapproved personal devices
- Weak physical security
- Insecure remote administration
- Data leakage through personal applications
Simple Principle
The location may change, but the organization’s security requirements still apply.
What Does Annex A 6.7 Require?
The organization should establish and apply security measures for remote working.
The controls should be appropriate to:
- The type of work being performed
- Information being accessed
- Devices being used
- Business risks
- Remote-working locations
- Legal and regulatory requirements
- Customer requirements
- Organizational policies
- Information classification
ISO 27001 does not require every organization to use the same remote-working controls.
A startup handling public marketing information may have different requirements from a fintech company processing sensitive financial information.
What is Remote Working Security?
Remote working security is the combination of:
People + Devices + Networks + Applications + Information + Physical Environment
For example:
An employee working from home may need:
- MFA
- Company-managed laptop
- Disk encryption
- Screen lock
- Endpoint protection
- Secure Wi-Fi
- Approved applications
- Secure cloud access
- Security awareness
- Incident reporting
- Physical protection of the device
- Restrictions on local storage
These measures work together.
Activities Required to Implement Annex A 6.7
Step 1: Define the Remote Working Policy
Create a practical policy explaining:
- Who can work remotely
- What devices may be used
- How company information must be protected
- Approved applications
- Network requirements
- Authentication requirements
- Physical security expectations
- Data storage requirements
- Incident reporting
- Use of public Wi-Fi
- Printing requirements
- Lost/stolen device reporting
- Remote access requirements
The policy should be understandable to employees.
Step 2: Identify Remote Working Risks
Consider the organization’s actual environment.
For example:
| Risk | Example | Possible Control |
|---|---|---|
| Device theft | Laptop stolen from hotel | Encryption + screen lock + remote management |
| Public Wi-Fi | Employee works from airport | Approved secure connection / VPN where appropriate |
| Unauthorized access | Family member uses laptop | Individual accounts + screen lock |
| Phishing | Employee receives fake MFA request | MFA + awareness training |
| Data leakage | Files copied to personal drive | Approved storage + DLP where appropriate |
| Shoulder surfing | Sensitive information viewed in café | Privacy precautions |
| Malware | Employee installs unauthorized software | Endpoint protection + application controls |
| Lost phone | Mobile device lost | Device encryption + remote wipe where supported |
| Unauthorized application | Employee uploads files to personal AI/cloud service | Acceptable use + approved tools + data handling rules |
Step 3: Define Approved Devices
Decide what devices can be used for organizational work.
Possible models include:
Company-Owned Devices
The organization provides:
- Laptop
- Mobile device
- Security software
- Endpoint management
- Encryption
- Security configuration
BYOD
Employees use personal devices under defined security requirements.
If BYOD is permitted, the organization should consider:
- Device security
- Separation of company and personal information
- Mobile/device management
- Access restrictions
- Data storage
- Remote wipe
- Privacy implications
- Offboarding
Practical Startup Recommendation
For employees with access to sensitive information, a company-managed device model is often easier to control and demonstrate during an audit.
Step 4: Secure Remote Authentication
Remote access should use appropriate authentication controls.
Examples:
- MFA
- Strong authentication
- SSO
- Conditional access
- Device-based controls
- Privileged access controls
- Risk-based authentication
For example:
Employee → SSO → MFA → Device Check → Application Access
Avoid relying only on a username and password for sensitive systems where stronger authentication is appropriate.
Step 5: Secure Devices
Remote-working devices should have appropriate security configurations.
Depending on risk, this may include:
- Full-disk encryption
- Endpoint protection
- EDR
- Automatic updates
- Screen lock
- Password/PIN
- Secure configuration
- Firewall
- USB restrictions where appropriate
- Device management
- Remote lock/wipe
- Restricted administrator privileges
- Application control
- Backup where appropriate
Step 6: Secure Remote Networks
Employees should understand how to use networks safely.
