ISO 27001 Teleworking Security: Secure Remote Work
ISO 27001 teleworking security, governed by Annex A.6.7, requires organisations to protect information accessed, processed or stored at remote work locations. This covers secure connections, endpoint security, data protection, home office requirements and incident reporting for employees who work outside the organisation’s physical premises.
Author: Mustafa Hasan · Published: 25 July 2026 · Last updated: 25 July 2026
Annex A.6.7 Requirements
Annex A.6.7 in ISO 27001:2022 replaced the previous A.11.2.6 (teleworking) from the 2013 version. The control is now positioned under the organisational controls theme (A.6), reflecting the reality that teleworking is no longer a niche arrangement but a permanent feature of modern working life that must be addressed at the policy and organisational level.
The control states: “A policy and supporting security measures shall be implemented to protect information accessed, processed or stored at teleworking sites.”
This single control drives requirements across several domains: policy, technology, physical security, data protection and incident response.
| Security Domain | Annex A.6.7 Requirements | Related Controls |
|---|---|---|
| Policy | Teleworking policy defining roles, responsibilities, permitted activities and restrictions | A.5.1 (Information security policy), A.6.1 (Roles and responsibilities) |
| Connectivity | Secure remote access using VPN or equivalent encrypted channel | A.8.15 (Access control), A.8.24 (Cryptographic controls) |
| Endpoint security | Device security requirements including anti-malware, patch management, disk encryption | A.8.20 (Endpoint security), A.8.21 (Data at rest) |
| Data protection | Controls for handling, storing and disposing of information in remote locations | A.8.2 (Information classification), A.8.32 (Data disposal) |
| Physical security | Home office requirements: lockable storage, screen privacy, visitor controls | A.7.1 (Physical perimeter), A.7.6 (Working in secure areas) |
| Incident reporting | Process for reporting security incidents from remote locations | A.6.8 (Incident management) |
Remote Work Policy (A.6.7)
The foundation of teleworking security is a documented policy that sets out what is permitted, what is prohibited and what controls the employee must maintain. The policy must be communicated to every teleworker and acknowledged in writing.
A compliant teleworking policy should cover:
- Which roles and activities are eligible for teleworking
- Approved devices and the prohibition on using personal devices for sensitive work, or the controls required if BYOD is permitted
- Network requirements – home Wi-Fi security standards, guest network segregation
- Data handling rules – what data may be stored locally, what must remain on corporate servers
- Physical security requirements for the home workspace
- Requirements for family members or visitors in the workspace
- Incident reporting obligations and contact details
- Consequences of non-compliance
The policy must be reviewed annually or whenever the organisation’s risk profile changes significantly.
Secure Connections: VPN and Remote Access (A.6.7 / A.8.15)
Every remote connection to the corporate network must be encrypted. For most organisations, this means a virtual private network (VPN) with strong authentication. The ISO 27001 auditor will examine how remote access is controlled, authenticated, logged and reviewed.
Key requirements for remote access security include:
- Mandatory VPN use for all remote connections to corporate systems
- Multi-factor authentication (MFA) for VPN access
- Device compliance checking before VPN connection is granted (health checks for patch level, anti-malware status, disk encryption)
- Split-tunnelling disabled by default to prevent traffic bypassing the corporate security stack
- Session timeouts and automatic disconnection after inactivity
- Logging of all remote connections with user, device, timestamp and duration
- Regular review of remote access logs for anomalous activity
Zero Trust Network Access (ZTNA) solutions are increasingly replacing traditional VPNs for organisations implementing a mature remote access architecture. ZTNA provides device-level micro-segmentation and application-specific access rather than network-level entry. ZTNA is not explicitly required by ISO 27001 but is recognised as a stronger control and is increasingly expected in higher-risk environments.
Endpoint Security for Remote Workers (A.8.20)
Remote endpoints are the most exposed devices in any organisation. They operate outside the corporate network perimeter, often on untrusted home networks, and are used by employees without direct IT supervision. Annex A.6.7 must be implemented alongside A.8.20 (Endpoint security) to create a combined defence.
Essential endpoint controls for teleworkers include:
- Full-disk encryption (FDE) on all corporate laptops and mobile devices
- Centrally managed anti-malware with real-time protection and scheduled scans
- Automated patch management for operating system and applications
- Device firewall enabled and configured to block unauthorised inbound connections
- Screen lock with automatic timeout (5 minutes maximum)
- Remote wipe capability for lost or stolen devices
- Application allow-listing or software restriction policies
For organisations that permit BYOD, additional controls are needed: containerisation of corporate data, separate VPN profiles, and the ability to wipe corporate data without affecting personal data. BYOD policies must be explicit about what the organisation can and cannot do on a personal device, and employees must provide informed consent.
