ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 3. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 6.7 Remote working

ISO 27001 Annex A 6.7 Remote working

What is ISO 27001 Annex A 6.7 – Remote Working?

ISO 27001 Annex A 6.7 requires organizations to implement security measures when personnel work remotely.

Remote working means performing organizational work outside the organization’s controlled physical premises.

This can include:

  • Working from home
  • Working from a coworking space
  • Working from a customer location
  • Working while travelling
  • Working from hotels or temporary locations
  • Working from another office
  • Working internationally
  • Using company-managed or approved personal devices for remote work

The objective is to ensure that information remains protected even when employees are working outside the organization’s normal physical environment.

Simple Explanation

Security should not disappear when employees leave the office.

Remote work changes the security environment. The organization may no longer control the physical location, network, people nearby, or environmental conditions.

Therefore, additional or adapted security measures may be required.


Why is Annex A 6.7 Important?

When employees work remotely, company information may be accessed through:

  • Home Wi-Fi
  • Public Wi-Fi
  • Personal networks
  • Laptops
  • Mobile phones
  • Cloud applications
  • VPNs
  • Collaboration platforms
  • Remote administration tools
  • Video conferencing systems
  • Shared physical environments

This can introduce additional risks.

Common Remote Working Risks

  • Lost or stolen laptops
  • Shoulder surfing
  • Unsecured home Wi-Fi
  • Public Wi-Fi attacks
  • Unauthorized family or third-party access
  • Malware
  • Phishing
  • Device theft
  • Screen exposure
  • Printing confidential information at home
  • Use of unauthorized cloud storage
  • Local storage of sensitive information
  • Unapproved personal devices
  • Weak physical security
  • Insecure remote administration
  • Data leakage through personal applications

Simple Principle

The location may change, but the organization’s security requirements still apply.


What Does Annex A 6.7 Require?

The organization should establish and apply security measures for remote working.

The controls should be appropriate to:

  • The type of work being performed
  • Information being accessed
  • Devices being used
  • Business risks
  • Remote-working locations
  • Legal and regulatory requirements
  • Customer requirements
  • Organizational policies
  • Information classification

ISO 27001 does not require every organization to use the same remote-working controls.

A startup handling public marketing information may have different requirements from a fintech company processing sensitive financial information.


What is Remote Working Security?

Remote working security is the combination of:

People + Devices + Networks + Applications + Information + Physical Environment

For example:

An employee working from home may need:

  • MFA
  • Company-managed laptop
  • Disk encryption
  • Screen lock
  • Endpoint protection
  • Secure Wi-Fi
  • Approved applications
  • Secure cloud access
  • Security awareness
  • Incident reporting
  • Physical protection of the device
  • Restrictions on local storage

These measures work together.


Activities Required to Implement Annex A 6.7

Step 1: Define the Remote Working Policy

Create a practical policy explaining:

  • Who can work remotely
  • What devices may be used
  • How company information must be protected
  • Approved applications
  • Network requirements
  • Authentication requirements
  • Physical security expectations
  • Data storage requirements
  • Incident reporting
  • Use of public Wi-Fi
  • Printing requirements
  • Lost/stolen device reporting
  • Remote access requirements

The policy should be understandable to employees.


Step 2: Identify Remote Working Risks

Consider the organization’s actual environment.

For example:

RiskExamplePossible Control
Device theftLaptop stolen from hotelEncryption + screen lock + remote management
Public Wi-FiEmployee works from airportApproved secure connection / VPN where appropriate
Unauthorized accessFamily member uses laptopIndividual accounts + screen lock
PhishingEmployee receives fake MFA requestMFA + awareness training
Data leakageFiles copied to personal driveApproved storage + DLP where appropriate
Shoulder surfingSensitive information viewed in caféPrivacy precautions
MalwareEmployee installs unauthorized softwareEndpoint protection + application controls
Lost phoneMobile device lostDevice encryption + remote wipe where supported
Unauthorized applicationEmployee uploads files to personal AI/cloud serviceAcceptable use + approved tools + data handling rules

Step 3: Define Approved Devices

Decide what devices can be used for organizational work.

Possible models include:

Company-Owned Devices

The organization provides:

  • Laptop
  • Mobile device
  • Security software
  • Endpoint management
  • Encryption
  • Security configuration

BYOD

Employees use personal devices under defined security requirements.

