Where personnel work remotely, security measures are to be applied to protect information that is accessed, processed or held away from the organization's premises. Purpose: keep information secure during remote working. Guidance: remote working means working from anywhere outside the premises with access to paper or electronic information, including teleworking, telecommuting, flexible workplaces, virtual environments and remote maintenance; local law may prevent some measures. Organizations allowing it issue a topic-specific remote working policy setting conditions and restrictions. Matters to weigh include: the physical security of the remote site and its surroundings, including the jurisdictions people are in; rules and mechanisms there such as lockable storage, secure transport between locations, and rules on remote access, clear desk, printing, disposal and event reporting (6.8); the physical environments expected; communications security given the systems reached, the sensitivity of information passed and of the systems and applications; remote access methods such as virtual desktops that allow work on privately owned equipment; the risk of access by others at the site, such as family and friends, or by people in public places; use of home and public networks and rules on wireless configuration; firewalls and anti-malware; secure remote deployment and initialization of systems; and secure authentication and privilege enablement, bearing in mind the weakness of single-factor authentication for network access. Measures include: providing equipment and storage furniture where private equipment is not allowed; defining the permitted work, the classification levels of information allowed to be held and the systems the worker may use; training for remote workers and their support staff on working securely; suitable communication equipment with secured remote access, screen locks, inactivity timeouts, location tracking and remote wipe; physical security; rules on what household members and visitors may see or touch; hardware and software support and maintenance; insurance; backup and continuity procedures; audit and security monitoring; and withdrawing authority and access and recovering equipment when remote working ends.
This control maps to 81 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 6.7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.