Implement security measures to protect information accessed, processed or stored at remote working sites.
Also written as A6.7, Annex A 6.7, ISO 27001:2022 A.6.7, ISO27001 A.6.7.
Remote working is one of 8 People Controls in ISO/IEC 27001:2022 Annex A. Implement security measures to protect information accessed, processed or stored at remote working sites. People controls are tested against HR records, so the evidence usually lives outside the security team — joiner/mover/leaver files, training completions, and signed acknowledgements need to reconcile with your current headcount.
When preparing your Statement of Applicability (SoA) for A.6.7, gather artefacts such as:
If you run more than one framework, the same evidence usually satisfies all of them. A.6.7 aligns with:
SOC 2: CC6.6 Protection against external threats, CC6.7 Protection of data in transmission and movement
NIST CSF 2.0: PR.AA-05 Access authorization and least privilege, PR.DS-02 Data-in-transit protection, PR.IR-01 Network protection from unauthorized access
A.6.7 consolidates the following ISO 27001:2013 control(s): A.6.2.2. If you are transitioning an existing ISMS, map your prior evidence for these to A.6.7 in your updated SoA.
Annex A controls are not mandatory in the abstract. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify, in the Statement of Applicability, any control you exclude. If your risk assessment surfaces a risk that A.6.7 addresses, excluding it needs a documented, risk-based rationale that an auditor will test.
In two passes. First design: does a documented control exist, is it owned, and does it address the risk? Then operating effectiveness: the auditor samples records from across the audit period to confirm the control actually ran. A Stage 2 audit will typically pull several samples, so evidence that only exists for the month before the audit is a common finding.
ISO 27001 sets no fixed interval — it requires review at "planned intervals" and after significant change. Annual review is the norm most certification bodies expect, with an out-of-cycle review triggered by incidents, major system changes, restructures, or new regulatory obligations. Record the review date and outcome either way; an undated control is treated as unreviewed.
A.6.7 aligns with SOC 2 CC6.6, CC6.7 and NIST CSF PR.AA-05, PR.DS-02, PR.IR-01. Evidence gathered for one framework will usually satisfy the others, which is the basis for a test-once, satisfy-many control library.
A.6.7 consolidates 1 control(s) from the 2013 edition: A.6.2.2. When transitioning, re-point the existing evidence rather than rebuilding it — the underlying requirement has not changed materially.