How to Implement ISO 27001 Annex A 6.7 Remote Working

Stuart Barker - High Table - ISO27001 Director

The ultimate how to implement guide to ISO 27001 Annex A 6.7 Remote Working.

1. Enforce Full-Disk Encryption (FDE)

Control Requirement: Protect data at rest on portable devices used remotely.

Required Implementation Step: Configure your MDM (Mobile Device Management) policy (e.g., Intune, Kandji) to mandatorily enable BitLocker (Windows) or FileVault (macOS) before the device is allowed to access corporate resources. Escrow the recovery keys to your central management console, not the user’s local account.

Minimum Requirement: 100% of remote endpoints encrypted with recovery keys centralized in the MDM.

2. Mandate Always-On VPN or ZTNA

Control Requirement: Secure communication over untrusted public networks.

Required Implementation Step: Deploy an “Always-On” VPN profile or a Zero Trust Network Access (ZTNA) agent (e.g., Cloudflare WARP, Zscaler) that forces all traffic through your secure gateway. The device must not be capable of accessing the internet directly without passing through your security stack (DNS filtering, IPS).

Minimum Requirement: Network logs showing all remote traffic routing through the corporate secure gateway.

3. Implement Geofencing and Impossible Travel Logic

Control Requirement: Detect and block unauthorised remote access attempts.

Required Implementation Step: Configure your Identity Provider (IdP) to block logins from high-risk countries where you have no staff. Enable “Impossible Travel” alerts to automatically suspend accounts that log in from London at 09:00 and Moscow at 09:15.

Minimum Requirement: Conditional Access policies blocking non-operational geolocations.

ISO 27001 Toolkit Business Edition

4. Restrict Printing and Local Storage

Control Requirement: Prevent data leakage outside the corporate boundary.

Required Implementation Step: Use Endpoint Protection policies to disable the “Print to Local Printer” spooler service and block USB mass storage devices. Remote workers should not be printing sensitive PII on their family inkjet printer where pages can be lost or seen by visitors.

Minimum Requirement: Configuration settings proving USB and local print blocking are active.

5. Secure the Home Wi-Fi Environment

Control Requirement: Provide guidance on securing the physical connection point.

Required Implementation Step: Issue a “Home Network Security Standard” requiring staff to change default router passwords and enable WPA2/WPA3 encryption. While you cannot enforce this technically without intrusion, you must make it a policy violation to connect to open/unsecured WEP networks.

Minimum Requirement: A signed Teleworking Policy where the user attests to securing their home router.

6. Define Physical Security for Home Offices

Control Requirement: Prevent oversight and theft of assets in domestic settings.

Required Implementation Step: Mandate a “Clean Desk Policy” for the home. Users must agree to lock their screen when answering the door and store laptops in a secure location (e.g., a locked drawer) when not in use. Prohibit the use of voice assistants (Alexa/Siri) in rooms where confidential meetings occur.

Minimum Requirement: Training acknowledgement regarding voice assistants and physical locking of devices.

7. Enforce Screen Privacy Filters

Control Requirement: Prevent shoulder surfing in public workspaces.

Required Implementation Step: Provide physical privacy screens to all staff who work in shared spaces (cafés, trains, co-working hubs). Update the policy to mandate their use whenever the screen is visible to the public. Visually verify this during random video calls or office visits.

Minimum Requirement: Purchase orders or asset logs confirming distribution of privacy filters to mobile staff.

8. Implement Remote Wipe Capabilities

Control Requirement: Capability to sanitise compromised or lost devices remotely.

Required Implementation Step: Verify that your MDM can execute a “Corporate Wipe” (removing only business data) for BYOD and a “Full Wipe” for corporate devices. Test this capability annually on a test device to ensure it executes even if the device is not on the VPN.

Minimum Requirement: Successful test logs of a remote wipe command execution.

9. Segregate Family Use from Corporate Use

Control Requirement: Prevent unauthorised users (family members) from accessing systems.

Required Implementation Step: Strict configuration: The laptop is for the employee only. Create a policy that forbids family members from using the device for homework or browsing. Technically enforce this by disallowing the creation of secondary local user accounts on the OS.

Minimum Requirement: Policy explicitly banning family use, backed by OS settings preventing new user creation.

10. Establish Virtual Meeting Security Protocols

Control Requirement: Secure remote collaboration channels.

Required Implementation Step: Configure Zoom/Teams/Meet settings centrally. Force waiting rooms for external guests, disable “Join before Host,” and require passcodes for all meetings. Disable file transfers in chat for external participants to prevent malware ingress.

Minimum Requirement: Global configuration settings for video conferencing tools enforcing security defaults.

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top