The organization can define requirements for:
- Home Wi-Fi security
- Router configuration
- Public Wi-Fi
- VPN
- Secure remote access
- Avoiding untrusted networks
- Network segmentation where applicable
A common misconception is:
“Remote employee = VPN required.”
VPN is one possible control, not automatically the answer for every cloud-based startup.
If applications are securely delivered through SSO, MFA, conditional access, device controls, and secure cloud architecture, the organization may use a different remote-access model.
The control should match the risk.
Step 7: Protect Information in Remote Locations
Employees should understand how confidential information must be handled outside the office.
Examples:
- Do not leave confidential documents unattended.
- Do not store company information in unauthorized personal drives.
- Do not share work devices with family members.
- Do not use personal email for confidential company information.
- Do not upload sensitive company information to unauthorized applications.
- Secure printed documents.
- Dispose of sensitive documents appropriately.
- Avoid discussing confidential information in public areas.
Step 8: Protect Physical Security
Remote work is not only an IT issue.
Employees should protect:
- Laptops
- Mobile devices
- Security keys
- Printed documents
- Storage media
- Confidential conversations
For example, an employee working from a coffee shop should consider:
- Screen visibility
- Device theft
- Nearby people
- Public conversations
- Unattended devices
Step 9: Define Incident Reporting
Employees should know what to do if something goes wrong.
Examples:
- Laptop lost
- Phone stolen
- Suspicious login
- Malware infection
- Phishing
- Accidental data disclosure
- Unauthorized access
- Lost security key
- Compromised account
A simple process:
Incident Occurs → Report Immediately → Security Assessment → Containment → Investigation → Recovery
This connects A.6.7 with Annex A 5.24–5.28 and A.6.8.
Step 10: Provide Security Awareness Training
Employees should receive practical remote-working security guidance.
Training can cover:
- Phishing
- MFA
- Password security
- Device security
- Public Wi-Fi
- Physical security
- Confidential information
- Remote meetings
- Screen sharing
- Secure printing
- Personal devices
- Cloud storage
- Lost device reporting
- Remote-working incidents
This connects directly with A.6.3.
Startup Example
Consider a 50-person SaaS startup where most employees work remotely.
Employees access:
- Google Workspace
- GitHub
- AWS
- Slack
- Jira
- Customer support systems
- HR systems
The startup establishes:
Remote Working Policy
↓
Company-Managed Laptop
↓
Full-Disk Encryption
↓
Endpoint Protection
↓
SSO + MFA
↓
Approved Cloud Applications
↓
Automatic Screen Lock
↓
Security Awareness Training
↓
Incident Reporting
↓
Periodic Security Review
An employee working from home can therefore access company systems without requiring the organization to control the employee’s entire home environment.
The objective is not to make the home identical to the office.
The objective is to implement appropriate controls around the people, devices, information, applications, and access paths used for remote work.
Example: Employee Working From a Café
Suppose an employee needs to work from a café.
The employee should consider:
- Is confidential information visible on the screen?
- Is the laptop physically protected?
- Is the network trusted?
- Is MFA enabled?
- Are sensitive conversations being held publicly?
- Is the laptop left unattended?
- Are confidential documents being printed?
- Is the employee using approved applications?
The organization’s policy should provide practical guidance rather than simply saying:
“Employees must work securely.”
Startup-Focused Quick Summary
A startup can implement A.6.7 with a relatively simple baseline.
Minimum Practical Model
1. Approved Device
Use a company-managed or appropriately secured device.
2. Strong Authentication
Use MFA for important systems.
3. Secure Configuration
Encryption, endpoint protection, updates, screen lock and appropriate device controls.
4. Approved Applications
Define where company information can be stored and processed.
5. Secure Network Access
Define acceptable use of home and public networks.
6. Physical Security
Protect laptops, phones, documents and screens.
7. Security Awareness
Train employees about remote-working risks.
8. Incident Reporting
Provide a simple mechanism to report lost devices, suspicious activity and data exposure.
