Skip to content
arrow_back
search
Annex A 6.7 verified ISO/IEC 27001:2022

Remote Working Security Measures

Implement security measures to protect company info when working outside the office.

People controls Preventative ISO/IEC 27001:2022remote working
record_voice_over

Plain language

When employees work from home or any place outside the office, their laptops and information can be at risk. This control is about ensuring the safety of company data when staff are working remotely. If it's not followed, sensitive information could be accessed by unauthorised people, leading to data breaches or identity theft.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

People controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

12 Apr 2026

Maturity levels

N/A

Official control statement

Security measures shall be implemented when personnel are working remotely to protect information accessed, processed or stored outside the organization’s premises.
verified ISO/IEC 27001:2022 Annex A 6.7
priority_high

Why it matters

Without robust remote-working controls, data accessed off-site may be intercepted on insecure Wi‑Fi or lost from unmanaged devices, leading to breaches and unauthorised disclosure.

settings

Operational notes

Harden remote access: enforce VPN + MFA, keep remote access clients patched, and require managed devices with encryption, screen locks and remote wipe for off-premises work.

Mapping detail

Mapping

Direction

Controls