ISO 27001 Annex A 6.7 Remote Working (The Unofficial Zero BS Guide)

ISO 27001 Annex A 6.7

ISO 27001 Annex A 6.7 Remote working requires organisations to implement clear security rules and controls for staff working outside the office. Storing these policies in a central document hub helps protect company data on remote devices and ensures strong compliance.

Key Takeaways

  • What is ISO 27001 Annex A 6.7? ISO 27001 Annex A 6.7 is an information security control that requires organisations to protect company data outside the main office.
  • Document clear remote work rules: Create simple, written policies for working from home and other off-site locations.
  • Provide central policy access: Store remote working security rules in a central document hub so all staff can easily find and read them.
  • Secure remote devices: Protect laptops, phones, and home devices with strong passwords, lock screens, and automatic updates.
  • Use secure connections: Require staff to access company systems and business tools through encrypted internet connections.
  • Safeguard company data: Keep sensitive files, customer details, and business records safe from theft, loss, and unauthorised access.
  • Train staff regularly: Teach team members how to spot risks, report security issues quickly, and follow safe habits outside the office.
  • Meet compliance standards: Following these clear steps helps small teams pass security audits and build trust with clients.

How to Implement ISO 27001 Annex A 6.7

  • Draft remote working rules: Write a clear remote work policy and store it in your central document repository.
  • Secure off-site devices: Require device lock screens, full disk encryption, and automatic security updates on all remote equipment.
  • Control system access: Use multi-factor authentication and encrypted network connections for staff accessing company tools from home.
  • Protect home workspaces: Require staff to use private work areas, follow clean desk habits, and shield screens from view.
  • Prevent data loss: Restrict the use of unapproved personal devices and ban the transfer of company files to personal storage.
  • Train remote staff: Teach workers how to spot phishing scams, use public networks safely, and report lost devices quickly.
  • Set incident response steps: Give off-site workers a fast, simple path to report security issues and stolen hardware immediately.
  • Review remote access logs: Check user login records and system access logs regularly to spot unusual remote activity.
  • Audit compliance regularly: Review your remote working controls annually to keep risk low and pass ISO 27001 audits.

When you’re ready to bring compliance into one place

High Table Compliance Platform powered by hicomply
High Table Compliance Platform powered by hicomply

How to Audit ISO 27001 Annex A 6.7

  • Review remote working policies: Check written rules to confirm clear guidance exists for working from home, teleworking, and travel.
  • Audit the remote asset register: Sample entries in the inventory log to verify all laptops and remote devices match real assets.
  • Verify device encryption settings: Inspect sample remote laptops and phones to ensure strong disk protection guards all stored data.
  • Check remote access controls: Confirm staff use multi-factor authentication and secure, encrypted connections to reach business systems.
  • Inspect physical workspace standards: Verify remote workers understand how to keep home offices secure, lock doors, and hide screens.
  • Review bring your own device rules: Check that personal devices used for work follow approved security controls and data isolation rules.
  • Verify patch and update management: Test sample remote computers to ensure automatic security updates and antivirus tools run on time.
  • Audit remote data handling habits: Confirm staff do not print sensitive files at home or transfer work records to personal storage.
  • Review remote offboarding steps: Check that managers revoke system access and retrieve remote hardware promptly when staff leave the company.
  • Inspect remote access logs: Review user login records and network connection logs to spot unusual off-site activity fast.
  • Review lost device incident logs: Inspect report tickets for missing remote hardware to confirm teams ran full risk checks and wiped drives fast.
  • Verify staff training records: Confirm employees complete regular security awareness training on remote working risks and clean desk rules.
  • Check public network safety controls: Verify staff use secure connections and avoid untrusted public Wi-Fi when working on the move.
  • Review communication tool guidelines: Check that teams use approved, secure channels for business calls, messaging, and video meetings.

Audit Evidence Checklist

  • Remote working policy: Maintain a documented remote working policy with a complete version history in your central document repository.
  • Remote asset register: Keep an active, up-to-date inventory list of all laptops, phones, and hardware issued to off-site staff.
  • Remote device encryption logs: Maintain audit records showing that all remote laptops and mobile devices carry active disk encryption.
  • Multi-factor authentication reports: Provide system records proving all remote workers use two-step login checks for cloud services.
  • Remote worker risk assessments: Produce signed review forms that assess the physical and digital safety of home work setups.
  • Secure connection logs: Keep network connection records showing that off-site workers route traffic through encrypted tunnels.
  • Incident reporting tickets: Supply support logs showing fast action taken for lost remote equipment or suspicious login alerts.
  • Staff training logs: Show sign-off sheets proving employees completed security awareness training on safe remote working habits.

