Vendor-neutral guide · 9 min read

ISO/IEC 27001:2022 and remote support: the Annex A controls involved

Written by the 247connect Marketing Team

Shape of the topic

A standards clause list linked to a shield of controls and an evidence file with an audit tick.A standards clause list linked to a shield of controls and an evidence file with an audit tick.
A control, the evidence for it, and a reviewer who signs it off: that chain is what an audit actually looks at.

In short

ISO/IEC 27001 is the international standard for an information security management system, a documented, risk-based way of protecting information that an organisation can have independently certified. The 2022 revision reorganised the reference controls in Annex A into four themes: organisational, people, physical and technological. Remote support and remote access do not have a control named after them, but they touch a recognisable subset of Annex A, particularly around access control, cryptography, logging and supplier relationships. This guide maps those controls to remote access decisions and to the evidence an auditor is likely to ask for.

Key takeaways

  • ISO/IEC 27001:2022 organises Annex A into organisational, people, physical and technological control themes, with 93 controls in total.
  • Remote support intersects mainly with access control, cryptography, logging and monitoring, and supplier relationship controls.
  • Certification audits look for documented evidence: policies, logs and records, not just described intentions.
  • Named accounts, encryption and audit logs give an organisation concrete evidence against several controls at once.
  • A statement of applicability should explain why each relevant control is included and how it is met, including for remote access.
  • Because ISO 27001 scope decisions vary by organisation, specific certification questions should go to a UKAS-accredited certification body.

How ISO 27001 is structured

The standard has two parts: the main clauses, which describe how an information security management system should be planned, run, checked and improved, and Annex A, a reference set of controls an organisation draws on to address the risks it identifies. The 2022 revision reduced the previous fourteen control categories into four themes and 93 controls, several of which were newly introduced, including ones covering threat intelligence, data masking and web filtering.

Organisations are not required to implement every Annex A control. Instead, they run a risk assessment, decide which controls are relevant, and record the outcome in a statement of applicability. Remote access controls become relevant the moment an organisation identifies remote access, whether inbound support or outbound working, as part of its information security risk landscape, which in practice is almost always.

Access control (A.5.15 to A.5.18, A.8.2 to A.8.5)

The access control group covers how access rights are granted, reviewed and removed, how privileged access is managed, and how authentication is enforced. Remote access is a direct application of these controls: every remote session represents a granted access right, and the standard expects that right to be based on business need, reviewed periodically, and revoked when no longer required.

Secure authentication (A.8.5) specifically expects strong authentication methods appropriate to the risk, which in practice means multi-factor authentication for remote access to anything sensitive. Auditors typically ask to see the access control policy, a sample of access review records, and evidence that leaver accounts were disabled within a reasonable timeframe.

  • Access rights granted on a documented business need, not by default
  • Privileged and remote access reviewed on a defined schedule
  • Strong authentication required in proportion to the risk of what is being accessed

Cryptography and network security (A.8.24, A.8.20 to A.8.23)

The cryptography control asks organisations to define and apply rules for the use of encryption, appropriate to the classification of the information involved. Remote support sessions that carry screen content, keystrokes and file transfers should be encrypted in transit, and organisations should be able to state which encryption standard is used and why it is considered adequate.

Network security controls cover segregation, monitoring and secure configuration of networks and network devices, which extends to how a remote access gateway or agent sits within the network architecture. A remote access product using AES-256 encryption for session data, of the kind offered by tools such as 247connect, gives an organisation a concrete answer when an auditor asks how remote sessions are protected in transit, though the wider network architecture around it still needs to be assessed on its own merits.

Logging and monitoring (A.8.15, A.8.16)

Logging (A.8.15) requires event logs recording user activities, exceptions and security events to be produced, retained and reviewed. Monitoring activities (A.8.16) expects networks and systems to be monitored for anomalous behaviour. Remote access sessions are exactly the kind of event these controls are aimed at: who connected, to what, for how long, and whether anything about the session looked unusual.

For an auditor, the useful evidence is not a claim that logging exists but a sample log extract showing operator identity, timestamp, target system and duration, alongside evidence that logs are actually reviewed rather than only stored. A log nobody ever looks at satisfies the letter of the control poorly, even if it technically exists.

