Policies, Procedures & FormsFree

Remote Working Policy Template

Security standards for remote and hybrid work: devices, home networks, VPN, document storage, and physical security — aligned with ISO 27001 control A.6.7.

In short

A remote working policy sets the security conditions for working outside the office: which devices may be used, how to connect, how information is handled in public spaces, and the duty to report loss or incident. ISO 27001 control A.6.7 requires security measures for remote working.

Format
DOCX
Size
15 KB
Price
Free

Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.

What This Document Is For

Remote working moves most security controls into places the organisation does not control: home networks with never-updated equipment, coworking spaces with open Wi-Fi, and screens visible to strangers. The office perimeter does not travel with the laptop.

This policy closes that gap with rules that work without expensive additional tooling. The decisive part is not the technical rules but clarity about what to do when something goes missing — a laptop left behind, a stolen phone — because reporting speed in the first hours determines how large the impact becomes.

Most Useful For

  • Organisations with hybrid or permanently remote working arrangements
  • Teams pursuing ISO 27001 who need to satisfy control A.6.7
  • Companies engaging remote contractors with access to internal systems

What's Inside

01

Device requirements

Which devices may be used, and encryption, patching, and endpoint protection duties.

02

Network security

Rules for home and public networks, VPN use, and the prohibition on unprotected tethering.

03

Physical workspace

Screen privacy, storage of printed documents, and locking devices when unattended.

04

Information handling

Limits on storing and printing classified information away from the office.

05

Incident reporting

What to report, to whom, and within what deadline when a device is lost or accessed by others.

06

Personal devices (BYOD)

Minimum conditions when personal devices are used to access organisational information.

Standards & Regulations It Helps Satisfy

Standard / RegulationClause / ArticleWhat this document covers
ISO/IEC 27001:2022Control A.6.7Security measures for personnel working remotely.
ISO/IEC 27001:2022Control A.7.9Security of assets off-premises.
ISO/IEC 27001:2022Control A.8.1User endpoint devices and their protection.

This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.

Questions About This Document

Is a VPN mandatory for all access?

It depends on the architecture. If internal systems are reachable only from the organisation's network, yes. If services are already cloud-based with strong authentication and device checks, a VPN for everything adds complexity without meaningful security. What matters is that the decision and its reasoning are written down.

How should personal devices be governed?

Set verifiable minimum conditions — encryption on, a supported operating system, screen lock enabled — and limit what information may be reached from a personal device. Permitting without conditions and banning outright both fail in practice.

Does this policy cover working from abroad?

It needs adding if that applies to you, because working from another jurisdiction raises cross-border transfer questions under the PDP Law and sometimes tax and employment obligations. This template leaves room for it, but the decision remains yours.

Related Reading

Background that helps you fill this document in correctly, rather than merely filling it in.

Need guidance, not just a template?

A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.