ISO 27001 Control A.6.7: Remote Working
Control A.6.7 recognises a reality that the 2022 revision made explicit: for most organizations, “the office” is no longer where the work happens. People work from home, from cafes, from client sites, and from airports, carrying access to sensitive information into environments the organization does not control. A.6.7 requires you to implement security measures when personnel work remotely, to protect information accessed, processed, or stored outside your premises. It is a people control by placement, but in practice it pulls together policy, technology, and behaviour. This is the seventh control in our walk through Annex A.
What the control requires
Annex A control 6.7 of ISO 27001:2022 states that security measures shall be implemented when personnel are working remotely to protect information accessed, processed or stored outside the organization’s premises.
The control is deliberately broad. “Remotely” covers home working, hybrid work, travel, and working from any location outside your controlled sites. The measures span the physical environment, the devices, the network, and the person’s behaviour. A.6.7 is a preventive control. Annex A states it; ISO 27002 gives detailed guidance, and your Statement of Applicability records how you apply it.
How to implement remote working security
Start with a remote working policy
The anchor is a clear policy that tells people what secure remote working looks like: approved devices and connections, handling of confidential information away from the office, use of public networks, physical security of devices, and what to do if a device is lost or stolen. The policy makes expectations explicit and gives the other measures something to reference.
Secure the device and the connection
Most of the technical protection comes from controls you apply to the endpoint and the link back to your systems:
- Managed, encrypted devices with screen lock, disk encryption, and current patches
- Strong authentication and secure remote access (VPN or zero-trust access) rather than exposing services directly
- Endpoint protection and the ability to remotely wipe a lost device
- Restrictions on saving sensitive data locally where cloud access suffices
These lean heavily on the technological controls, but A.6.7 is where they are framed specifically for the out-of-office context.
Address the physical and human environment
Technology does not cover shoulder-surfing on a train, a family member using a work laptop, or confidential calls in a public space. The policy and awareness training should cover clear-screen habits away from the office, privacy in public places, secure storage of any physical documents, and not letting others use work devices. Home working also raises questions about home network security and printed material.
Consider higher-risk scenarios explicitly
Working while travelling internationally, from high-risk locations, or on personal (BYOD) devices carries extra risk. Decide your stance in advance: what is allowed, what requires approval, and what is prohibited. BYOD in particular needs its own rules on separation of work and personal data.
Evidence the control operates
Auditors want to see the policy, evidence people have acknowledged it, and evidence the supporting technical measures are in place - device management enrollment, VPN or access configuration, encryption status. Acknowledgement plus a device-compliance report is usually enough.
Related controls and clauses
A.6.3 connection. Awareness and training is what turns the remote working policy into actual behaviour away from supervision.
A.7.9 connection. Security of assets off-premises (A.7.9) is the physical-controls counterpart, protecting equipment taken outside the office.
A.8.1 connection. User endpoint devices (A.8.1) provide the technical hardening - encryption, patching, device management - that remote working depends on.
A.5.14 connection. Information transfer controls govern how confidential data moves to and from remote locations.
Clause 6.1 connection. How strict your remote working measures need to be should trace back to your risk assessment and the sensitivity of the information involved.
What auditors check
A remote working policy exists. Auditors expect a documented policy covering devices, connections, physical security, and information handling away from the office.
People know it. They look for evidence personnel have read and acknowledged the policy.
Technical measures are real. Auditors check that the supporting controls - device encryption, managed endpoints, secure remote access, remote wipe - are actually deployed, not just described.
Higher-risk cases are addressed. They probe your stance on BYOD, travel, and high-risk locations.
Incident handling. Auditors may ask what happens when a remote device is lost or stolen, expecting a defined, practised response.
Common mistakes to avoid
A policy with no teeth. A remote working policy that is not backed by device management, encryption, and secure access is just words. Pair the policy with real controls.
Ignoring BYOD. Letting people use personal devices for work with no rules or separation is a frequent and serious gap.
Forgetting the physical side. Focusing only on VPNs and encryption while ignoring shoulder-surfing, shared home devices, and printed documents leaves obvious exposure.
No lost-device response. If there is no way to remotely wipe or disable a lost laptop, a single misplaced device becomes a breach.
Treating remote as an exception. Writing the policy as if remote work is rare, when it is the norm, leaves most of your working reality ungoverned.
No acknowledgement or evidence. A policy nobody signed and controls you cannot demonstrate will not satisfy an auditor.
How 27kay can help
We help organizations secure remote and hybrid work in a way that fits how people actually work - practical measures that protect information without getting in the way. As part of ISO 27001 implementation, we write a workable remote working policy, align it with your endpoint, access, and asset controls, set your BYOD and travel stance, and put the evidence in place for audit. For the full picture, see our ISO 27001 knowledge hub.
Is your remote working policy keeping up with how your team actually works? Get in touch - we will review it and help you close the gaps between policy and practice.