ISO/IEC 27001:2022 Annex A · Control 6.7
Remote Working: A Practical Implementation Guide
Protect information and services wherever personnel work outside controlled organizational premises.
This control concerns security measures for remote working locations and activities.
What should the control achieve?
- Remote-work scenarios and risks are assessed.
- Approved devices, access and communication methods are defined.
- Physical and privacy safeguards are understood.
- Support, monitoring and incident processes work remotely.
Step-by-step implementation
Define eligible scenarios
Cover home, coworking, travel, public locations and cross-border work.
Set device and access baseline
Use managed devices, encryption, screen lock, MFA, updates and secure remote access.
Protect the workspace
Address privacy, conversations, screens, paper, storage and visitors.
Control networks and sharing
Give rules for public Wi-Fi, hotspots, printing, file transfer and collaboration.
Support and report
Provide secure helpdesk verification and rapid lost-device or suspected-compromise reporting.
Review exceptions
Assess personal devices, foreign locations and accessibility needs.
What this could look like in practice
Remote staff use managed encrypted laptops with MFA and automatic updates. Confidential calls require a private setting and paper records are prohibited. Lost devices are reported through a 24/7 channel and can be remotely disabled.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Home setup | Worker completes security checklist and uses managed equipment. | Acknowledgement |
| Travel | High-risk location assessment adds privacy screen and reduced local data. | Travel approval |
| Lost device | User reports immediately; IT revokes sessions and initiates response. | Incident ticket |
| Remote support | Helpdesk verifies identity before privileged assistance. | Support record |
Implementation evidence
- Remote-working policy
- Risk assessments
- Device baseline
- Access configuration
- User guidance
- Exception approvals
- Lost-device records
- Remote support procedure
Useful metrics
- Remote devices compliant
- Lost devices reported within target
- Remote-access anomalies
- Expired remote-work exceptions
Common mistakes
- Assuming home is physically secure.
- Allowing unmanaged devices by default.
- Ignoring conversations and paper.
- Blocking work without approved alternatives.
- Forgetting cross-border legal and tax implications.
Questions an auditor may ask
- Which remote locations are permitted?
- What baseline applies to devices and access?
- How are lost devices handled?
- How are personal-device exceptions assessed?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.