A.6.7 People
Remote working
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (19)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AC-17mostlycovers — The ISO control establishes policy, technical safeguards, and monitoring requirements for all remote access to organizational systems, directly satisfying the core intent of AC-17.
- AC-19mostlycovers — By mandating controls over mobile and privately-owned devices used outside organizational premises, the ISO guidance fulfills the same objective as AC-19.
- AC-20mostlycovers — The requirement to define permitted external-system use, device ownership rules, and security mechanisms for remote locations aligns with AC-20’s scope.
- PE-17mostlycovers — Physical-security, visitor, and equipment-protection measures for alternate work sites are explicitly addressed, matching the intent of PE-17.
- IA-2partialaligns with — Guidance on multi-factor authentication and privilege enablement for remote access supports the identification-and-authentication requirements of IA-2.
- SC-7partialaligns with — Network-boundary protections and firewall requirements for remote connections partially satisfy the boundary-protection objective of SC-7.
- SI-3partialaligns with — Mandating malware protection on remote devices and networks contributes to the malicious-code-protection objective of SI-3.
- IA-2covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (30)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-01mostlyaligns with — The ISO control requires managed issuance, authentication, and revocation of remote-access credentials and privileges, directly supporting the CSF outcome of managing identities and credentials for authorized users and services.
- PR.AA-05mostlyaligns with — By defining permitted work, information classifications, and authorized internal systems for remote workers, the control establishes and enforces access permissions and entitlements in line with the CSF outcome.
- PR.AA-06mostlyaligns with — The control addresses physical security of remote sites, lockable storage, and protection against unauthorized physical access by family or visitors, matching the CSF outcome for managing and monitoring physical access commensurate with risk.
- PR.IR-01mostlyaligns with — Requirements for communications security, firewalls, malware protection, and secure remote-access mechanisms collectively protect networks and environments from unauthorized logical access, aligning with the CSF outcome.
- GV.PO-01partialaligns with — Issuing a topic-specific remote-working policy that defines conditions, restrictions, and risk-based controls directly fulfills the CSF outcome of establishing policy for managing cybersecurity risks based on organizational context.
- PR.AT-01partialaligns with — Training on secure remote-working practices and support procedures is required, satisfying the CSF outcome that personnel receive awareness and training to perform tasks securely.
- PR.PS-01partialaligns with — The control mandates secure configuration of home and public networks, device screen locks, inactivity timers, and remote-wipe capabilities, supporting the CSF outcome of applying configuration-management practices.
- GV.PO-01implements — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AA-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AA-05implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AA-06implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AT-01implements — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (11)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V13.2.1partialaligns with — The ISO control's emphasis on secure remote-access mechanisms and communications security for personnel outside organizational premises aligns with the ASVS requirement to protect backend communications that bypass standard user-session controls.
- V13.2.4partialaligns with — Defining permitted remote systems, services, and access privileges in the ISO policy corresponds to the ASVS requirement that an allow-list governs which external resources the application may communicate with.
- V13.3.2partialaligns with — The ISO guidance on restricting remote-worker access to only authorized internal systems and services aligns with the ASVS principle of least privilege for access to secret assets.
- V6.3.1partialaligns with — The ISO control's requirement for secure authentication mechanisms when granting remote access to organizational systems directly supports the ASVS mandate to implement controls against credential stuffing and brute-force attacks.
- V7.3.1partialaligns with — By mandating inactivity timers and device screen locks for remote workers, the ISO guidance aligns with the ASVS requirement to enforce session inactivity timeouts that trigger re-authentication.
Related weaknesses / CWE (3)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200prevents — Rules for physical security, clear-desk practices, secure transport, and restrictions on family or visitor access at remote sites reduce the probability that sensitive information will be exposed to unauthorized individuals in the remote environment.
- CWE-284prevents — Requiring a topic-specific remote-working policy that explicitly defines permitted work, information classifications, and authorized internal systems reduces the chance that personnel will be granted access to resources they should not reach from outside the premises.
- CWE-319mitigates — Specifying communications-security requirements and secure remote-access methods (including encryption expectations) prevents the transmission of sensitive data in cleartext over home or public networks.
