ISO 27001A.6 — Remote working
A.6.7
Remote working
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Implement security measures that protect information accessed, processed, or stored outside the organization's premises.
Points of focus
- Remote access architecture (VPN/ZTNA)
- Endpoint security baseline for remote devices
- Rules for local data storage
- Support and incident paths for remote staff
Implementation notes
Require company-managed endpoints for production access. Prefer ZTNA over flat VPN. Ban downloading production dumps to laptops; use ephemeral query tools. Document video-call screen-share rules for support roles.
Audit tip: Show MDM compliance rates and a sample of remote access logs for production apps. Interview one remote engineer about where they store customer data.
Evidence auditors typically request:
- Remote work / WFH security standard
- MDM compliance dashboard
- VPN/ZTNA configuration and access logs
- Exception tickets for unmanaged devices
Common gaps
- Personal laptops on production without MDM
- Customer data synced to personal Drive
- No guidance for café/public Wi-Fi
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.6.7 | This control |
| SOC 2 | CC6.1, CC6.7 | Related SOC 2 themes (CC6.1, CC6.7) — map in your crosswalk; not identical requirements. |
| HIPAA | §164.312(a)(1), §164.312(e)(1) | Related HIPAA themes (§164.312(a)(1), §164.312(e)(1)) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.6.7)
Frequently Asked Questions
Only with MDM and disk encryption; many SaaS teams disallow BYOD for production.
Yes — treat them as remote locations with the same endpoint and network rules.
Remote access to ePHI needs the same technical safeguards plus BA procedures.
Even without owned data centers, remote working still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with remote work / wfh security standard, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.