Remote Working Policy Template
Security standards for remote and hybrid work: devices, home networks, VPN, document storage, and physical security — aligned with ISO 27001 control A.6.7.
In short
A remote working policy sets the security conditions for working outside the office: which devices may be used, how to connect, how information is handled in public spaces, and the duty to report loss or incident. ISO 27001 control A.6.7 requires security measures for remote working.
- Format
- DOCX
- Size
- 15 KB
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
What This Document Is For
Remote working moves most security controls into places the organisation does not control: home networks with never-updated equipment, coworking spaces with open Wi-Fi, and screens visible to strangers. The office perimeter does not travel with the laptop.
This policy closes that gap with rules that work without expensive additional tooling. The decisive part is not the technical rules but clarity about what to do when something goes missing — a laptop left behind, a stolen phone — because reporting speed in the first hours determines how large the impact becomes.
Most Useful For
- Organisations with hybrid or permanently remote working arrangements
- Teams pursuing ISO 27001 who need to satisfy control A.6.7
- Companies engaging remote contractors with access to internal systems
What's Inside
Device requirements
Which devices may be used, and encryption, patching, and endpoint protection duties.
Network security
Rules for home and public networks, VPN use, and the prohibition on unprotected tethering.
Physical workspace
Screen privacy, storage of printed documents, and locking devices when unattended.
Information handling
Limits on storing and printing classified information away from the office.
Incident reporting
What to report, to whom, and within what deadline when a device is lost or accessed by others.
Personal devices (BYOD)
Minimum conditions when personal devices are used to access organisational information.
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| ISO/IEC 27001:2022 | Control A.6.7 | Security measures for personnel working remotely. |
| ISO/IEC 27001:2022 | Control A.7.9 | Security of assets off-premises. |
| ISO/IEC 27001:2022 | Control A.8.1 | User endpoint devices and their protection. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
Is a VPN mandatory for all access?
It depends on the architecture. If internal systems are reachable only from the organisation's network, yes. If services are already cloud-based with strong authentication and device checks, a VPN for everything adds complexity without meaningful security. What matters is that the decision and its reasoning are written down.
How should personal devices be governed?
Set verifiable minimum conditions — encryption on, a supported operating system, screen lock enabled — and limit what information may be reached from a personal device. Permitting without conditions and banning outright both fail in practice.
Does this policy cover working from abroad?
It needs adding if that applies to you, because working from another jurisdiction raises cross-border transfer questions under the PDP Law and sometimes tax and employment obligations. This template leaves room for it, but the decision remains yours.
Related Reading
Background that helps you fill this document in correctly, rather than merely filling it in.
Documents Often Taken Together With This One
Policy, Procedure & Form Template Pack
A ready-to-use collection of information security policy, procedure, and form templates.
Free DownloadAI Usage Policy Template
A generative AI acceptable-use policy template for employees: permitted use, confidential data input restrictions, output review, and accountability — aligned with the direction of ISO/IEC 42001.
Free DownloadAcceptable Use Policy (AUP) Template
Ground rules for company devices, networks, email, and internet use — including prohibited activities, user responsibilities, and consequences, aligned with ISO 27001 control A.5.10.
Free DownloadNeed guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.