If BYOD is permitted, the organization should consider:

  • Device security
  • Separation of company and personal information
  • Mobile/device management
  • Access restrictions
  • Data storage
  • Remote wipe
  • Privacy implications
  • Offboarding

Practical Startup Recommendation

For employees with access to sensitive information, a company-managed device model is often easier to control and demonstrate during an audit.


Step 4: Secure Remote Authentication

Remote access should use appropriate authentication controls.

Examples:

  • MFA
  • Strong authentication
  • SSO
  • Conditional access
  • Device-based controls
  • Privileged access controls
  • Risk-based authentication

For example:

Employee → SSO → MFA → Device Check → Application Access

Avoid relying only on a username and password for sensitive systems where stronger authentication is appropriate.


Step 5: Secure Devices

Remote-working devices should have appropriate security configurations.

Depending on risk, this may include:

  • Full-disk encryption
  • Endpoint protection
  • EDR
  • Automatic updates
  • Screen lock
  • Password/PIN
  • Secure configuration
  • Firewall
  • USB restrictions where appropriate
  • Device management
  • Remote lock/wipe
  • Restricted administrator privileges
  • Application control
  • Backup where appropriate

Step 6: Secure Remote Networks

Employees should understand how to use networks safely.

The organization can define requirements for:

  • Home Wi-Fi security
  • Router configuration
  • Public Wi-Fi
  • VPN
  • Secure remote access
  • Avoiding untrusted networks
  • Network segmentation where applicable

A common misconception is:

“Remote employee = VPN required.”

VPN is one possible control, not automatically the answer for every cloud-based startup.

If applications are securely delivered through SSO, MFA, conditional access, device controls, and secure cloud architecture, the organization may use a different remote-access model.

The control should match the risk.


Step 7: Protect Information in Remote Locations

Employees should understand how confidential information must be handled outside the office.

Examples:

  • Do not leave confidential documents unattended.
  • Do not store company information in unauthorized personal drives.
  • Do not share work devices with family members.
  • Do not use personal email for confidential company information.
  • Do not upload sensitive company information to unauthorized applications.
  • Secure printed documents.
  • Dispose of sensitive documents appropriately.
  • Avoid discussing confidential information in public areas.

Step 8: Protect Physical Security

Remote work is not only an IT issue.

Employees should protect:

  • Laptops
  • Mobile devices
  • Security keys
  • Printed documents
  • Storage media
  • Confidential conversations

For example, an employee working from a coffee shop should consider:

  • Screen visibility
  • Device theft
  • Nearby people
  • Public conversations
  • Unattended devices

Step 9: Define Incident Reporting

Employees should know what to do if something goes wrong.

Examples:

  • Laptop lost
  • Phone stolen
  • Suspicious login
  • Malware infection
  • Phishing
  • Accidental data disclosure
  • Unauthorized access
  • Lost security key
  • Compromised account

A simple process:

Incident Occurs → Report Immediately → Security Assessment → Containment → Investigation → Recovery

This connects A.6.7 with Annex A 5.24–5.28 and A.6.8.


Step 10: Provide Security Awareness Training

Employees should receive practical remote-working security guidance.

Training can cover:

  • Phishing
  • MFA
  • Password security
  • Device security
  • Public Wi-Fi
  • Physical security
  • Confidential information
  • Remote meetings
  • Screen sharing
  • Secure printing
  • Personal devices
  • Cloud storage
  • Lost device reporting
  • Remote-working incidents

This connects directly with A.6.3.


Startup Example

Consider a 50-person SaaS startup where most employees work remotely.

Employees access:

  • Google Workspace
  • GitHub
  • AWS
  • Slack
  • Jira
  • Customer support systems
  • HR systems

The startup establishes:

Remote Working Policy

↓

Company-Managed Laptop

↓

Full-Disk Encryption

↓

Endpoint Protection

↓

SSO + MFA

↓

Approved Cloud Applications

↓

Automatic Screen Lock

↓

Security Awareness Training

↓

Incident Reporting

↓

Periodic Security Review

An employee working from home can therefore access company systems without requiring the organization to control the employee’s entire home environment.

