Skip to content

ISO 27001 ·

ISO 27001 and hybrid work: scope, devices and logging in 2026

August 2026. Hybrid and remote work are structural, but scope, SoA and audit evidence often lag reality. Certification bodies sample remote access, device posture and logging outside the office.

Scope and boundaries

Record which locations, devices and networks are in scope. Allow BYOD only with explicit policy and risk acceptance in management review. Remote work without MDM is a conscious choice, document residual risk.

Controls auditors check

  • MFA on all remote access, no exceptions for leadership;
  • endpoint: patch, encryption, screen lock, remote wipe;
  • logging: VPN, IdP, cloud apps, same retention as office;
  • awareness: remote work and phishing, metrics in review.

More: ISMS, ISO 27001 certification and readiness overview.

Review remote work annually or after major SaaS change. Scope drift is a common surveillance theme when teams adopt new tools without ISMS update.

Primary sources for this topic

Deep dive in the knowledge base

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

← Back to overview

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)