  • Retain remote access logs for a defined, documented period
  • Review logs on a schedule, not only after an incident is already suspected
  • Be able to produce a sample log extract on request during an audit

Supplier relationships (A.5.19 to A.5.23)

Where remote access is provided by a third party, such as an IT support company connecting into client systems, or where a remote access product is bought from a vendor, the supplier relationship controls apply. These expect organisations to assess information security risk in supplier relationships, address security requirements in agreements, and monitor supplier performance against those requirements.

In practice this means a documented view of what any remote access vendor or supplier can reach, what their own security practices are, and how that risk is reviewed over the life of the relationship, rather than assessed once at the point of purchase and never revisited.

Best-practice checklist

  1. 1. Identify remote access in the risk assessment

    Confirm remote support and remote working access are explicitly considered assets or processes within the information security risk assessment.

  2. 2. Include relevant controls in the statement of applicability

    Record which access control, cryptography, logging and supplier controls apply to remote access, and how each is met.

  3. 3. Enforce named accounts and MFA

    Apply strong authentication to remote access in line with A.8.5, sized to the sensitivity of what is being accessed.

  4. 4. Document the encryption standard in use

    Record which encryption protects remote session data in transit and confirm it meets the organisation's cryptography policy.

  5. 5. Set a log retention and review schedule

    Define how long remote access logs are kept and how often they are actually reviewed, then follow the schedule.

  6. 6. Review remote access rights periodically

    Run access reviews on a defined cycle and record the outcome, including any rights removed.

  7. 7. Assess remote access suppliers under A.5.19 to A.5.23

    Document the security requirements agreed with any remote access vendor or support supplier and how compliance is monitored.

  8. 8. Prepare a sample evidence pack before the audit

    Pull together a policy, an access review record and a log extract in advance, so evidence is ready rather than assembled under time pressure.

Common pitfalls

  • Treating remote access as out of scope because it is not named directly in Annex A
  • Having an access control policy that describes intentions but no records to show it is followed
  • Leaving logs unreviewed, so the control exists on paper but not in practice
  • Not documenting the security requirements agreed with a remote access vendor
  • Assuming a certified vendor product automatically satisfies the organisation's own certification requirements

What to measure

Metrics for ISO 27001 & remote support
Access review completionTrack against the defined review schedule
Remote accounts with MFA enforcedTarget 100%
Log review frequencyShould match the documented policy, not be ad hoc
Supplier security assessments completedTrack against total number of remote access suppliers

Select any column heading to sort.

Frequently asked questions

Does ISO 27001 require a specific remote access tool?
No, the standard is technology-neutral and does not mandate any product. It asks that access, encryption, logging and supplier risks are assessed and addressed with appropriate controls, which can be met by a range of tools provided the evidence is there.
Which Annex A controls are most relevant to remote support?
Primarily the access control group (A.5.15 to A.5.18, A.8.2 to A.8.5), cryptography (A.8.24), logging and monitoring (A.8.15, A.8.16), and supplier relationship controls (A.5.19 to A.5.23), since remote support touches identity, encryption, audit trails and third-party access.
What evidence does an ISO 27001 auditor ask for regarding remote access?
Typically a policy document, a sample of access review records, evidence of multi-factor authentication, a log extract showing who connected to what and when, and documentation of any remote access supplier's security requirements.
Do we have to implement every Annex A control to be certified?
No, organisations select controls based on their own risk assessment and record the decision in a statement of applicability, including a justification for excluding any control judged not applicable.
How is the 2022 revision different from the 2013 version for remote access purposes?
The 2022 revision consolidated and reorganised controls into four themes and added a small number of new controls, including ones touching data masking and web filtering, but the core expectations around access control, cryptography and logging that apply to remote access carried through with clearer structure rather than fundamentally new requirements.

Sources

Independent, standards-body and peer-reviewed material. None of these sources is affiliated with 247connect.

Putting it into practice

This guide is deliberately product-neutral. If you want to see how one implementation handles these requirements — attended and unattended access, named operator accounts, AES-256 encryption, audit logs and fixed pricing — the reference pages on this hub document 247connect in detail, and the product itself lives at 247connect.cloud.

More best-practice guides