1. Purpose
The purpose of this Remote Working Policy is to define security requirements for employees, contractors, consultants, and other authorized personnel who work remotely or access organizational information and systems outside the organization’s controlled office environment.
The policy is intended to protect organizational information, customer data, systems, applications, cloud infrastructure, and credentials while supporting secure and flexible remote working.
The policy addresses risks associated with:
- Home and remote networks
- Corporate laptops and mobile devices
- Public Wi-Fi
- Remote access to business applications
- Cloud and SaaS services
- Confidential and customer information
- Physical security outside the office
- Lost or stolen devices
- Unauthorized access
- Remote working from third-party or public locations
2. Scope
This policy applies to:
- Employees
- Contractors and consultants
- Interns and temporary staff
- Remote and hybrid workers
- Third-party personnel with authorized remote access
It applies to remote use of:
- Company laptops and desktops
- Mobile devices
- Corporate applications
- SaaS applications
- Cloud infrastructure
- Email and collaboration platforms
- Source-code repositories
- Customer systems
- Corporate networks
- VPN or other remote-access solutions
- Organizational information and data
3. Remote Working Security Principles
Remote working shall follow these principles:
- Authorized access only – Remote access must be approved and provided only to authorized users.
- Least privilege – Users receive only the access required for their role.
- Strong authentication – MFA should be enabled for remote access and business-critical systems.
- Secure devices – Devices used for organizational work must have appropriate security controls.
- Secure networks – Users should avoid insecure or untrusted networks where practical.
- Information protection – Confidential and restricted information must be protected from unauthorized access or disclosure.
- Physical security – Devices and information must be protected in homes, hotels, coworking spaces, airports, and other remote locations.
- Secure communication – Approved corporate communication and collaboration tools should be used.
- Incident reporting – Loss, theft, suspected compromise, or accidental disclosure must be reported promptly.
- Compliance with organizational policies – Remote workers remain subject to all applicable information security policies.
4. Remote Working Authorization
Remote working may be permitted based on organizational requirements and role responsibilities.
Before providing remote access, the organization should consider:
- User role
- Information accessed
- System criticality
- Security risk
- Device security
- Authentication requirements
- Customer or contractual requirements
- Regulatory requirements
- Geographic restrictions, where applicable
Remote access to highly sensitive systems or production environments should require additional controls based on risk.
5. Corporate Devices
Where organizational devices are provided, users shall:
- Use company-approved devices for organizational work where required.
- Keep operating systems and applications updated.
- Use approved endpoint security controls.
- Enable device encryption where supported and required.
- Use screen lock when the device is unattended.
- Protect devices from unauthorized use.
- Avoid allowing family members or other unauthorized persons to use corporate devices.
- Report lost or stolen devices immediately.
- Not disable security controls without authorization.
Example:
An employee working from home must lock their corporate laptop whenever they leave the workspace, even if the laptop remains inside their home.
6. Personal Devices and BYOD
If personal devices are permitted for organizational activities, the organization should define minimum security requirements.
These may include:
- Supported operating system
- Current security updates
- Device encryption
- Screen lock
- MFA
- Approved applications
- Endpoint protection where appropriate
- Separation of business and personal information
- Ability to remove organizational information when employment or access ends
Personal devices should not be used to access highly sensitive systems unless specifically authorized and adequately protected.
7. Home Network Security
Remote workers should maintain reasonable security for their home network.
Where applicable:
- Use a properly configured wireless router.
- Use strong Wi-Fi authentication.
- Change default router credentials.
- Keep router firmware updated.
- Avoid sharing corporate access through unsecured networks.
- Separate work devices from untrusted devices where practical.
- Use organization-approved VPN or secure remote-access mechanisms where required.
The organization may provide additional technical requirements based on the sensitivity of information being accessed.
8. Public Wi-Fi and Untrusted Networks
Users should exercise caution when working from:
- Airports
- Hotels
- Cafés
- Restaurants
- Coworking spaces
- Public transportation
- Conference venues
- Other public locations
Users should:
- Avoid accessing sensitive information over unsecured networks where possible.
- Use approved secure connections.
- Use VPN where required by organizational security requirements.
- Avoid automatically connecting to unknown wireless networks.
- Confirm that the intended network is legitimate.
Highly sensitive activities should preferably be performed using trusted networks or approved secure access mechanisms.