What to Teach Employees

  • Encrypt all remote devices: Teach workers that all portable work hardware must carry full drive encryption before saving any business files.
  • Lock screens when stepping away: Instruct staff to lock computer screens and close laptops whenever they leave their home desk or workspace.
  • Never use unsecured public Wi-Fi: Warn employees never to connect work laptops to open public networks without an approved encrypted connection.
  • Keep work and personal tasks separate: Train workers never to let friends or family members use company devices for personal tasks.
  • Follow secure transit steps: Instruct staff to keep laptops in carry-on bags and never leave work gear unattended in cars or public places.
  • Prevent shoulder surfing: Remind workers to use privacy screen filters and sit with their backs to walls when working in public spaces.
  • Keep clear desk areas: Teach staff to clear desks of all confidential notes, client files, and paper printouts after the working day.
  • Use strong passwords and passphrases: Instruct team members to set unique, complex passwords alongside multi-factor authentication for every account.
  • Report missing devices fast: Ensure employees know to report lost or stolen laptops and phones immediately to trigger a remote data wipe.
  • Spot remote phishing scams: Remind staff to check sender details carefully and report fake emails or messages aimed at home workers.
  • Avoid personal storage items: Warn staff against saving company data to personal cloud drives, email inboxes, or unmanaged home drives.
  • Understand remote security rules: Train workers on how poor home security habits lead to data leaks, compliance fines, and business damage.

Common Implementation Challenges

  • Unapproved device usage: Staff use unmanaged home computers for work tasks. Enforce clear device policies and restrict access to approved hardware.
  • Incomplete asset registers: Teams issue laptops to remote hires without updating tracking lists. Run regular inventory checks to keep device registers accurate.
  • Unencrypted remote laptops: Staff store sensitive customer files on unencrypted local drives. Mandate full drive encryption across all portable work equipment.
  • Shared family devices: Household members use work laptops for gaming or web browsing. Provide dedicated work hardware and block non-staff user profiles.
  • Weak home network security: Workers use default router passwords and unpatched home routers. Share clear guides on how to secure home Wi-Fi networks.
  • Overlooking paper records: Teams print customer files at home and discard them in domestic bins. Prohibit home printing or supply cross-cut shredders.
  • Unsecure mobile working: Staff work from busy cafes and leave laptops exposed to theft. Require screen locks, privacy guards, and secure travel bags.
  • Slow patch deployment: Remote laptops miss critical security patches when kept offline. Use cloud-based update tools to push fixes automatically.
  • Shadow software adoption: Remote teams sign up for unapproved cloud apps to share files. Supply approved collaboration tools and block rogue web services.
  • Poor remote offboarding: Ex-workers keep company laptops or access rights after leaving. Set strict offboarding steps to cut access and retrieve hardware fast.
  • Lack of physical workspace privacy: Visitors see sensitive work data displayed on open screens. Require workers to use dedicated rooms or privacy shields.
  • Delayed loss reporting: Staff wait days to report lost laptops out of fear. Build a blameless culture so workers report missing hardware right away.
  • Public network threats: Workers connect to unverified public Wi-Fi hotspots without protection. Enforce automatic secure connections for all remote internet traffic.
  • Excessive local data storage: Staff save files to local desktops instead of secure cloud drives. Configure systems to sync data to central cloud hubs automatically.
  • Inconsistent policy awareness: Remote workers forget key security habits over time. Deliver short, regular training refreshers to keep awareness high.
  • Missing remote wipe controls: Administrators cannot clear stolen laptops that lack tracking tools. Install remote management tools on all company assets.

How to Measure Effectiveness (KPIs)

  • Remote device encryption rate: Measure the percentage of active remote laptops and phones that carry full disk protection.
  • Multi-factor authentication rate: Track the proportion of remote user accounts that enforce two-step login checks for system access.
  • Remote asset register accuracy: Measure how many off-site devices match central tracking records during quarterly inventory reviews.
  • Lost remote device rate: Track the number of lost, stolen, or misplaced remote work devices reported each year.
  • Device loss reporting speed: Monitor the average time taken by remote staff to report missing hardware after noticing the loss.
  • Remote security patch pass rate: Measure the percentage of off-site laptops running the latest operating system security updates.
  • Unapproved software block rate: Track the number of unapproved applications or cloud services blocked on remote machines.
  • Secure connection compliance: Measure the proportion of off-site network connections routed through approved encrypted channels.
  • Remote wipe success rate: Track the percentage of lost or retired remote devices wiped clean within target response times.
  • Remote working audit finding count: Monitor the number of security gaps flagged during internal reviews of remote working controls.
  • Remote training completion rate: Track the percentage of off-site workers who complete annual remote security training.
  • Offboarding hardware recovery rate: Measure the percentage of company laptops retrieved from departing remote staff on time.
ISO 27001 Remote Working Explained - Annex A 6.7 - High Table Compliance Platform powered by hicomply
High Table Compliance Platform powered by hicomply