9. Access Control
Apply least privilege and appropriate authentication.
10. Evidence
Maintain records demonstrating that the controls actually operate.
Remote Working Security Checklist
| Area | Example Control |
|---|---|
| Device | Company-managed laptop |
| Encryption | Full-disk encryption |
| Authentication | MFA |
| Identity | SSO |
| Endpoint | EDR/endpoint protection |
| Updates | Automatic patching |
| Screen | Automatic lock |
| Network | Secure home Wi-Fi |
| Public Wi-Fi | Defined security requirements |
| Applications | Approved applications |
| Storage | Approved cloud storage |
| Data | Confidentiality requirements |
| Physical | Device protection |
| Training | Remote-working awareness |
| Incident | Lost/stolen device reporting |
| Access | Least privilege |
| Monitoring | Appropriate security logging |
| Offboarding | Access/device removal |
Remote Working Risk Assessment Example
A startup can maintain a simple risk assessment.
| Remote Working Risk | Likelihood | Impact | Control |
|---|---|---|---|
| Laptop theft | Medium | High | Encryption + MDM + remote wipe |
| Phishing | High | High | MFA + training |
| Public Wi-Fi exposure | Medium | Medium/High | Secure access controls |
| Family member accessing device | Medium | High | Individual account + screen lock |
| Unauthorized cloud storage | Medium | High | Approved storage + policy |
| Shoulder surfing | Medium | Medium | Privacy awareness |
| Lost mobile device | Medium | Medium/High | Device security + remote wipe |
| Malware | Medium | High | EDR + patching |
| Unauthorized software | Medium | Medium | Endpoint/application controls |
| Confidential discussion in public | Low/Medium | High | Awareness + policy |
The risk assessment should reflect the organization’s actual environment rather than being copied from another company.
Remote Working Policy – Key Topics
A practical Remote Working Policy can cover:
1. Purpose
Why remote working security requirements exist.
2. Scope
Who and what the policy applies to.
3. Approved Locations
Requirements for working from home, customer locations, coworking spaces, travel, etc.
4. Device Security
Requirements for company and personal devices.
5. Authentication
MFA, passwords, SSO and remote access.
6. Network Security
Home networks, public Wi-Fi and remote connectivity.
7. Information Handling
Storage, transmission, printing and disposal.
8. Physical Security
Protection of devices and information.
9. Remote Meetings
Secure meetings, screen sharing and confidential discussions.
10. Incident Reporting
How employees report security incidents.
11. Monitoring
Applicable security monitoring and logging.
12. Offboarding
Return of devices and removal of remote access.
Remote Working and BYOD
BYOD means Bring Your Own Device.
If a startup permits employees to use personal devices, additional questions should be considered:
- Is encryption enabled?
- Is the operating system supported?
- Is the device patched?
- Is endpoint protection required?
- Can company information be downloaded?
- Can company information be copied to personal applications?
- Can company data be remotely removed?
- How is access revoked when employment ends?
- What happens to personal information on the device?
- Can the organization monitor the device?
- Are employees informed about privacy implications?
BYOD should therefore be treated as a deliberate risk decision rather than simply an employee convenience.
Remote Working and Cloud Services
Modern startups may have no traditional corporate network.
Employees may work entirely through:
- Microsoft 365
- Google Workspace
- AWS
- Azure
- GitHub
- Slack
- Jira
- Salesforce
- Other SaaS applications
In such environments, remote-working security depends heavily on:
Identity + MFA + Device Security + Application Security + Data Protection
This means A.6.7 should work together with cloud and access controls rather than being implemented as a standalone “VPN policy.”
Remote Working During Travel
Employees travelling internationally or working from unfamiliar locations may face additional risks.
The organization should consider:
- Device theft
- Public networks
- Border/customs exposure where relevant
- Physical surveillance
- Loss of devices
- Different legal environments
- International data transfer considerations
- Restricted locations
- Untrusted charging/accessories
- Use of public computers
Employees handling highly sensitive information may require additional restrictions or controls.
