# Remote and hybrid working policy

Source: https://aestech.com.au/policy-templates/#remote-working-policy
Markdown URL: https://aestech.com.au/policy-templates/remote-working-policy.md

Use for ISO 27001 A.6.7, remote and hybrid work arrangements, home office security, and SOC 2 endpoint and access controls.

Frameworks: ISO 27001, SOC 2

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines the security requirements that apply when staff work away from company premises, including working from home, while travelling, and in public or shared spaces. It exists so that the confidentiality, integrity and availability of company and customer information does not depend on where the work happens.

2. Scope
This policy applies to all employees, contractors and third parties who access company information or systems from any location outside company-controlled offices, using company-issued or approved personal devices.

3. Policy statements
- Remote work is permitted only on devices that meet the requirements of the [endpoint and mobile device policy], including disk encryption, screen lock, endpoint protection and a supported operating system.
- Home networks used for company work must have the router administrator password changed from the default, use WPA2 or WPA3 encryption, and have remote administration disabled.
- Company information must be accessed only through approved tools and services listed in [approved tools register]. Personal email, personal cloud storage and unapproved messaging apps must not be used for company data.
- In public or shared spaces, staff must use a privacy screen where practical, position screens away from overlooking, never leave devices unattended, and avoid discussing confidential matters where they can be overheard.
- Public wifi may be used only with [company VPN or equivalent protection] enabled. Public charging cables and unknown USB accessories must not be used with company devices.
- Confidential papers must not be printed at home or in public facilities unless approved by [role], and must be stored locked and destroyed by [cross-cut shredding or approved return process].
- Household members and other third parties must not use company devices or view company information.

4. Roles and responsibilities
- Staff: comply with this policy, maintain their home working environment, and report issues.
- Managers: confirm remote arrangements are appropriate for the role and data involved.
- [IT or security lead]: maintain the approved tools register, VPN and device controls.

5. Procedures
- New remote workers complete the [remote work checklist] before their first remote day.
- Exceptions are requested through [ticketing system] and approved by [role].
- Lost or stolen devices, suspected compromise, or accidental disclosure while remote must be reported to [security contact] within [1 hour] of discovery.

6. Evidence and records
Keep signed policy acknowledgements, remote work checklists, VPN and device management enrolment reports, exception approvals and incident tickets relating to remote work.

7. Review
Owner: [role]. Reviewed at least annually and after any incident or material change to remote working arrangements.
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md