ISO/IEC 27001:2022 · Annex A controls · derived mapping target
A.6.7Remote working
Set and apply security measures for staff who work remotely, covering devices, connections and home or public environments. Work outside the office should not mean protection is left behind.
Mapping at a glance
A.6.7Remote workingISO/IEC 27001:2022 · Annex A controls
What an auditor, or Sekit's evidence engine, asks for.
VPN and remote access configuration
How employees connect securely to company systems when working outside the office: VPN, remote-access rules and allowed devices.
Mobile device management configuration
The tool that manages work phones and tablets, able to enforce security rules and remotely wipe a lost device.
From the Sekit evidence catalog
In practice
In practice remote working security comes down to one question: can an employee reach company systems from an unmanaged personal laptop over open wifi, or is every connection forced through an approved VPN or zero-trust gateway with MFA. Auditors ask to see the remote access configuration and a sample of enrolled devices, then check whether any internal service is reachable directly from the internet, bypassing the VPN entirely. The common gap is a policy that reads correctly but a handful of legacy services left exposed because migrating them to the VPN was deferred and never revisited.
Common gaps
A handful of internal services remain directly reachable from the internet, bypassing the VPN or zero-trust gateway the policy claims is mandatory.
Personal devices connect to email or file storage without ever being enrolled in mobile device management, so lost devices cannot be remotely wiped.
VPN accounts for former employees or old contractors were never removed and still show as active in the access list.
Questions your auditor will ask
Can any internal service be reached directly from the internet, bypassing remote access controls?
The VPN and remote access configuration is reviewed specifically for this, and any exception must be justified and time-limited.
Is multi-factor authentication enforced on every remote connection?
The VPN configuration requires MFA for all users before granting network access, with no bypass path documented.
How are lost or stolen mobile devices handled?
Enrolled devices are managed through the mobile device management platform, which can remotely wipe company data on a lost or stolen phone.
Who approves and reviews VPN access?
VPN accounts require approval before provisioning, and the account list is reviewed periodically to remove access no longer needed.
Where regulation demands it
NIS2 11.7 requires multi-factor authentication, which A.6.7 expects on every remote connection into company systems.
ENS mp.eq.2 requires screen locking on workstations, part of the same discipline of securing devices used outside the office under A.6.7.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.