9. Remote Access to Corporate Systems
Remote access must use approved authentication and access mechanisms.
Controls may include:
- MFA
- Single Sign-On
- VPN
- Zero Trust access mechanisms
- Device authentication
- Conditional access
- Role-based access
- Privileged access controls
- Session logging
- Access monitoring
Remote access privileges should be removed when no longer required.
10. Access to Production and Privileged Systems
Access to production environments and privileged systems from remote locations shall be risk-based and appropriately controlled.
Where applicable:
- Privileged accounts must use MFA.
- Administrative access should use dedicated privileged accounts.
- Production access should be limited to authorized personnel.
- Temporary or emergency access should be controlled and reviewed.
- Administrative activities should be logged.
- Access should be periodically reviewed.
- Direct access from unmanaged devices should be restricted where appropriate.
AWS SaaS Example
A developer working remotely may access AWS development resources through the organization’s identity provider with MFA.
Production administrative access may require:
SSO → MFA → Privileged Role → Temporary Access → CloudTrail Logging → Review
The developer should not use shared AWS root credentials or store AWS access keys in a personal device.
11. Information Protection
Remote workers must protect organizational information according to its classification.
Users shall:
- Access information only when authorized.
- Store information only in approved locations.
- Avoid downloading sensitive information unnecessarily.
- Use approved cloud storage and collaboration platforms.
- Avoid transferring confidential information through personal email or unauthorized applications.
- Prevent unauthorized persons from viewing screens or documents.
- Follow the organization’s Data Classification and Acceptable Use requirements.
12. Clean Desk and Clear Screen
Remote workers should maintain a secure working environment.
Users should:
- Lock screens when leaving the workstation.
- Avoid leaving confidential documents unattended.
- Secure printed documents.
- Dispose of sensitive documents securely.
- Position screens so unauthorized persons cannot easily view them.
- Avoid discussing confidential matters where conversations can be overheard.
This is particularly important when working from shared homes, hotels, coworking spaces, or public locations.
13. Printing and Physical Documents
Printing organizational information remotely should be minimized where practical.
Where printing is necessary:
- Use a secure printer.
- Do not leave confidential documents unattended.
- Store documents securely.
- Dispose of documents using an appropriate secure disposal method.
- Do not leave sensitive documents in public or shared printers.
14. Remote Meetings and Video Conferencing
Users shall use approved collaboration and meeting platforms.
For confidential meetings:
- Use meeting passwords or appropriate access controls.
- Do not publicly share meeting links.
- Verify participants where appropriate.
- Avoid discussing sensitive information in public locations.
- Use headphones where necessary.
- Do not record meetings unless authorized.
- Store recordings securely if recording is permitted.
15. Email and Communication
Remote workers must use approved corporate communication channels for business information.
Users should not:
- Forward confidential information to personal email.
- Use unauthorized messaging applications for sensitive business information.
- Share credentials through email or chat.
- Send customer information to unauthorized recipients.
Sensitive information should be shared using approved secure mechanisms.
16. Remote Working and Cloud/SaaS Applications
Access to cloud and SaaS applications must follow organizational access-control requirements.
The organization should maintain:
- Approved SaaS applications
- Application owners
- User access controls
- MFA
- Administrative access controls
- Supplier security assessments where applicable
- Access review processes
- Logging and monitoring
- Secure configuration requirements
Unapproved SaaS applications must not be used to store or process confidential organizational or customer information.
17. Remote Development Activities
Developers working remotely must follow the organization’s Secure Development requirements.
They shall:
- Use approved source-code repositories.
- Protect source code.
- Use MFA.
- Avoid storing credentials in source code.
- Use approved secrets-management mechanisms.
- Follow code-review requirements.
- Use approved development environments.
- Avoid downloading production data to personal devices.
- Follow production-access restrictions.
Example:
A developer may work remotely on application code using the approved Git repository, but customer production data should not be copied to the developer’s personal laptop for testing.
18. Mobile Working
When working from mobile devices:
- Use device authentication.
- Enable encryption where available.
- Use approved applications.
- Keep devices updated.
- Avoid storing sensitive information unnecessarily.
- Do not leave devices unattended.
- Report lost or stolen devices immediately.