Mitigated MITRE ATT&CK techniques (287)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1005prevents — A.6.7's policy, training, equipment rules, physical security, network restrictions, firewalls/malware protection, and remote-access mechanisms (VDI, MFA, device controls) constrain data exposure and collection on remote endpoints, but do not stop local-system searches once an adversary has obtained a foothold on a managed or unmanaged remote device.
- T1011prevents — A.6.7's policy, rules, training, and mandated security measures (firewalls, malware protection, comms requirements, home/public network restrictions, device controls) directly constrain the insecure secondary mediums and configurations that T1011 relies on in remote-working environments, but only for the organization's own remote workers and only where those measures are applied.
- T1016.002prevents — A.6.7's policy, training, network configuration rules, firewalls/malware protection, and remote-device controls (e.g. no unmanaged private equipment, secure remote access mechanisms) reduce the likelihood and success of an adversary already on a remote system enumerating Wi-Fi credentials via local commands or files, but do not stop the post-compromise discovery technique itself.
- T1021detects — A.6.7 explicitly requires audit, security monitoring, information security event reporting, and device location tracking/remote wipe, which can surface anomalous or unauthorized use of remote services (especially from unmanaged/home/public networks), but this is scoped only to the remote-working slice rather than all T1021 abuse vectors such as internal lateral movement via RDP/SSH on domain assets.
- T1021prevents — A.6.7's policy, training, authentication hardening, remote-access mechanisms, network restrictions and device controls directly constrain many vectors for obtaining/using valid credentials over remote services (especially from unmanaged/home/public sites), but stop short of universal enforcement on all enterprise remote services or credential acquisition paths.
- T1021.001detects — A.6.7 explicitly requires audit, security monitoring, information security event reporting, and device location tracking/remote wipe, which surface anomalous or unauthorized RDP sessions once underway; this is a genuine but minority slice of the technique (remote worker environments only, not all RDP usage or pre-authentication detection).
- T1021.001prevents — A.6.7's policy, training, authentication mechanisms, remote-access rules, device controls and network restrictions (including MFA consideration and single-factor warnings) directly constrain the conditions under which valid-account RDP logons can occur from remote sites, but do not eliminate the technique when credentials are already available or when the service is enabled on the target.
- T1021.004prevents — A.6.7's policy, training, authentication hardening (esp. against single-factor), remote-access mechanisms, network restrictions, and device controls directly constrain the conditions under which valid-account SSH logins from remote sites can occur, but do not eliminate the technique when the account is already authorized or when the remote worker's own legitimate SSH use is permitted.
- T1021.005detects — A.6.7 explicitly lists audit, security monitoring, training on secure remote practices, device tracking, and remote-access authentication requirements that can surface anomalous VNC usage or brute-force attempts against remote sessions, but only for organizationally sanctioned remote-working setups and not for arbitrary adversary VNC abuse on unmanaged endpoints.
- T1021.005prevents — A.6.7's policy, training, authentication hardening, remote-access mechanisms, network restrictions, and device controls (e.g. MFA consideration, screen locks, firewalls, no private equipment) directly constrain or block many abuse vectors for VNC-based remote control, but leave residual paths such as legitimate VNC use by valid accounts, public-network exceptions, and implementation-specific flaws like brute-force or memory exploits.
- T1021.006prevents — A.6.7's policy, training, authentication hardening, remote-access mechanisms, network restrictions and device controls can stop many remote-working scenarios that would otherwise allow an adversary with valid credentials to successfully invoke WinRM from outside the premises.
- T1021.008prevents — A.6.7's remote-working policy, authentication hardening (esp. against single-factor), network restrictions, device controls and training constrain many vectors for abusing valid accounts to reach cloud VMs from remote sites, but do not block the technique outright when performed from an authorized remote worker's approved endpoint.
- T1040detects — A.6.7 explicitly requires audit, security monitoring, and information security event reporting for remote working environments (including home/public networks and remote access), which can surface anomalous sniffing or related network events, but this is scoped only to remote-worker contexts rather than general network sniffing across all platforms and scenarios.
- T1040prevents — A.6.7's policy, training, network security requirements, firewalls/malware protection, secure remote access mechanisms, and restrictions on home/public networks directly constrain sniffing opportunities on remote worker links and devices, but leave untouched sniffing on internal networks, cloud traffic mirroring, network devices, and non-remote vectors.