Audit Evidence for Annex A 6.7
An auditor may request:
Policies
- Remote Working Policy
- Acceptable Use Policy
- Information Security Policy
- BYOD Policy, if applicable
- Mobile Device Policy
- Endpoint Security Policy
- Access Control Policy
Procedures
- Remote Access Procedure
- Secure Remote Working Procedure
- Lost/Stolen Device Procedure
- BYOD Procedure
- Incident Reporting Procedure
- Device Offboarding Procedure
Technical Evidence
- MFA configuration
- SSO configuration
- MDM/device management
- Encryption status
- Endpoint protection
- EDR deployment
- Patch status
- Screen-lock configuration
- Device inventory
- Remote-wipe capability
- Access-control configuration
Operational Evidence
- Employee acknowledgements
- Security awareness training
- Remote-working training
- Incident records
- Lost-device records
- Device assignment records
- Access review records
- BYOD approvals
- Security exceptions
Audit Checklist for Annex A 6.7
| Audit Question | Evidence |
|---|---|
| Is remote working formally addressed? | Remote Working Policy |
| Are remote-working risks identified? | Risk assessment |
| Are approved devices defined? | Device policy |
| Is MFA implemented? | IAM evidence |
| Are devices encrypted? | MDM/endpoint evidence |
| Is endpoint protection implemented? | EDR evidence |
| Are devices patched? | Patch records |
| Are screen locks enforced? | Device configuration |
| Are remote access methods defined? | Remote Access Procedure |
| Are public networks addressed? | Remote Working Policy |
| Is BYOD addressed if permitted? | BYOD Policy |
| Are confidential information requirements defined? | Data handling policy |
| Are employees trained? | Training records |
| Can employees report lost devices? | Incident process |
| Are remote incidents tracked? | Incident records |
| Are remote access rights removed during offboarding? | JML/access records |
| Are exceptions documented? | Exception register |
| Are controls periodically reviewed? | Review records |
Common Mistakes
1. Assuming VPN Automatically Means Secure
A VPN can protect certain network connections, but it does not solve:
- Phishing
- Stolen laptops
- Weak passwords
- Malware
- Excessive access
- Data leakage
- Unauthorized cloud applications
Remote security requires multiple controls.
2. Having a Policy But No Technical Controls
A policy may say:
“Employees must encrypt company laptops.”
But the auditor may ask:
“How do you know encryption is actually enabled?”
Technical evidence is important.
3. Ignoring Physical Security
Remote security is not only cybersecurity.
A laptop containing customer information can be stolen from:
- Home
- Hotel
- Airport
- Café
- Vehicle
- Coworking space
4. Ignoring BYOD
If personal devices are allowed, the organization should explicitly determine the security requirements.
“Employees can use their own laptops” should not be an undocumented assumption.
5. Allowing Sensitive Information Through Personal Applications
Examples:
- Personal Gmail
- Personal Google Drive
- Personal Dropbox
- Personal messaging applications
- Unapproved AI tools
- Personal USB storage
The organization should define what is permitted.
6. No Lost Device Process
Employees should know exactly what to do if a laptop or phone is lost.
A fast response can reduce the potential impact.
7. No Remote Working Training
Employees may understand office security but make poor decisions when travelling or working remotely.
Remote-working awareness should be part of the security training program.
8. Treating Every Remote Worker the Same
A developer with production access and a marketing employee working only with public content may have very different risks.
Controls should be proportionate.
Practical Startup Implementation Model
A practical implementation model is:
Define
Define remote-working rules and scope.
Assess
Identify remote-working risks.
Secure
Secure devices, identity, applications and networks.
Restrict
Limit access according to business need.
Educate
Train employees about remote-working risks.
Monitor
Monitor relevant security events and device status.
Report
Provide a simple incident-reporting process.
