How to use ISO 27001 to Secure Data When Working Remotely

How to use ISO 27001 to Secure Data When Working Remotely
Representative Picture. Image Credit: ANI

Although remote work has gained a lot of visibility as a solution for the continuity of operations for many companies in these pandemic times, its adoption in an appropriate way requires certain planning and testing that many companies have not had time to carry out.

As a result, several of these companies now face greater risks related to the compromise of their data, as they are stored in locations, or transmitted by channels, where they have no control. And, to make matters worse, many of these companies also have no idea on how to start protecting their data.

Fortunately, the market already has frameworks that can help in this situation, one of which is ISO 27001, an internationally recognized standard that addresses information security management.

This article will present in a more direct way how ISO 27001 controls can help an organization to protect data outside its limits, whether they are simply stored or are being communicated.

Common risks related to data located off-premises

From a business perspective, some of the common risks to which company data are subjected when outside its controlled environment are:

  • Data being viewed by an unauthorized person when working in shared spaces
  • User laptops being infected by malware
  • Data being compromised through network hacking
  • Company device being used by persons other than the employee
  • Company data is stored on the user's own device

And while a quick Internet search can show several good solutions on how to deal with these risks, the lack of a systematic approach can cause a company to overprotect data, negatively impacting performance, or to leave critical risks unproperly treated, leaving data without adequate protection.

ISO 27001

ISO 27001 is the leading information security standard published by the International Organization for Standardization (ISO). It defines the requirements for systematic protection of information, in the form of an Information Security Management System (ISMS), which is applicable to organizations of any size and industry.

Its Annex A provides a set of information security controls covering organizational, technical, and physical aspects, which can help companies to implement robust protection for their data located off-premises.

The selection of controls is based on the identification of applicable legal requirements (e.g., laws, regulations, and contracts), and in a company-defined risk management methodology. These approaches allow a company to select controls in a cost-effective way - no more and no less than what the business requires.

Protection using on-site controls

Considering the previously mentioned risks, the implementation of robust data protection where the data are located, taking into account controls from ISO 27001 Annex A, would include:

- A.9.4.1 – Information access restriction: the use of cryptographic solutions to ensure that even if the stored data is lost or stolen, it cannot be read by unauthorized persons.

- A.11.1.1 – Physical security perimeter: work in places where people traffic is not common (e.g., rooms and offices), decrease the risks of unauthorized persons being capable of gaining access to data.

- A.11.1.2 – Physical entry controls: an additional layer of security to the physical security perimeter, the adoption of simple lockable doors, which can have a huge effect in protecting data stored onsite.

- A.11.2.6 – Security of equipment and assets off-premises: basic practices like not leaving equipment and media unattended, and leaving it safely locked after working hours.

- A.11.2.9 – Clear desk and clear screen policy: Even when away from your work desk for just a few minutes, you should consider blocking access to your workstation and keeping paper information off of your desk.

- A.12.2.1 - Controls against malware: Anti-virus and anti-spam are examples of tools you can implement so defective software inside your laptop or computer cannot be exploited to compromise information.

- A.12.3.1 – Backup: Even the best security controls won't prevent all possible incidents, so it is better to be safe than sorry and create regular copies of your data and keep them in a safe place.

Protection using communication controls

Now, considering protection of data when in transit over uncontrolled channels, the controls from ISO 27001 Annex A to be taken into account would include:

- 8.3.3 Physical media transfer – Do not forget that data can be on paper media, or that you may have to send a pen drive or other electronic storage media by courier service, so you also need to consider a reliable service, and proper means to verify courier identity and pack the media.

- A.13.1.1 – Network controls: Adoption of Virtual Private Networks (VNPs) and connection authentication can help ensure that only authorized personnel have access to the data being transmitted.

- A.13.1.3 – Segregation in networks: In off-premises environments where you can have access to a minimal level of control (e.g., at the user's home, or a partner site), the ability to have a physically or logically separated network where company data can flow through will help increase data security.

Data is mobile, and so must also be its security

In order for information to be useful, it must be used, and this sometimes involves keeping it or sending it out of the company-controlled environment, increasing the risks of it being compromised.

However, such risks can still be minimized through good security practices, which in many cases are the same practices used within the company, with only a few adjustments.

ISO 27001 presents a set of security controls that can be adapted to the needs of data mobility, allowing business activities to be carried out within acceptable levels of risk.

Rhand Leal is an ISO 27001 expert and an author of many articles and white papers at Advisera. He holds a number of certifications, including ISO 27001, ISO 9001 Lead Auditor, CISSP, CISM, and PMP.

(Disclaimer: The opinions expressed are the personal views of the author. The facts and opinions appearing in the article do not reflect the views of Devdiscourse and Devdiscourse does not claim any responsibility for the same.)

Give Feedback

Use this form for editorial or site feedback. We usually reply within 2 to 3 working days.

By submitting, you agree that we may use your email address to respond.