The objective is not to make the home identical to the office.

The objective is to implement appropriate controls around the people, devices, information, applications, and access paths used for remote work.


Example: Employee Working From a Café

Suppose an employee needs to work from a café.

The employee should consider:

  • Is confidential information visible on the screen?
  • Is the laptop physically protected?
  • Is the network trusted?
  • Is MFA enabled?
  • Are sensitive conversations being held publicly?
  • Is the laptop left unattended?
  • Are confidential documents being printed?
  • Is the employee using approved applications?

The organization’s policy should provide practical guidance rather than simply saying:

“Employees must work securely.”


Startup-Focused Quick Summary

A startup can implement A.6.7 with a relatively simple baseline.

Minimum Practical Model

1. Approved Device

Use a company-managed or appropriately secured device.

2. Strong Authentication

Use MFA for important systems.

3. Secure Configuration

Encryption, endpoint protection, updates, screen lock and appropriate device controls.

4. Approved Applications

Define where company information can be stored and processed.

5. Secure Network Access

Define acceptable use of home and public networks.

6. Physical Security

Protect laptops, phones, documents and screens.

7. Security Awareness

Train employees about remote-working risks.

8. Incident Reporting

Provide a simple mechanism to report lost devices, suspicious activity and data exposure.

9. Access Control

Apply least privilege and appropriate authentication.

10. Evidence

Maintain records demonstrating that the controls actually operate.


Remote Working Security Checklist

AreaExample Control
DeviceCompany-managed laptop
EncryptionFull-disk encryption
AuthenticationMFA
IdentitySSO
EndpointEDR/endpoint protection
UpdatesAutomatic patching
ScreenAutomatic lock
NetworkSecure home Wi-Fi
Public Wi-FiDefined security requirements
ApplicationsApproved applications
StorageApproved cloud storage
DataConfidentiality requirements
PhysicalDevice protection
TrainingRemote-working awareness
IncidentLost/stolen device reporting
AccessLeast privilege
MonitoringAppropriate security logging
OffboardingAccess/device removal

Remote Working Risk Assessment Example

A startup can maintain a simple risk assessment.

Remote Working RiskLikelihoodImpactControl
Laptop theftMediumHighEncryption + MDM + remote wipe
PhishingHighHighMFA + training
Public Wi-Fi exposureMediumMedium/HighSecure access controls
Family member accessing deviceMediumHighIndividual account + screen lock
Unauthorized cloud storageMediumHighApproved storage + policy
Shoulder surfingMediumMediumPrivacy awareness
Lost mobile deviceMediumMedium/HighDevice security + remote wipe
MalwareMediumHighEDR + patching
Unauthorized softwareMediumMediumEndpoint/application controls
Confidential discussion in publicLow/MediumHighAwareness + policy

The risk assessment should reflect the organization’s actual environment rather than being copied from another company.


Remote Working Policy – Key Topics

A practical Remote Working Policy can cover:

1. Purpose

Why remote working security requirements exist.

2. Scope

Who and what the policy applies to.

3. Approved Locations

Requirements for working from home, customer locations, coworking spaces, travel, etc.

4. Device Security

Requirements for company and personal devices.

5. Authentication

MFA, passwords, SSO and remote access.

6. Network Security

Home networks, public Wi-Fi and remote connectivity.

7. Information Handling

Storage, transmission, printing and disposal.

8. Physical Security

Protection of devices and information.

9. Remote Meetings

Secure meetings, screen sharing and confidential discussions.

10. Incident Reporting

How employees report security incidents.

11. Monitoring

Applicable security monitoring and logging.

12. Offboarding

Return of devices and removal of remote access.


Remote Working and BYOD

BYOD means Bring Your Own Device.

If a startup permits employees to use personal devices, additional questions should be considered:

  • Is encryption enabled?
  • Is the operating system supported?
  • Is the device patched?
  • Is endpoint protection required?
  • Can company information be downloaded?
  • Can company information be copied to personal applications?
  • Can company data be remotely removed?
  • How is access revoked when employment ends?
  • What happens to personal information on the device?
  • Can the organization monitor the device?
  • Are employees informed about privacy implications?

BYOD should therefore be treated as a deliberate risk decision rather than simply an employee convenience.


