Remote working changes where work happens, not who is responsible for security. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations deploy corporate VPNs and assume their remote security is complete, while completely ignoring the human and physical realities, like family members using work laptops, sensitive client calls taken in crowded coffee shops, or unencrypted home Wi-Fi networks exposed to local attacks. Moving outside the office perimeter shifts your threat landscape significantly; Annex A 6.7 ensures your security controls move with your workforce.
ISO 27001:2022 includes Annex A 6.7 to ensure your organisation protects information accessed, processed, or stored across remote locations. This control replaces the former 2013 “teleworking” requirement (6.2.2) and updates operational baselines for modern hybrid working, Bring Your Own Device (BYOD) risks, cloud-first architectures, and off-premises physical data handling.
Quick Summary: What ISO 27001 Annex A 6.7 Requires
At a practical level, Annex A 6.7 is about maintaining a defensible security posture wherever your people operate. It is not about banning remote work or heavily spying on employees; it expects clear, risk-based safeguards that support flexibility without compromising confidentiality. Here is what you need to do in plain English:
- Publish a Remote Working Policy: Define explicit conditions, acceptable locations, authorized roles, and data handling rules for working off-site.
- Enforce Secure Remote Access: Require Multi-Factor Authentication (MFA) (Annex A 8.5) and Zero Trust Network Access (ZTNA) or encrypted VPNs for cloud and internal network links.
- Mandate Full-Disk Encryption (FDE): Encrypt storage media across all remote endpoints to ensure data remains unreadable if hardware is lost or stolen (Annex A 8.24).
- Address Remote Physical & Visual Risks: Train staff to lock screens, prevent “shoulder-surfing” in public spaces, and secure physical files away from household members.
- Control Personal Device (BYOD) Use: Isolate corporate data on personal devices using secure mobile containerisation (MAM) or virtual desktop environments.
- Revoke Remote Rights Upon Offboarding: Automate session revocation, cloud token invalidation, and hardware return workflows when remote arrangements end (Annex A 8.2).
Why Hybrid and Remote Work Present Elevated Security Hazards
When employees work outside controlled corporate premises, your traditional physical barriers, network firewalls, and direct supervision vanish. Remote environments introduce unique physical, technical, and behavioral vulnerabilities that cybercriminals actively target.
Ignoring remote working security controls exposes your business to severe hazards:
- Public Visual Data Leaks (“Shoulder-Surfing”): Onlookers viewing unshielded laptop screens displaying confidential customer PII or financial forecasts in cafés, airport terminals, or trains (Annex A 7.9).
- Unsecured Home Network Compromise: Home Wi-Fi routers operating with default passwords or outdated firmware allowing attackers to intercept unencrypted traffic.
- Unauthorized Household Access: Family members, flatmates, or guests using unattended corporate hardware to browse the web, introducing malware or accidentally deleting critical files.
- Unmonitored Shadow IT: Remote staff adopting unvetted personal cloud storage, file-sharing apps, or messaging tools to bypass corporate friction.
My 8 Step Plan to Implement Annex A 6.7 Fast
You do not need an intrusive surveillance suite to satisfy an ISO 27001 auditor. Here is my pragmatic, 8-step plan to establish an audit-ready remote working security framework.
1. Establish an Explicit Remote Working Policy
Document a clear topic-specific policy defining acceptable remote working environments, user responsibilities, and operational boundaries:
- Define permitted remote locations (e.g., primary home office vs. public places vs. working internationally).
- Specify data classification tiers permitted for remote processing (e.g., prohibiting local downloads of “Restricted” databases).
- Outline mandatory physical security steps required when leaving remote workstations unattended.
2. Enforce Robust Identity Verification and Access Controls
Remote connections bypass physical perimeter badge readers. Technical identity verification must be rock-solid:
- Mandate Multi-Factor Authentication (MFA) globally across all cloud portals, VPNs, and remote desktops (Annex A 8.5).
- Deploy Conditional Access policies to evaluate identity, user risk, and endpoint compliance health before granting session access.
- Configure session inactivity timeouts (e.g., 5–10 minutes) forcing screen lockouts on remote endpoints (Annex A 8.1).
3. Secure Remote Network Communications
Assume that all external networks—whether home Wi-Fi or coffee shop hot-spots—are actively monitored or insecure:
- Require remote endpoints to route connections through encrypted ZTNA gateways or enterprise VPN tunnels using strong cipher suites (Annex A 8.24).
