The ultimate how to implement guide to ISO 27001 Annex A 6.7 Remote Working.
Table of contents
- 1. Enforce Full-Disk Encryption (FDE)
- 2. Mandate Always-On VPN or ZTNA
- 3. Implement Geofencing and Impossible Travel Logic
- 4. Restrict Printing and Local Storage
- 5. Secure the Home Wi-Fi Environment
- 6. Define Physical Security for Home Offices
- 7. Enforce Screen Privacy Filters
- 8. Implement Remote Wipe Capabilities
- 9. Segregate Family Use from Corporate Use
- 10. Establish Virtual Meeting Security Protocols
1. Enforce Full-Disk Encryption (FDE)
Control Requirement: Protect data at rest on portable devices used remotely.
Required Implementation Step: Configure your MDM (Mobile Device Management) policy (e.g., Intune, Kandji) to mandatorily enable BitLocker (Windows) or FileVault (macOS) before the device is allowed to access corporate resources. Escrow the recovery keys to your central management console, not the user’s local account.
Minimum Requirement: 100% of remote endpoints encrypted with recovery keys centralized in the MDM.
2. Mandate Always-On VPN or ZTNA
Control Requirement: Secure communication over untrusted public networks.
Required Implementation Step: Deploy an “Always-On” VPN profile or a Zero Trust Network Access (ZTNA) agent (e.g., Cloudflare WARP, Zscaler) that forces all traffic through your secure gateway. The device must not be capable of accessing the internet directly without passing through your security stack (DNS filtering, IPS).
Minimum Requirement: Network logs showing all remote traffic routing through the corporate secure gateway.
3. Implement Geofencing and Impossible Travel Logic
Control Requirement: Detect and block unauthorised remote access attempts.
Required Implementation Step: Configure your Identity Provider (IdP) to block logins from high-risk countries where you have no staff. Enable “Impossible Travel” alerts to automatically suspend accounts that log in from London at 09:00 and Moscow at 09:15.
Minimum Requirement: Conditional Access policies blocking non-operational geolocations.
DO IT YOURSELF
ISO 27001
All the templates, tools, support and knowledge you need to do it yourself.
4. Restrict Printing and Local Storage
Control Requirement: Prevent data leakage outside the corporate boundary.
Required Implementation Step: Use Endpoint Protection policies to disable the “Print to Local Printer” spooler service and block USB mass storage devices. Remote workers should not be printing sensitive PII on their family inkjet printer where pages can be lost or seen by visitors.
Minimum Requirement: Configuration settings proving USB and local print blocking are active.
5. Secure the Home Wi-Fi Environment
Control Requirement: Provide guidance on securing the physical connection point.
Required Implementation Step: Issue a “Home Network Security Standard” requiring staff to change default router passwords and enable WPA2/WPA3 encryption. While you cannot enforce this technically without intrusion, you must make it a policy violation to connect to open/unsecured WEP networks.
Minimum Requirement: A signed Teleworking Policy where the user attests to securing their home router.
6. Define Physical Security for Home Offices
Control Requirement: Prevent oversight and theft of assets in domestic settings.
Required Implementation Step: Mandate a “Clean Desk Policy” for the home. Users must agree to lock their screen when answering the door and store laptops in a secure location (e.g., a locked drawer) when not in use. Prohibit the use of voice assistants (Alexa/Siri) in rooms where confidential meetings occur.
Minimum Requirement: Training acknowledgement regarding voice assistants and physical locking of devices.
7. Enforce Screen Privacy Filters
Control Requirement: Prevent shoulder surfing in public workspaces.
Required Implementation Step: Provide physical privacy screens to all staff who work in shared spaces (cafés, trains, co-working hubs). Update the policy to mandate their use whenever the screen is visible to the public. Visually verify this during random video calls or office visits.
Minimum Requirement: Purchase orders or asset logs confirming distribution of privacy filters to mobile staff.
8. Implement Remote Wipe Capabilities
Control Requirement: Capability to sanitise compromised or lost devices remotely.
Required Implementation Step: Verify that your MDM can execute a “Corporate Wipe” (removing only business data) for BYOD and a “Full Wipe” for corporate devices. Test this capability annually on a test device to ensure it executes even if the device is not on the VPN.
Minimum Requirement: Successful test logs of a remote wipe command execution.
9. Segregate Family Use from Corporate Use
Control Requirement: Prevent unauthorised users (family members) from accessing systems.
Required Implementation Step: Strict configuration: The laptop is for the employee only. Create a policy that forbids family members from using the device for homework or browsing. Technically enforce this by disallowing the creation of secondary local user accounts on the OS.
Minimum Requirement: Policy explicitly banning family use, backed by OS settings preventing new user creation.
10. Establish Virtual Meeting Security Protocols
Control Requirement: Secure remote collaboration channels.
Required Implementation Step: Configure Zoom/Teams/Meet settings centrally. Force waiting rooms for external guests, disable “Join before Host,” and require passcodes for all meetings. Disable file transfers in chat for external participants to prevent malware ingress.
Minimum Requirement: Global configuration settings for video conferencing tools enforcing security defaults.

