ISO 27001 Annex A 6.7 Remote working requires organisations to implement clear security rules and controls for staff working outside the office. Storing these policies in a central document hub helps protect company data on remote devices and ensures strong compliance.
Table of contents
Key Takeaways
- What is ISO 27001 Annex A 6.7? ISO 27001 Annex A 6.7 is an information security control that requires organisations to protect company data outside the main office.
- Document clear remote work rules: Create simple, written policies for working from home and other off-site locations.
- Provide central policy access: Store remote working security rules in a central document hub so all staff can easily find and read them.
- Secure remote devices: Protect laptops, phones, and home devices with strong passwords, lock screens, and automatic updates.
- Use secure connections: Require staff to access company systems and business tools through encrypted internet connections.
- Safeguard company data: Keep sensitive files, customer details, and business records safe from theft, loss, and unauthorised access.
- Train staff regularly: Teach team members how to spot risks, report security issues quickly, and follow safe habits outside the office.
- Meet compliance standards: Following these clear steps helps small teams pass security audits and build trust with clients.
How to Implement ISO 27001 Annex A 6.7
- Draft remote working rules: Write a clear remote work policy and store it in your central document repository.
- Secure off-site devices: Require device lock screens, full disk encryption, and automatic security updates on all remote equipment.
- Control system access: Use multi-factor authentication and encrypted network connections for staff accessing company tools from home.
- Protect home workspaces: Require staff to use private work areas, follow clean desk habits, and shield screens from view.
- Prevent data loss: Restrict the use of unapproved personal devices and ban the transfer of company files to personal storage.
- Train remote staff: Teach workers how to spot phishing scams, use public networks safely, and report lost devices quickly.
- Set incident response steps: Give off-site workers a fast, simple path to report security issues and stolen hardware immediately.
- Review remote access logs: Check user login records and system access logs regularly to spot unusual remote activity.
- Audit compliance regularly: Review your remote working controls annually to keep risk low and pass ISO 27001 audits.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 6.7
- Review remote working policies: Check written rules to confirm clear guidance exists for working from home, teleworking, and travel.
- Audit the remote asset register: Sample entries in the inventory log to verify all laptops and remote devices match real assets.
- Verify device encryption settings: Inspect sample remote laptops and phones to ensure strong disk protection guards all stored data.
- Check remote access controls: Confirm staff use multi-factor authentication and secure, encrypted connections to reach business systems.
- Inspect physical workspace standards: Verify remote workers understand how to keep home offices secure, lock doors, and hide screens.
- Review bring your own device rules: Check that personal devices used for work follow approved security controls and data isolation rules.
- Verify patch and update management: Test sample remote computers to ensure automatic security updates and antivirus tools run on time.
- Audit remote data handling habits: Confirm staff do not print sensitive files at home or transfer work records to personal storage.
- Review remote offboarding steps: Check that managers revoke system access and retrieve remote hardware promptly when staff leave the company.
- Inspect remote access logs: Review user login records and network connection logs to spot unusual off-site activity fast.
- Review lost device incident logs: Inspect report tickets for missing remote hardware to confirm teams ran full risk checks and wiped drives fast.
- Verify staff training records: Confirm employees complete regular security awareness training on remote working risks and clean desk rules.
- Check public network safety controls: Verify staff use secure connections and avoid untrusted public Wi-Fi when working on the move.
- Review communication tool guidelines: Check that teams use approved, secure channels for business calls, messaging, and video meetings.
Audit Evidence Checklist
- Remote working policy: Maintain a documented remote working policy with a complete version history in your central document repository.
- Remote asset register: Keep an active, up-to-date inventory list of all laptops, phones, and hardware issued to off-site staff.
- Remote device encryption logs: Maintain audit records showing that all remote laptops and mobile devices carry active disk encryption.
- Multi-factor authentication reports: Provide system records proving all remote workers use two-step login checks for cloud services.
- Remote worker risk assessments: Produce signed review forms that assess the physical and digital safety of home work setups.
- Secure connection logs: Keep network connection records showing that off-site workers route traffic through encrypted tunnels.
- Incident reporting tickets: Supply support logs showing fast action taken for lost remote equipment or suspicious login alerts.
- Staff training logs: Show sign-off sheets proving employees completed security awareness training on safe remote working habits.
What to Teach Employees
- Encrypt all remote devices: Teach workers that all portable work hardware must carry full drive encryption before saving any business files.
- Lock screens when stepping away: Instruct staff to lock computer screens and close laptops whenever they leave their home desk or workspace.
