Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Operations Manager

previous version on gdrive

A.6.7 Remote Working

Control Objective

Security measures shall be implemented when personnel are working remotely to protect information accessed, processed or stored outside the organisation’s premises.

Policy Statement

As a remote-first organization with no physical office infrastructure, anDREa mandatorily applies its information security baselines across all remote working environments. Security integrity is maintained through a combination of endpoint protection, strict data handling rules, centralized identity controls, and mobile device management (MDM).


1. Mobile Device Security & Endpoint Management

All endpoints used to access anDREa networks must comply with:

Device Provisioning and Enrollment

  • anDREa-Issued Devices: Must be immediately enrolled via the steps in Enrolling a Device (anDREa Employees). Endpoints are automatically managed via Google Endpoint Management.
  • Bring Your Own Device (BYOD): Personnel using personal hardware must install an isolated, designated anDREa Work Profile. Non-work applications and corporate data must remain strictly segregated.
  • MDM Enforcement & Wipe Authority: Users acknowledge that anDREa enforces mandatory PIN/biometrics, inactivity locks, and compliance checks via MDM. Non-compliant devices will face automated data-access revocation. Users explicitly accept that anDREa retains the administrative authority to remotely wipe the device without warning to protect corporate data.

Technical Device Baselines

  • Patch Management: All operating system and security updates must be applied promptly; critical patches must be installed within 72 hours of release.
  • Local Encryption: Full disk encryption is mandatory for all endpoints. Windows devices must utilize BitLocker; macOS must manually enable FileVault; ChromeOS full-disk encryption must be verified via chrome://system (confirming mount-encrypted).
  • Endpoint Protection: Devices must run industry-accepted malware protection (e.g., Windows Defender, Microsoft Defender for Mac, or Bitdefender for ChromeOS).
  • Network Security: Secure VPN extensions (e.g., NordVPN) must be enabled when connecting to public networks or untrusted connections lacking WPA2/WPA3 wireless protection. Home, secure personal hotspots, and Eduroam are considered pre-approved networks.
  • Physical Guarding: Devices must never be left unattended in public. While working, if a device is left unattended for any duration, it must be locked instantly using biometric authentication, a secure password, or a PIN (see A.07.07).

Hardware Lifecycle and Lifecycle Changes

When decommissioning, replacing, or changing an endpoint, hard disk, or storage medium, personnel must execute the following and report completion to the Security Officer:

  1. Revoke and delete the corporate anDREa Work Profile.
  2. Back up and safely migrate all business files to the cloud, then permanently purge local directories and empty recycling bins.
  3. Perform a full cryptographic factory reset/wipe of the media carrier. Securely damage the drive physically if it is being permanently retired.
  4. The Security Officer logs this attestation and reserves the right to perform random compliance audits.

2. Teleworking & Data Handling Procedures

Personnel must systematically manage their environments to minimize exposure risks:

  • Travel and International Remote Work: Personnel must consult the Security Officer prior to conducting work outside their primary country of registration. Travel security is governed under A.07.09: Security of Assets Off-Premises.

  • Account Integrity: Corporate accounts (mydre.org or andrea-cloud.com) must be used exclusively for authorized business tasks and are prohibited from being linked to personal third-party subscriptions.

  • Data Locality & Transfer Controls: * Personnel should work natively within MFA-protected cloud repositories rather than downloading files locally.

    • High/Confidential data must never be transmitted as direct email attachments; instead, securely share assets via Google Workspace or myDRE cloud links using granular, email-specific Role-Based Access Control (RBAC).
    • Local storage is permissible only if its loss does not disrupt operations and allows the user to rebuild a standard workflow on a vanilla device within one week.
  • Removable Media Constraints: The use of USB flash drives or external media carriers is heavily discouraged. If unavoidable, the media carrier must be fully encrypted. Untrusted or third-party USB drives must never be inserted into anDREa-managed devices. All local data not classified as Low must be synced to the cloud prior to external media transfers.


3. Centrally Managed Security Controls

anDREa deploys enterprise-grade configurations to enforce remote access boundaries across our cloud environments:

Authentication and Access Baselines

  • Core SaaS (Google Workspace & 1Password): Enforces mandatory Group-membership parameters paired with strict Multi-Factor Authentication (MFA).
  • Production Platforms (myDRE): Managed entirely via conditional access policies and explicit RBAC. Access requires verified credentials or an approved external guest identity within anDREa Entra ID. Authentication demands multi-factor confirmation combining number matching, geolocation validation, and application context.
  • Privileged Access: The Research Support Team utilizes Azure Privileged Identity Management (PIM) for just-in-time elevation control. Third-party application integrations (OAuth apps) are blocked unless formally approved by the Director.

Emergency Enforcement Capabilities

The Management Team maintains automated mechanisms to instantly respond to threats or device losses by executing:

  • Instant global user account blocking and session revocation.
  • Remote credential and MFA token resets.
  • Centralized security logging acquisition for investigation and potential escalation to A.06.04: Disciplinary Process.