Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Operations Manager

previous version on gdrive

A.7.9 Security of Assets Off-Premises

Travel & International Teleworking Procedure

Personnel who infrequently work from abroad (defined as less than twice a year) must complete the following mandatory authorization workflow prior to departure:

1. Ticket Submission

Create a formal request ticket within the internal system titled Teleworking request. The ticket must be submitted with the tag teleworking.

2. Mandatory Declarations & Information

The travel ticket must explicitly contain the following details and compliance agreements:

  • Logistics: Exact international location(s) and the specific time period of travel.

Security Note: This data is critical for our Identity Protection systems. Unannounced international authentication attempts will trigger automated risk blocks on your accounts.

  • Environmental Safety: Formal agreement that you will operate exclusively from a verified, safe, and secure environment (e.g., a private residence or secured corporate facility).

  • Network Security: Commitment to utilize only secure, encrypted Wi-Fi or wired connections. If forced to handle tasks in public transit or shared spaces, a corporate VPN must be continuously enabled.

  • Rigorous Data Locality Constraints: Express agreement that no company data will be stored locally on the endpoint. This mitigates the risk of exposure due to physical device theft. Local storage restrictions specifically include:

  • The device Desktop environment.

  • The internal drive (C:\, home/, SSD/HDD).

  • Removable storage media (USB flash drives, SD cards).

  • All operational data must remain natively inside our MFA-protected cloud ecosystems (Google Workspace for business staff, Azure DevOps for engineering teams).

  • Workspace Standards: Agreement to fully maintain the A.07.07 Clear Desk and Clear Screen protocols while abroad.

  • Incident Awareness: Confirmation that you understand the immediate escalation pathways outlined in A.06.08 if the device is lost, compromised, or stolen.

3. Review and Lifecycle

  • Approval: The Management Team must review and explicitly approve the ticket before the employee travels.
  • Closure: The tracking ticket will remain in an active, open state for the duration of the trip and will only be closed upon the employee’s confirmed return to their primary country of residence.

Administration & Audit Tracking

  • Historical Records: All international travel requests are logged and retained for compliance review. To audit past travels, navigate to Views > Archived > Archived tickets and filter or search for the teleworking tag.
  • Technical Constraints: Enforcement of travel-based conditional access and geo-blocking exceptions is managed by the Security Team based on approved ticket parameters.