Data Protection for Remote Workers (A.6.7 / A.8.2)
Information that leaves the organisation’s physical perimeter is at greater risk of loss, theft or interception. Remote work controls must address the full information lifecycle: access, processing, storage, transfer and disposal.
Practical data protection measures for teleworking include:
- Restricting the ability to download or copy data to local devices
- Using cloud-based or remote-desktop solutions so data never leaves the corporate data centre
- Data classification labels that are visible when documents are opened
- Watermarking on printed or exported sensitive documents
- Prohibition on using personal cloud storage (Google Drive, Dropbox personal) for corporate data
- Secure disposal of physical documents through shredding or secure collection
- Data loss prevention (DLP) tools on corporate devices
Data protection obligations under Bahrain PDPL, Saudi PDPL and similar GCC data protection laws add an additional layer of requirements. Remote workers who process personal data from home must do so in a manner that complies with the organisation’s data protection obligations, including cross-border transfer restrictions if the teleworker is located in a different jurisdiction.
Home Office Requirements (A.6.7)
The physical security of the home workspace is part of ISO 27001 teleworking security. Annex A.6.7 expects the organisation to assess the home working environment and implement reasonable controls to protect information from physical threats.
Home office requirements should include:
- A dedicated workspace that can be separated from household activities
- Lockable storage for physical documents and devices when not in use
- Screen privacy filters on laptops in shared living spaces
- A clear desk policy that prevents documents being left visible
- Adequate network security: WPA3 or WPA2 encryption, guest network for family devices, changed default router password
- Controls to prevent unauthorised persons viewing or accessing corporate information during video calls
Incident Reporting for Remote Workers (A.6.7 / A.6.8)
Remote workers are often the first to detect a security incident but may not know how to report it. Annex A.6.7 requires that the teleworking policy includes clear incident reporting procedures that remote workers can follow even when they cannot access the corporate network.
- Lost or stolen devices (the most common teleworking incident)
- Suspected malware infection
- Phishing or social engineering attempts
- Unauthorised access to home network
- Loss or exposure of physical documents
- Breach of VPN or remote access credentials
- Any other security event affecting corporate information
Common Teleworking Security Findings in ISO 27001 Audits
Frequently Asked Questions
Does ISO 27001 allow employees to use personal devices for work?
Yes, but only if the organisation has a BYOD policy that addresses the additional risks. The policy must cover device security requirements, corporate data segregation, remote wipe capability and user consent. Many organisations choose to issue corporate devices specifically to avoid the complexity of BYOD controls under Annex A.6.7.
Is a VPN mandatory under ISO 27001 for remote workers?
Practically, yes. While ISO 27001 does not explicitly name VPN technology, Annex A.6.7 requires that remote connections are secured, and Annex A.8.24 requires cryptographic controls to protect data in transit. A properly configured VPN with strong authentication is the most common and auditor-accepted way to satisfy these requirements for remote access to corporate networks.
How do I handle teleworking for employees in different countries?
Cross-border teleworking introduces legal and regulatory complexity. Data protection laws in the employee’s location may apply, and cross-border data transfer restrictions may limit what data can be accessed remotely. The teleworking policy should include a cross-border approval process, and legal advice should be sought before permitting remote work from jurisdictions with restrictive data localisation requirements.
What is the minimum home office standard for ISO 27001 compliance?
The minimum standard is a dedicated workspace that can be locked, a secure Wi-Fi network (WPA2 or better), a corporate device with full-disk encryption and anti-malware, mandatory VPN use for corporate access, MFA on all remote access, and a clear desk policy. The organisation should document this standard and require each teleworker to confirm compliance annually.
How often must the teleworking policy be reviewed?
The teleworking policy should be reviewed at least annually as part of the ISMS management review cycle. Additional reviews should occur when the organisation introduces new remote access technologies, adopts a BYOD model, experiences a remote-work security incident, or changes its operating model significantly.
Can a remote worker be audited for ISO 27001 compliance?
Yes. The certification body may request to observe a remote worker’s setup either through a virtual visit or, in high-risk cases, an in-person inspection. The organisation must be prepared to demonstrate that teleworking controls are implemented in practice, not just documented. This includes showing that the remote worker uses VPN, has encrypted storage, follows the clear desk policy and can report incidents.
How Bitrixme Can Help
Bitrixme provides consultancy, gap analysis, implementation support, internal auditing and training for ISO 27001 certification. Certification audits are conducted by an independent accredited certification body. We prepare you for that audit; we do not issue the certificate.
Our teleworking security support includes Annex A.6.7 gap analysis, teleworking policy development, remote access architecture review, endpoint security configuration guidance, home office assessment templates, incident response playbook development for remote workers, and internal audit services covering all teleworking controls.
Contact Bitrixme for a free 30-minute consultation, or reach us on WhatsApp to discuss your ISO 27001 teleworking security requirements.
Related reading: ISO 27001 Annex A Controls · ISO 27001 Certification Cost · ISMS Implementation Guide