Policies, Procedures & Forms
Remote Working Policy Template
Security standards for remote and hybrid work: devices, home networks, VPN, document storage, and physical security — aligned with ISO 27001 control A.6.7.
- Format
- DOCX
- Size
- 15 KB
- Language
- Indonesian & English
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
In short
A remote working policy sets the security conditions for working outside the office: which devices may be used, how to connect, how information is handled in public spaces, and the duty to report loss or incident. ISO 27001 control A.6.7 requires security measures for remote working.
What This Document Is For
Remote working moves most security controls into places the organisation does not control: home networks with never-updated equipment, coworking spaces with open Wi-Fi, and screens visible to strangers. The office perimeter does not travel with the laptop.
This policy closes that gap with rules that work without expensive additional tooling. The decisive part is not the technical rules but clarity about what to do when something goes missing — a laptop left behind, a stolen phone — because reporting speed in the first hours determines how large the impact becomes.
What's Inside
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| ISO/IEC 27001:2022 | Control A.6.7 | Security measures for personnel working remotely. |
| ISO/IEC 27001:2022 | Control A.7.9 | Security of assets off-premises. |
| ISO/IEC 27001:2022 | Control A.8.1 | User endpoint devices and their protection. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
Is a VPN mandatory for all access?
It depends on the architecture. If internal systems are reachable only from the organisation's network, yes. If services are already cloud-based with strong authentication and device checks, a VPN for everything adds complexity without meaningful security. What matters is that the decision and its reasoning are written down.
How should personal devices be governed?
Set verifiable minimum conditions — encryption on, a supported operating system, screen lock enabled — and limit what information may be reached from a personal device. Permitting without conditions and banning outright both fail in practice.
Does this policy cover working from abroad?
It needs adding if that applies to you, because working from another jurisdiction raises cross-border transfer questions under the PDP Law and sometimes tax and employment obligations. This template leaves room for it, but the decision remains yours.
Need guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.