19. Remote Working in Public Locations
Users working in public places should consider:
- Shoulder surfing
- Eavesdropping
- Theft
- Unsecured Wi-Fi
- Unauthorized photography
- Lost documents
- Device theft
- Conversations being overheard
Sensitive work should be performed in a private environment whenever practical.
20. International or Cross-Border Remote Working
Where employees intend to work remotely from another country or jurisdiction, organizational approval may be required.
The organization should consider:
- Data protection requirements
- Customer contractual restrictions
- Regulatory requirements
- Data transfer requirements
- Tax/employment considerations
- Access restrictions
- Security risks
- Customer commitments
Remote access from restricted or high-risk locations may require additional controls.
21. Remote Working Incident Reporting
Users must promptly report:
- Lost or stolen devices
- Suspected account compromise
- Malware infection
- Phishing attacks
- Accidental disclosure
- Unauthorized access
- Lost documents
- Suspicious login activity
- Security incidents involving home networks
- Exposure of credentials
- Unauthorized access to customer information
The incident should be handled according to the organization’s Security Incident Management Procedure and Incident Response Plan.
22. Remote Device Loss or Theft
When a corporate device is lost or stolen, the user should immediately notify the appropriate IT/security team.
The organization may:
- Disable the user account or sessions.
- Revoke active sessions.
- Revoke credentials or tokens.
- Remotely lock or wipe the device where supported.
- Assess the information stored or accessible.
- Review logs for suspicious activity.
- Determine whether an information security incident occurred.
- Perform required regulatory or contractual assessment.
- Document the incident and corrective actions.
23. Remote Working Monitoring
The organization may monitor security-relevant activities associated with remote access, subject to applicable law, organizational policies, and contractual requirements.
Monitoring may include:
- Authentication logs
- VPN activity
- Cloud access logs
- Endpoint security alerts
- Identity provider logs
- Privileged access activity
- Security alerts
- Data-loss prevention alerts where implemented
Monitoring should support security, investigation, compliance, and incident response.
24. Employee Responsibilities
Remote workers are responsible for:
- Protecting organizational information.
- Protecting credentials.
- Using approved devices and applications.
- Following access-control requirements.
- Maintaining reasonable physical security.
- Reporting security incidents promptly.
- Following information classification requirements.
- Completing required security awareness training.
- Complying with applicable organizational policies.
25. IT / Security Responsibilities
IT and Security should:
- Implement appropriate remote-access controls.
- Manage authentication and MFA.
- Secure corporate devices.
- Monitor security events where applicable.
- Manage endpoint security.
- Review remote-access privileges.
- Respond to security incidents.
- Support secure remote working.
- Periodically review remote-working risks and controls.
26. Access Review
Remote access should be reviewed periodically based on risk.
The review should consider:
- Active users
- Privileged users
- Remote-access permissions
- Dormant accounts
- Third-party access
- Users who changed roles
- Users who left the organization
- Access to production environments
- Access from unmanaged devices
Access that is no longer required should be removed promptly.
27. Remote Working Risk Assessment
The organization should assess risks associated with remote working as part of its information security risk management process.
Typical risks include:
| Risk | Example Control |
|---|---|
| Device theft | Encryption, screen lock, remote wipe |
| Public Wi-Fi compromise | VPN, secure access |
| Unauthorized family access | Screen lock, dedicated corporate device |
| Phishing | MFA, awareness training |
| Credential compromise | MFA, password controls |
| Data leakage | Classification, DLP, approved storage |
| Unauthorized production access | PAM, RBAC, MFA, logging |
| Lost documents | Secure storage and disposal |
| Shadow IT | SaaS approval and monitoring |
| Home network compromise | Secure Wi-Fi and endpoint controls |
The organization should determine actual risk based on its environment rather than adopting a generic risk list without assessment.
28. Evidence and Records
Evidence demonstrating implementation of this policy may include:
- Remote access policy
- Approved remote-access list
- VPN configuration
- MFA configuration
- Identity-provider logs
- Device inventory
- Endpoint security reports
- Encryption status
- Access reviews
- Privileged-access reviews
- Security awareness records
- Incident records
- Lost-device records
- Remote-working risk assessments
- SaaS application register
- Cloud access logs
- Employee acknowledgements
- Exception approvals
29. Policy Exceptions
Any exception to this policy should be:
- Documented.
- Risk assessed.
- Approved by the appropriate authority.
