Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Business Manager

previous version on gdrive

N.2.06 Working from home or hybrid in a safe way

Control Overview

This control mandates that the organization defines, communicates, and enforces strict security guidelines and technical baselines for information processing at external locations, such as home offices, co-working spaces, or during travel. Because remote and hybrid working environments lack the physical and network boundaries of a corporate office, the organization must implement specific defensive measures—including secure connectivity, comprehensive asset encryption, endpoint access restrictions, and clean-environment protocols—to prevent data leaks, unauthorized exposure, or accidental data loss.

note

Applicability Note: This control is highly critical and fully applicable to the anDREa platform, as it underpins our fully remote operational model.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement incorporates remote endpoint governance directly into our ISO/IEC 27001-based ISMS, treating the remote workplace as a secure, logical extension of our primary infrastructure.

Since anDREa operates as a fully remote organization, our A.06.07 - Remote working enforces a zero-trust model at the endpoint layer. We do not rely on local network safety; instead, all company-issued devices must employ mandatory full-disk encryption and enforce Multi-Factor Authentication (MFA). When operating on untrusted or public networks, secure corporate VPN channels are mandatory. Operational guardrails extend to physical environments, mandating automated screen locks and strict clear-desk/clear-screen behaviors. Furthermore, device lifecycles—including the changing, de-provisioning, or lifecycle disposal of remote hardware—are managed centrally to guarantee that no anDREa or client data is ever left exposed on retired local media.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.06.07 - Remote workingMandates security measures to protect information accessed, processed, or stored at remote working sites.
ISO/IEC 27001A.07.14 - Secure disposal or re-use of equipmentEnforces secure erasure, sanitization, or destruction of local hardware components when decommissioning remote devices.
Core Operational PolicyA.06.07 - Remote workingThe authoritative manual defining network requirements, mandatory endpoint settings, physical environment rules, and reporting steps for lost hardware.
Endpoint ConfigurationEnrolling a Device (anDREa Employees)Automated Mobile Device Management (MDM) profiles proving forced full-disk encryption, automated inactivity screen-locks, and mandatory MFA.
Asset DecommissioningA.05.11 - Return of assetsTracking data and certificates of secure erasure proving remote endpoints are safely wiped before recycling or replacement.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Technical controls (MFA, MDM encryption, mandatory VPN) and behavioral standards for our fully remote operating model are thoroughly documented, automated, and enforced. Continuous Improvement: Ensure that any future operational deviations or the use of specialized localized development tools are formally risk-assessed and appended to this control profile.