Remote Working and Cloud Services

Modern startups may have no traditional corporate network.

Employees may work entirely through:

  • Microsoft 365
  • Google Workspace
  • AWS
  • Azure
  • GitHub
  • Slack
  • Jira
  • Salesforce
  • Other SaaS applications

In such environments, remote-working security depends heavily on:

Identity + MFA + Device Security + Application Security + Data Protection

This means A.6.7 should work together with cloud and access controls rather than being implemented as a standalone “VPN policy.”


Remote Working During Travel

Employees travelling internationally or working from unfamiliar locations may face additional risks.

The organization should consider:

  • Device theft
  • Public networks
  • Border/customs exposure where relevant
  • Physical surveillance
  • Loss of devices
  • Different legal environments
  • International data transfer considerations
  • Restricted locations
  • Untrusted charging/accessories
  • Use of public computers

Employees handling highly sensitive information may require additional restrictions or controls.


Audit Evidence for Annex A 6.7

An auditor may request:

Policies

  • Remote Working Policy
  • Acceptable Use Policy
  • Information Security Policy
  • BYOD Policy, if applicable
  • Mobile Device Policy
  • Endpoint Security Policy
  • Access Control Policy

Procedures

  • Remote Access Procedure
  • Secure Remote Working Procedure
  • Lost/Stolen Device Procedure
  • BYOD Procedure
  • Incident Reporting Procedure
  • Device Offboarding Procedure

Technical Evidence

  • MFA configuration
  • SSO configuration
  • MDM/device management
  • Encryption status
  • Endpoint protection
  • EDR deployment
  • Patch status
  • Screen-lock configuration
  • Device inventory
  • Remote-wipe capability
  • Access-control configuration

Operational Evidence

  • Employee acknowledgements
  • Security awareness training
  • Remote-working training
  • Incident records
  • Lost-device records
  • Device assignment records
  • Access review records
  • BYOD approvals
  • Security exceptions

Audit Checklist for Annex A 6.7

Audit QuestionEvidence
Is remote working formally addressed?Remote Working Policy
Are remote-working risks identified?Risk assessment
Are approved devices defined?Device policy
Is MFA implemented?IAM evidence
Are devices encrypted?MDM/endpoint evidence
Is endpoint protection implemented?EDR evidence
Are devices patched?Patch records
Are screen locks enforced?Device configuration
Are remote access methods defined?Remote Access Procedure
Are public networks addressed?Remote Working Policy
Is BYOD addressed if permitted?BYOD Policy
Are confidential information requirements defined?Data handling policy
Are employees trained?Training records
Can employees report lost devices?Incident process
Are remote incidents tracked?Incident records
Are remote access rights removed during offboarding?JML/access records
Are exceptions documented?Exception register
Are controls periodically reviewed?Review records

Common Mistakes

1. Assuming VPN Automatically Means Secure

A VPN can protect certain network connections, but it does not solve:

  • Phishing
  • Stolen laptops
  • Weak passwords
  • Malware
  • Excessive access
  • Data leakage
  • Unauthorized cloud applications

Remote security requires multiple controls.


2. Having a Policy But No Technical Controls

A policy may say:

“Employees must encrypt company laptops.”

But the auditor may ask:

“How do you know encryption is actually enabled?”

Technical evidence is important.


3. Ignoring Physical Security

Remote security is not only cybersecurity.

A laptop containing customer information can be stolen from:

  • Home
  • Hotel
  • Airport
  • Café
  • Vehicle
  • Coworking space

4. Ignoring BYOD

If personal devices are allowed, the organization should explicitly determine the security requirements.

“Employees can use their own laptops” should not be an undocumented assumption.


5. Allowing Sensitive Information Through Personal Applications

Examples:

  • Personal Gmail
  • Personal Google Drive
  • Personal Dropbox
  • Personal messaging applications
  • Unapproved AI tools
  • Personal USB storage

The organization should define what is permitted.


6. No Lost Device Process

Employees should know exactly what to do if a laptop or phone is lost.

A fast response can reduce the potential impact.


7. No Remote Working Training

Employees may understand office security but make poor decisions when travelling or working remotely.

Remote-working awareness should be part of the security training program.


8. Treating Every Remote Worker the Same

A developer with production access and a marketing employee working only with public content may have very different risks.