Review
Review risks and controls periodically.
Improve
Update controls based on incidents, technology changes and business requirements.
Evidence
Maintain sufficient evidence to demonstrate implementation.
Policy vs. Process vs. Evidence
| Layer | Example |
|---|---|
| Policy | Remote work must be performed securely |
| Procedure | Employees follow defined remote access and device-security procedures |
| Technical Control | MFA, encryption, EDR, MDM |
| Process | Lost/stolen device reporting |
| Evidence | MDM report showing encryption |
| Evidence | MFA configuration |
| Evidence | Training completion |
| Evidence | Incident record |
| Review | Periodic review of remote-working risks |
A strong ISO 27001 implementation connects all of these layers.
Relationship With Other ISO 27001 Controls
A.5.10 – Acceptable Use
Defines acceptable use of information and organizational assets.
A.5.15 – Access Control
Determines who can access systems and information remotely.
A.5.16 – Identity Management
Supports secure identity lifecycle management.
A.5.17 – Authentication Information
Protects authentication information.
A.5.18 – Access Rights
Ensures remote users receive appropriate permissions.
A.5.23 – Cloud Services
Important for startups using cloud-based applications remotely.
A.6.2 – Terms and Conditions of Employment
Employees should understand their security responsibilities.
A.6.3 – Awareness, Education and Training
Employees need training on remote-working risks.
A.6.5 – Responsibilities After Termination or Change of Employment
Remote access must be removed or modified when employment or roles change.
A.6.8 – Information Security Event Reporting
Employees need a way to report remote-working security events.
A.7.7 – Clear Desk and Clear Screen
Particularly relevant when employees work outside controlled offices.
A.8.1 – User Endpoint Devices
Provides important technical security measures for laptops and other endpoint devices.
A.6.7 vs. A.8.1
These controls are closely related but have different focuses.
| Control | Focus |
|---|---|
| A.6.7 Remote Working | Security requirements for working outside organizational premises |
| A.8.1 User Endpoint Devices | Security of endpoint devices themselves |
For example:
A.6.7
An employee working from home must protect company information and use approved secure remote-working practices.
A.8.1
The laptop used by the employee must have appropriate endpoint security controls.
Together they provide a stronger control environment.
Questions an Auditor May Ask
“Do employees work remotely?”
Explain the organization’s actual working model.
“Show me your remote-working requirements.”
Provide the Remote Working Policy.
“How are employees trained?”
Show awareness and training records.
“How do you secure remote laptops?”
Demonstrate encryption, endpoint protection, patching, screen lock, MDM or other applicable controls.
“How do you protect remote access?”
Demonstrate MFA, SSO, conditional access, VPN or other applicable controls.
“What happens if a laptop is lost?”
Demonstrate the incident/lost-device process.
“Do employees use personal devices?”
Explain the organization’s BYOD position and controls.
“How do you prevent employees from sharing confidential information from home?”
Show information handling, acceptable use, access controls, training and technical controls where applicable.
“How do you handle remote access after an employee leaves?”
Demonstrate the joiner-mover-leaver and access revocation process.
Startup-Focused Final Takeaway
Remote working should not be treated as an exception to information security.
For a modern startup, the office may simply be one of many locations from which employees access organizational information.
A practical approach is:
Secure the person
→ Awareness and training
Secure the identity
→ SSO and MFA
Secure the device
→ Encryption, EDR, patching and device management
Secure the access
→ Least privilege and appropriate authentication
Secure the information
→ Classification, approved storage and data handling
Secure the environment
→ Physical and network security
Prepare for incidents
→ Clear reporting and response
Review continuously
→ Risk and control review
The key audit question is:
Can we demonstrate that employees can work remotely while maintaining appropriate protection of organizational information, systems, devices, and access?
For startups, the goal is not to recreate the office security environment at every employee’s home.
The goal is to build a risk-based remote-working security model that works with the way the company actually operates.