- Prohibit connecting corporate devices to open, unencrypted public Wi-Fi networks without active VPN protection.
- Provide guidance for remote staff on securing home Wi-Fi networks (changing default router passwords, enabling WPA3 encryption).
4. Harden Remote Endpoint Hardware and Media
Ensure that remote hardware remains fully secured against physical theft, loss, and unauthorized tampering:
- Enforce full-disk encryption (BitLocker, FileVault) across all laptops, smartphones, and portable drives used off-site (Annex A 8.1).
- Centralise device management via Mobile Device Management (MDM / MAM) to enforce security baselines and enable immediate remote wipe capabilities.
- Block local administrator rights to prevent staff from installing unapproved software or altering security baselines (Annex A 8.2).
5. Mitigate Physical and Visual Exposure in Remote Spaces
Technical controls cannot stop someone looking over a remote worker’s shoulder. Train staff on physical environmental security:
- Issue privacy screen filters to employees who routinely work in high-traffic or public environments (Annex A 7.9).
- Train staff to position screens away from ground-floor windows, public pathways, and family living areas.
- Instruct remote workers never to leave corporate hardware unattended in vehicles, hotel rooms, or public venues.
6. Govern Bring Your Own Device (BYOD) and Personal Workspaces
Allowing personal smartphones or home PCs to access corporate resources introduces severe cross-contamination risks:
- Use Mobile Application Management (MAM) or Virtual Desktop Infrastructure (VDI) to isolate corporate apps and data from personal OS files.
- Prohibit saving corporate files directly onto unencrypted personal hard drives or personal cloud accounts (e.g., personal iCloud or Dropbox).
- Block copy-pasting and file transfer capabilities between corporate virtual workspaces and local personal drives.
7. Deliver Tailored Remote Security Awareness Training
Remote personnel operate without direct physical oversight, making security habits their primary defense:
- Train remote staff on recognizing remote-specific threat vectors, such as urgent SMS phishing (smishing), vishing, and home router attacks.
- Ensure remote workers know exactly how to report lost devices, suspicious emails, or security events instantly (Annex A 6.8).
- Incorporate hybrid working scenarios and real-world off-premises security examples into annual awareness training.
8. Manage Remote Offboarding and Access Revocation
When remote working arrangements change, end, or an employee resigns, close off-site exposure pathways fast:
- Automate immediate account suspension and active remote session termination upon employee offboarding (Annex A 8.2).
- Execute remote wipe commands via MDM/MAM to scrub corporate data containers from personal or corporate devices.
- Provide pre-paid courier packaging to ensure prompt physical return of corporate hardware assets (Annex A 7.9).
Common Implementation Pitfalls and How to Fix Them
When preparing clients for ISO 27001 audits, I frequently spot the same remote working mistakes. Here are the main traps and how to solve them:
- Problem: Relying Solely on a VPN While Allowing Local Unencrypted File Saving
Ninja Solution: Combine VPN/ZTNA access controls with mandatory full-disk encryption (FDE) and cloud DLP policies to prevent unencrypted local storage. - Problem: Family Members Sharing Corporate Laptops for Homework or Gaming
Ninja Solution: Explicitly prohibit personal/family device sharing in policy and enforce strict endpoint PIN/biometric login controls. - Problem: Unmonitored Remote Staff Accessing Cloud Apps from Non-Compliant Personal PCs
Ninja Solution: Enforce Conditional Access policies that block logins unless the accessing endpoint passes central MDM health compliance checks. - Problem: Remote Staff Failing to Report Lost Laptops Out of Fear of Punishment
Ninja Solution: Promote a strict no-blame reporting culture (Annex A 6.8) that rewards fast loss reporting so IT can wipe missing hardware instantly.
The ISO 27001 Ninja Bottom Line
ISO 27001 Annex A 6.7 is about extending your information security posture directly to wherever your people operate. Remote working changes where work happens, but your responsibility to protect core data remains identical.
By publishing a clear remote policy, enforcing MFA and Zero Trust access, mandating full-disk encryption, training staff on public visual privacy, isolating BYOD environments, delivering remote threat training, and revoking off-site rights instantly upon offboarding, you maintain a defensible remote architecture, protect confidential assets, and satisfy your ISO 27001 auditor with complete confidence.
