ISO 27002:2022
People controls – ISO 27002:2022

ISO 27002:2022 6.7: Remote working

Where personnel work remotely, security measures are to be applied to protect information that is accessed, processed or held away from the organization's premises. Purpose: keep information secure during remote working. Guidance: remote working means working from anywhere outside the premises with access to paper or electronic information, including teleworking, telecommuting, flexible workplaces, virtual environments and remote maintenance; local law may prevent some measures. Organizations allowing it issue a topic-specific remote working policy setting conditions and restrictions. Matters to weigh include: the physical security of the remote site and its surroundings, including the jurisdictions people are in; rules and mechanisms there such as lockable storage, secure transport between locations, and rules on remote access, clear desk, printing, disposal and event reporting (6.8); the physical environments expected; communications security given the systems reached, the sensitivity of information passed and of the systems and applications; remote access methods such as virtual desktops that allow work on privately owned equipment; the risk of access by others at the site, such as family and friends, or by people in public places; use of home and public networks and rules on wireless configuration; firewalls and anti-malware; secure remote deployment and initialization of systems; and secure authentication and privilege enablement, bearing in mind the weakness of single-factor authentication for network access. Measures include: providing equipment and storage furniture where private equipment is not allowed; defining the permitted work, the classification levels of information allowed to be held and the systems the worker may use; training for remote workers and their support staff on working securely; suitable communication equipment with secured remote access, screen locks, inactivity timeouts, location tracking and remote wipe; physical security; rules on what household members and visitors may see or touch; hardware and software support and maintenance; insurance; backup and continuity procedures; audit and security monitoring; and withdrawing authority and access and recovering equipment when remote working ends.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 81 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 8 controls

  • AC-17 Remote Access
  • AC-17(1) Monitoring and Control
  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • AC-17(3) Managed Access Control Points
  • AC-17(4) Privileged Commands and Access
  • CM-2(7) Configure Systems and Components for High-Risk Areas
  • MA-4 Nonlocal Maintenance
  • PE-17 Alternate Work Site

FedRAMP Moderate · 8 controls

  • AC-17 Remote Access
  • AC-17(1) Monitoring and Control
  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • AC-17(3) Managed Access Control Points
  • AC-17(4) Privileged Commands and Access
  • CM-2(7) Configure Systems and Components for High-Risk Areas
  • MA-4 Nonlocal Maintenance
  • PE-17 Alternate Work Site

CIS Controls v8 · 6 controls

  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-14.8 Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks
  • CIS-3.6 Encrypt Data on End-User Devices
  • CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices
  • CIS-6.4 Require MFA for Remote Network Access

NIST SP 800-53 Rev 5 · 6 controls

PCI DSS 4.0 · 6 controls

  • 1.5.1 1.5.1 Security controls on dual-connected devices
  • 10.2.1 10.2.1 Audit logging enabled on all system components
  • 12.2.1 12.2.1 Rules for acceptable use of end-user technology
  • 3.4.2 3.4.2 Remote access blocks copying or relocating PAN
  • 5.4.1 5.4.1 Mechanisms detect and protect against phishing
  • 8.4.3 8.4.3 MFA for remote access that could reach CDE

CMMC 2.0 · 5 controls

SOC 2 · 5 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • ANSSI-HYG-30 Apply Physical Protection Measures to Mobile Devices
  • ANSSI-HYG-31 Encrypt Sensitive Data, in Particular on Equipment That May Be Lost
  • ANSSI-HYG-32 Secure the Network Connection of Devices Used for Mobile Working
  • ANSSI-HYG-33 Adopt Security Policies Dedicated to Mobile Terminals
  • ISM-0705 Disabling VPN split tunnelling
  • ISM-0866 Viewing classified data in public
  • ISM-1866 Preventing storage of classified data on private devices
  • ISM-2097 Always on VPN for mobile devices
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage

NIST SP 800-171 Rev 3 · 3 controls

  • 0135 0135 Risk-assess working in another government entity's facilities
  • 0136 0136 Agreement managing risks of working in another entity's facilities
  • 0138 0138 Risk-assess international remote work

UK Cyber Essentials · 3 controls

  • CE-FW.6 Host-Based Firewall for Remote Workers
  • CE-SC.9 Device Unlocking Credentials and Brute-Force Protection
  • CE-SCOPE.3 BYOD and Home Working
  • ASBv3-PA-6 Use privileged access workstations
  • IM-7 Restrict resource access based on conditions

ISO 27001:2022 · 2 controls

  • 6.7 Remote working
  • 7.9 Security of assets off-premises

NIST SP 800-161 Rev 1 · 2 controls

  • ASD37-20 Multi-factor authentication (Essential)

C5 (Germany) · 1 control

  • CCM-HRS-04 Remote and Home Working Policy and Procedures

HIPAA Security Rule · 1 control

ISO 27701:2019 · 1 control

  • 6.3.2 Mobile devices and teleworking

ISO/IEC 27011:2024 · 1 control

  • 27011-6.4 Remote working

NIST SP 800-172 · 1 control

  • 3.5.3e Prohibit Connection of Unknown or Unverified System Components
  • P2-4.3.2 P2-4.3.2 Remote access controlled and documented

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in People controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 6.7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 81 it maps to, and the evidence behind each claim, over MCP and REST.