Controls should be proportionate.


Practical Startup Implementation Model

A practical implementation model is:

Define

Define remote-working rules and scope.

Assess

Identify remote-working risks.

Secure

Secure devices, identity, applications and networks.

Restrict

Limit access according to business need.

Educate

Train employees about remote-working risks.

Monitor

Monitor relevant security events and device status.

Report

Provide a simple incident-reporting process.

Review

Review risks and controls periodically.

Improve

Update controls based on incidents, technology changes and business requirements.

Evidence

Maintain sufficient evidence to demonstrate implementation.


Policy vs. Process vs. Evidence

LayerExample
PolicyRemote work must be performed securely
ProcedureEmployees follow defined remote access and device-security procedures
Technical ControlMFA, encryption, EDR, MDM
ProcessLost/stolen device reporting
EvidenceMDM report showing encryption
EvidenceMFA configuration
EvidenceTraining completion
EvidenceIncident record
ReviewPeriodic review of remote-working risks

A strong ISO 27001 implementation connects all of these layers.


Relationship With Other ISO 27001 Controls

A.5.10 – Acceptable Use

Defines acceptable use of information and organizational assets.

A.5.15 – Access Control

Determines who can access systems and information remotely.

A.5.16 – Identity Management

Supports secure identity lifecycle management.

A.5.17 – Authentication Information

Protects authentication information.

A.5.18 – Access Rights

Ensures remote users receive appropriate permissions.

A.5.23 – Cloud Services

Important for startups using cloud-based applications remotely.

A.6.2 – Terms and Conditions of Employment

Employees should understand their security responsibilities.

A.6.3 – Awareness, Education and Training

Employees need training on remote-working risks.

A.6.5 – Responsibilities After Termination or Change of Employment

Remote access must be removed or modified when employment or roles change.

A.6.8 – Information Security Event Reporting

Employees need a way to report remote-working security events.

A.7.7 – Clear Desk and Clear Screen

Particularly relevant when employees work outside controlled offices.

A.8.1 – User Endpoint Devices

Provides important technical security measures for laptops and other endpoint devices.


A.6.7 vs. A.8.1

These controls are closely related but have different focuses.

ControlFocus
A.6.7 Remote WorkingSecurity requirements for working outside organizational premises
A.8.1 User Endpoint DevicesSecurity of endpoint devices themselves

For example:

A.6.7

An employee working from home must protect company information and use approved secure remote-working practices.

A.8.1

The laptop used by the employee must have appropriate endpoint security controls.

Together they provide a stronger control environment.


Questions an Auditor May Ask

“Do employees work remotely?”

Explain the organization’s actual working model.

“Show me your remote-working requirements.”

Provide the Remote Working Policy.

“How are employees trained?”

Show awareness and training records.

“How do you secure remote laptops?”

Demonstrate encryption, endpoint protection, patching, screen lock, MDM or other applicable controls.

“How do you protect remote access?”

Demonstrate MFA, SSO, conditional access, VPN or other applicable controls.

“What happens if a laptop is lost?”

Demonstrate the incident/lost-device process.

“Do employees use personal devices?”

Explain the organization’s BYOD position and controls.

“How do you prevent employees from sharing confidential information from home?”

Show information handling, acceptable use, access controls, training and technical controls where applicable.

“How do you handle remote access after an employee leaves?”

Demonstrate the joiner-mover-leaver and access revocation process.


Startup-Focused Final Takeaway

Remote working should not be treated as an exception to information security.

For a modern startup, the office may simply be one of many locations from which employees access organizational information.

A practical approach is:

Secure the person
→ Awareness and training

Secure the identity
→ SSO and MFA

Secure the device
→ Encryption, EDR, patching and device management

Secure the access
→ Least privilege and appropriate authentication

Secure the information
→ Classification, approved storage and data handling

Secure the environment
→ Physical and network security

Prepare for incidents
→ Clear reporting and response

Review continuously
→ Risk and control review

The key audit question is:

Can we demonstrate that employees can work remotely while maintaining appropriate protection of organizational information, systems, devices, and access?

For startups, the goal is not to recreate the office security environment at every employee’s home.

The goal is to build a risk-based remote-working security model that works with the way the company actually operates.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *