SekitCrosswalk
Start free trial
ISO/IEC 27001:2022 · Annex A controls · derived mapping target

A.6.7Remote working

Set and apply security measures for staff who work remotely, covering devices, connections and home or public environments. Work outside the office should not mean protection is left behind.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0082Remote access · PolicysupportsThis policy control defines the allowed connection methods, devices and prohibitions for remote work, supporting A.6.7's Policy facet while the process and technical enforcement sit in RCF-0083 and RCF-0084.RCF-0083Remote access · ProcesssupportsThis process control sets up every remote worker's access through the approved secure route with training, the enforcement that makes A.6.7's policy real in practice.RCF-0084Remote access · TechnicalsupportsThis technical control restricts remote connections to encrypted VPN or zero-trust access from enrolled devices only, the technical backbone A.6.7 requires.RCF-0152MDM/MAM · ProcesssupportsThis process control enrols every work-connected mobile device in management before it can reach company data, covering the mobile side of A.6.7's remote work scope.RCF-0187VPN management · PolicysupportsThis policy control governs who may use the VPN, from which devices and with what authentication, a specific instance of the remote access policy A.6.7 requires.RCF-0188VPN management · ProcesssupportsThis process control provisions VPN access only on approval and removes it promptly when no longer needed, the lifecycle discipline A.6.7 expects of remote access.RCF-0189VPN management · TechnicalsupportsThis technical control requires MFA, current encryption and restricted internal reach on the VPN, the technical enforcement A.6.7 requires for remote connections.RCF-0291Alternate work sites · TechnicalrelatedThis technical control sizes secure remote access so the whole company can work off-site at once, a business continuity angle on the same remote working capability A.6.7 covers.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

VPN and remote access configuration
How employees connect securely to company systems when working outside the office: VPN, remote-access rules and allowed devices.
Mobile device management configuration
The tool that manages work phones and tablets, able to enforce security rules and remotely wipe a lost device.
From the Sekit evidence catalog

In practice

In practice remote working security comes down to one question: can an employee reach company systems from an unmanaged personal laptop over open wifi, or is every connection forced through an approved VPN or zero-trust gateway with MFA. Auditors ask to see the remote access configuration and a sample of enrolled devices, then check whether any internal service is reachable directly from the internet, bypassing the VPN entirely. The common gap is a policy that reads correctly but a handful of legacy services left exposed because migrating them to the VPN was deferred and never revisited.

Common gaps

A handful of internal services remain directly reachable from the internet, bypassing the VPN or zero-trust gateway the policy claims is mandatory.
Personal devices connect to email or file storage without ever being enrolled in mobile device management, so lost devices cannot be remotely wiped.
VPN accounts for former employees or old contractors were never removed and still show as active in the access list.

Questions your auditor will ask

Can any internal service be reached directly from the internet, bypassing remote access controls?
The VPN and remote access configuration is reviewed specifically for this, and any exception must be justified and time-limited.
Is multi-factor authentication enforced on every remote connection?
The VPN configuration requires MFA for all users before granting network access, with no bypass path documented.
How are lost or stolen mobile devices handled?
Enrolled devices are managed through the mobile device management platform, which can remotely wipe company data on a lost or stolen phone.
Who approves and reviews VPN access?
VPN accounts require approval before provisioning, and the account list is reviewed periodically to remove access no longer needed.

Where regulation demands it

NIS2 11.7 requires multi-factor authentication, which A.6.7 expects on every remote connection into company systems.
ENS mp.eq.2 requires screen locking on workstations, part of the same discipline of securing devices used outside the office under A.6.7.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.6.7?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk
  1. In Claude or ChatGPT, add a custom connector and paste this URL.
  2. Sign in with your email to finish. Free, read-only, no organization required.