Skip to content
compliancebase
ISO 27001A.6 — Remote working

A.6.7

Remote working

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Implement security measures that protect information accessed, processed, or stored outside the organization's premises.

Points of focus

  • Remote access architecture (VPN/ZTNA)
  • Endpoint security baseline for remote devices
  • Rules for local data storage
  • Support and incident paths for remote staff

Implementation notes

Require company-managed endpoints for production access. Prefer ZTNA over flat VPN. Ban downloading production dumps to laptops; use ephemeral query tools. Document video-call screen-share rules for support roles.

Audit tip: Show MDM compliance rates and a sample of remote access logs for production apps. Interview one remote engineer about where they store customer data.

Evidence auditors typically request:

  • Remote work / WFH security standard
  • MDM compliance dashboard
  • VPN/ZTNA configuration and access logs
  • Exception tickets for unmanaged devices

Common gaps

  • Personal laptops on production without MDM
  • Customer data synced to personal Drive
  • No guidance for café/public Wi-Fi

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.6.7This control
SOC 2CC6.1, CC6.7Related SOC 2 themes (CC6.1, CC6.7) — map in your crosswalk; not identical requirements.
HIPAA§164.312(a)(1), §164.312(e)(1)Related HIPAA themes (§164.312(a)(1), §164.312(e)(1)) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Only with MDM and disk encryption; many SaaS teams disallow BYOD for production.

Yes — treat them as remote locations with the same endpoint and network rules.

Remote access to ePHI needs the same technical safeguards plus BA procedures.

Even without owned data centers, remote working still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with remote work / wfh security standard, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above