- Never use unsecured public Wi-Fi: Warn employees never to connect work laptops to open public networks without an approved encrypted connection.
- Keep work and personal tasks separate: Train workers never to let friends or family members use company devices for personal tasks.
- Follow secure transit steps: Instruct staff to keep laptops in carry-on bags and never leave work gear unattended in cars or public places.
- Prevent shoulder surfing: Remind workers to use privacy screen filters and sit with their backs to walls when working in public spaces.
- Keep clear desk areas: Teach staff to clear desks of all confidential notes, client files, and paper printouts after the working day.
- Use strong passwords and passphrases: Instruct team members to set unique, complex passwords alongside multi-factor authentication for every account.
- Report missing devices fast: Ensure employees know to report lost or stolen laptops and phones immediately to trigger a remote data wipe.
- Spot remote phishing scams: Remind staff to check sender details carefully and report fake emails or messages aimed at home workers.
- Avoid personal storage items: Warn staff against saving company data to personal cloud drives, email inboxes, or unmanaged home drives.
- Understand remote security rules: Train workers on how poor home security habits lead to data leaks, compliance fines, and business damage.
Common Implementation Challenges
- Unapproved device usage: Staff use unmanaged home computers for work tasks. Enforce clear device policies and restrict access to approved hardware.
- Incomplete asset registers: Teams issue laptops to remote hires without updating tracking lists. Run regular inventory checks to keep device registers accurate.
- Unencrypted remote laptops: Staff store sensitive customer files on unencrypted local drives. Mandate full drive encryption across all portable work equipment.
- Shared family devices: Household members use work laptops for gaming or web browsing. Provide dedicated work hardware and block non-staff user profiles.
- Weak home network security: Workers use default router passwords and unpatched home routers. Share clear guides on how to secure home Wi-Fi networks.
- Overlooking paper records: Teams print customer files at home and discard them in domestic bins. Prohibit home printing or supply cross-cut shredders.
- Unsecure mobile working: Staff work from busy cafes and leave laptops exposed to theft. Require screen locks, privacy guards, and secure travel bags.
- Slow patch deployment: Remote laptops miss critical security patches when kept offline. Use cloud-based update tools to push fixes automatically.
- Shadow software adoption: Remote teams sign up for unapproved cloud apps to share files. Supply approved collaboration tools and block rogue web services.
- Poor remote offboarding: Ex-workers keep company laptops or access rights after leaving. Set strict offboarding steps to cut access and retrieve hardware fast.
- Lack of physical workspace privacy: Visitors see sensitive work data displayed on open screens. Require workers to use dedicated rooms or privacy shields.
- Delayed loss reporting: Staff wait days to report lost laptops out of fear. Build a blameless culture so workers report missing hardware right away.
- Public network threats: Workers connect to unverified public Wi-Fi hotspots without protection. Enforce automatic secure connections for all remote internet traffic.
- Excessive local data storage: Staff save files to local desktops instead of secure cloud drives. Configure systems to sync data to central cloud hubs automatically.
- Inconsistent policy awareness: Remote workers forget key security habits over time. Deliver short, regular training refreshers to keep awareness high.
- Missing remote wipe controls: Administrators cannot clear stolen laptops that lack tracking tools. Install remote management tools on all company assets.
How to Measure Effectiveness (KPIs)
- Remote device encryption rate: Measure the percentage of active remote laptops and phones that carry full disk protection.
- Multi-factor authentication rate: Track the proportion of remote user accounts that enforce two-step login checks for system access.
- Remote asset register accuracy: Measure how many off-site devices match central tracking records during quarterly inventory reviews.
- Lost remote device rate: Track the number of lost, stolen, or misplaced remote work devices reported each year.
- Device loss reporting speed: Monitor the average time taken by remote staff to report missing hardware after noticing the loss.
- Remote security patch pass rate: Measure the percentage of off-site laptops running the latest operating system security updates.
- Unapproved software block rate: Track the number of unapproved applications or cloud services blocked on remote machines.
- Secure connection compliance: Measure the proportion of off-site network connections routed through approved encrypted channels.
- Remote wipe success rate: Track the percentage of lost or retired remote devices wiped clean within target response times.
- Remote working audit finding count: Monitor the number of security gaps flagged during internal reviews of remote working controls.
- Remote training completion rate: Track the percentage of off-site workers who complete annual remote security training.
- Offboarding hardware recovery rate: Measure the percentage of company laptops retrieved from departing remote staff on time.

