Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 6.7

Remote Working: A Practical Implementation Guide

Protect information and services wherever personnel work outside controlled organizational premises.

This control concerns security measures for remote working locations and activities.

Practical interpretation: Remote work changes physical, technical and human risks. Controls should cover devices, networks, conversations, paper, household access, travel, support and incident response without making work impractical.

What should the control achieve?

  • Remote-work scenarios and risks are assessed.
  • Approved devices, access and communication methods are defined.
  • Physical and privacy safeguards are understood.
  • Support, monitoring and incident processes work remotely.

Step-by-step implementation

1

Define eligible scenarios

Cover home, coworking, travel, public locations and cross-border work.

2

Set device and access baseline

Use managed devices, encryption, screen lock, MFA, updates and secure remote access.

3

Protect the workspace

Address privacy, conversations, screens, paper, storage and visitors.

4

Control networks and sharing

Give rules for public Wi-Fi, hotspots, printing, file transfer and collaboration.

5

Support and report

Provide secure helpdesk verification and rapid lost-device or suspected-compromise reporting.

6

Review exceptions

Assess personal devices, foreign locations and accessibility needs.

What this could look like in practice

Remote staff use managed encrypted laptops with MFA and automatic updates. Confidential calls require a private setting and paper records are prohibited. Lost devices are reported through a 24/7 channel and can be remotely disabled.

ActivityPractical implementationEvidence
Home setupWorker completes security checklist and uses managed equipment.Acknowledgement
TravelHigh-risk location assessment adds privacy screen and reduced local data.Travel approval
Lost deviceUser reports immediately; IT revokes sessions and initiates response.Incident ticket
Remote supportHelpdesk verifies identity before privileged assistance.Support record

Implementation evidence

  • Remote-working policy
  • Risk assessments
  • Device baseline
  • Access configuration
  • User guidance
  • Exception approvals
  • Lost-device records
  • Remote support procedure

Useful metrics

  • Remote devices compliant
  • Lost devices reported within target
  • Remote-access anomalies
  • Expired remote-work exceptions

Common mistakes

  • Assuming home is physically secure.
  • Allowing unmanaged devices by default.
  • Ignoring conversations and paper.
  • Blocking work without approved alternatives.
  • Forgetting cross-border legal and tax implications.

Questions an auditor may ask

  • Which remote locations are permitted?
  • What baseline applies to devices and access?
  • How are lost devices handled?
  • How are personal-device exceptions assessed?
Implementation test: Walk through a typical remote day and verify workspace, access, calls, file sharing, printing, support and incident reporting.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.