# SP-015 Secure Remote Working

Status: active. Release 26.02. Modified 2026-02-07. Licence: CC BY-SA 4.0.

Scope: Comprehensive remote and hybrid working security pattern covering endpoint hardening, ZTNA and VPN architectures, BYOD and corporate device management, split tunnelling, endpoint compliance verification, home network security considerations, collaboration platform security, and data loss prevention for distributed workforces. Addresses the post-pandemic reality where the corporate perimeter is the device, not the...
Use when: This pattern applies to every organisation with remote or hybrid workers -- which is now the majority. It is particularly critical for: financial services firms where regulators expect equivalent security controls regardless of work location, organisations processing sensitive personal data where GDPR breach risks increase with remote access, healthcare organisations accessing patient records remotely, legal and...
Not when: Organisations where all work is performed on-premises with no remote access requirements do not need this pattern -- but such organisations are increasingly rare.

## Controls (25, NIST SP 800-53 ids)
- Critical (10): AC-04, AC-17, AC-19, CM-02, CM-06, IA-02, SC-07, SC-08, SC-28, SI-03
- Important (12): AC-02, AC-06, AC-20, AT-02, AU-02, CA-07, CM-08, IA-05, MP-02, PE-17, SC-12, SI-04
- Standard (3): AC-22, MP-06, PM-14

## What each critical control mitigates (10)
- AC-04 Information Flow Enforcement: T-RW-004, T-RW-007, T-RW-009
- AC-17 Remote Access: T-RW-003, T-RW-005, T-RW-010
- AC-19 Access Control for Mobile Devices: T-RW-002, T-RW-004, T-RW-008
- CM-02 Baseline Configuration: T-RW-006
- CM-06 Configuration Settings: T-RW-002, T-RW-006, T-RW-008
- IA-02 Identification and Authentication (Organizational Users): T-RW-001, T-RW-008, T-RW-010
- SC-07 Boundary Protection: T-RW-003, T-RW-005, T-RW-006, T-RW-010
- SC-08 Transmission Confidentiality and Integrity: T-RW-001, T-RW-003
- SC-28 Protection of Information at Rest: T-RW-002, T-RW-009
- SI-03 Malicious Code Protection: T-RW-005, T-RW-006

## Threats and the controls that mitigate them (10)
- T-RW-001 Credential phishing targeting remote workers on unmanaged networks: IA-02, CA-07, AT-02, SC-08
- T-RW-002 Device theft or loss exposing corporate data stored locally: SC-28, CM-06, AC-19, MP-06
- T-RW-003 Man-in-the-middle attacks on untrusted WiFi networks: SC-08, SC-12, AC-17, SC-07
- T-RW-004 Data exfiltration through personal devices or unsanctioned cloud storage: AC-04, AC-19, SI-04, MP-02
- T-RW-005 Lateral movement from compromised remote endpoint into corporate network via VPN: SC-07, AC-06, AC-17, SI-03
- T-RW-006 Home network compromise spreading to corporate device via IoT or family devices: SI-03, CM-02, SC-07, CM-06
- T-RW-007 Shadow IT adoption due to overly restrictive remote access controls: AC-20, SI-04, AC-04, PM-14
- T-RW-008 Unauthorised access from non-compliant or jailbroken personal devices: CM-06, AC-19, IA-02, CA-07
- T-RW-009 Confidential information exposure through screen sharing, printing, or physical observation: PE-17, AC-04, SC-28, AT-02
- T-RW-010 VPN credential compromise providing full network access to attacker: IA-02, SC-07, AC-17, SI-04

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-015/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-015/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 29 KB: /api/v1/patterns/SP-015
- Page for people: /patterns/sp-015/
- Related: SP-006 Wireless Private Network Pattern; SP-007 Wireless Public Hotspot Pattern; SP-017 Secure Network Zone Module; SP-029 Zero Trust Architecture; SP-032 Modern Authentication

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