- Assigned an owner.
- Time-bound where practical.
- Reviewed periodically.
Exceptions should not become permanent alternatives to required security controls without appropriate risk consideration.
30. Review and Maintenance
This policy should be reviewed periodically and when significant changes occur, including:
- Major changes to remote-working arrangements
- New remote-access technologies
- Significant security incidents
- New regulatory or contractual requirements
- Major cloud or SaaS changes
- Changes to organizational structure
- Changes in information security risks
31. AWS SaaS Startup Example
Consider a 50-person SaaS company where employees work remotely.
A typical secure remote-working model could be:
Employee Laptop
↓
Device Encryption + Endpoint Security
↓
Identity Provider + MFA
↓
SSO / Secure Remote Access
↓
Approved SaaS Applications / AWS
↓
RBAC + Least Privilege + Logging
↓
Monitoring + Periodic Access Review
For production AWS access:
MFA → Privileged Role → Temporary Access → CloudTrail Logging → Security Monitoring → Periodic Review
For customer information:
Customer Data → Approved Application → Role-Based Access → Encryption → Logging → Backup → Monitoring
The objective is not to prevent remote work. The objective is to make remote work secure and controlled.
32. Relationship with Other ISMS Documents
The Remote Working Policy should work together with:
- Information Security Policy
- Acceptable Use Policy
- Employee IT Usage Policy
- Access Control Policy
- Asset Management Procedure
- Asset Classification Procedure
- Data Inventory
- Data Protection/Privacy Policy
- Security Awareness Policy
- Incident Response Plan
- Security Incident Management Procedure
- Business Continuity Plan
- Supplier Security Assessment
- Cloud Asset Inventory
- SaaS Application Register
- Risk Assessment and Risk Register
- Access Review Records
A useful relationship is:
Remote Working → Access → Device → Data → Risk → Security Controls → Monitoring → Incident Reporting → Review
33. Quick Audit Checklist
| Check | Status |
|---|---|
| Remote working requirements are documented | ☐ |
| Remote access is authorized | ☐ |
| MFA is implemented | ☐ |
| Corporate devices are identified | ☐ |
| Device encryption is enabled where required | ☐ |
| Endpoint protection is implemented | ☐ |
| Remote access is logged/monitored where appropriate | ☐ |
| Privileged remote access is restricted | ☐ |
| Production access is controlled | ☐ |
| Employees receive security awareness training | ☐ |
| Confidential information handling is defined | ☐ |
| Public Wi-Fi risks are addressed | ☐ |
| Lost/stolen device process exists | ☐ |
| Remote incident reporting is defined | ☐ |
| Remote access is periodically reviewed | ☐ |
| Exceptions are documented and approved | ☐ |
| Evidence is retained | ☐ |
| Policy is periodically reviewed | ☐ |
34. Startup-Friendly Implementation
A startup does not necessarily need a complicated remote-working technology stack.
A practical minimum model can be:
Corporate/Approved Device
→ Device Encryption
→ MFA
→ Approved SaaS/Cloud Applications
→ Least Privilege
→ Secure Remote Access
→ Logging & Monitoring
→ Periodic Access Review
→ Security Awareness
→ Incident Reporting
For a small SaaS company, existing tools such as the identity provider, endpoint-management platform, cloud security controls, MFA, logging platform, and approved SaaS applications can provide much of the required evidence.
The organization should implement controls proportionate to its risks rather than creating unnecessary remote-working documentation.
35. ISO 27001 Connection
Remote working is relevant to the organization’s information security risk management and applicable Annex A controls concerning areas such as:
- Information security policies
- Identity and access management
- Authentication
- Information classification
- Endpoint security
- Secure use of cloud services
- Remote working
- Information transfer
- Physical security
- Logging and monitoring
- Incident management
The organization should determine the controls necessary for its specific risks and document their applicability in the Statement of Applicability (SoA).
The policy itself is not sufficient evidence of implementation. Auditors may also look for operational evidence such as MFA configuration, device controls, access reviews, logs, training, incident records, and approved exceptions.
36. Final Principle
A secure remote-working program should follow:
Authorize → Authenticate → Secure Device → Protect Network → Protect Information → Control Access → Monitor → Report Incidents → Review → Improve
The goal is simple:
Work from anywhere, but protect organizational information everywhere.