- T1041detects — A.6.7 requires audit, security monitoring, communications security requirements, and rules for remote access and networks, which can surface anomalous exfiltration patterns over C2 channels from remote sites, but only where those monitoring scopes and mechanisms are defined and applied.
- T1041prevents — A.6.7's policy, communications security requirements, network configuration restrictions, firewalls, malware protection, secure remote access mechanisms and device controls (e.g. screen locks, remote wipe) can stop data from reaching an exfiltration channel in many remote-working scenarios, but do not address all C2 exfil paths or non-remote vectors and are not a universal barrier.
- T1048detects — A.6.7 explicitly requires audit, security monitoring, and information security event reporting for remote working, which can surface anomalous exfiltration (especially over alternate protocols or from remote sites), but only within the scoped remote-working slice rather than all T1048 instances.
- T1048prevents — A.6.7's remote-working policy, network/comms security requirements, restrictions on home/public networks, firewalls, malware protection, device controls and training reduce the feasible surface for exfiltration over alternate protocols from remote endpoints, but do not stop the technique outright (especially on IaaS/SaaS, unmanaged devices, or once data is already at the remote site).
- T1048.003detects — A.6.7 explicitly requires audit, security monitoring, and communications security requirements (including for remote/public networks and remote access), which can surface anomalous exfiltration over unencrypted non-C2 protocols from remote sites, but only where that monitoring is scoped to include it and does not address the technique on non-remote platforms or in non-remote scenarios.
- T1048.003prevents — A.6.7's policy, training, comms-security requirements, network restrictions, firewalls, malware protection and secure remote-access mechanisms (e.g. VDI, MFA) constrain or block many unencrypted exfil paths from remote sites, but leave residual cases (e.g. permitted protocols, public networks, or insider misuse of allowed channels) unaddressed.
- T1052detects — A.6.7 explicitly requires audit, security monitoring, information security event reporting, and device tracking/remote wipe, which can surface physical-medium exfiltration events (e.g. unauthorized USB use or data copy) when the remote worker or endpoint is in scope; it does not guarantee detection of every air-gapped or offline hop.
- T1052prevents — A.6.7's policy, rules on physical environment (lockable cabinets, clear desk, printing/disposal), equipment provisioning, training, family/visitor restrictions, and remote-site physical security directly constrain the introduction and use of removable media by authorized remote workers, preventing a meaningful slice of user-introduced exfiltration vectors; it does not address adversary-planted media, non-remote scenarios, or all air-gap hops.
- T1052.001detects — A.6.7 explicitly requires audit, security monitoring, and information security event reporting for remote working (including on home/public networks and removable media handling), which can surface anomalous USB usage or data movement in monitored environments, but this is scoped only to remote-worker assets and does not broadly instrument USB exfiltration across all platforms or air-gapped scenarios.
- T1052.001prevents — A.6.7's policy, training, equipment rules, physical security, clear-desk/printing/disposal guidance, and restrictions on privately-owned devices and home/public networks directly constrain the user-introduced USB vector for exfiltration in remote settings, but leave residual paths (e.g. authorized removable media, incomplete enforcement, or non-remote insider use).
- T1056.001detects — A.6.7 requires audit, security monitoring, and information security event reporting for remote working, which can surface anomalous keystroke-capturing behavior on monitored remote endpoints or networks, but only for the subset of remote-work scenarios the organization has placed in scope.
- T1056.001prevents — A.6.7's remote-work policy, training, device controls, network restrictions, malware protection and authentication requirements reduce the opportunity for keyloggers to be deployed or to succeed on remote endpoints, but do not stop all installation vectors or all keylogging methods (e.g. custom drivers, hardware buffer reads, or already-compromised remote devices).
- T1071.004detects — A.6.7 explicitly requires audit, security monitoring, and communication security requirements (including for remote access and public/home networks), which surfaces anomalous DNS traffic or tunneling in the remote working environment; this is a genuine but minority slice of the technique's full scope across all platforms and non-remote scenarios.
- T1078prevents — A.6.7's policy, training, authentication hardening (esp. against single-factor), remote-access mechanisms, device controls and network restrictions directly stop many ways valid accounts are obtained/abused for remote/VPN/RDP access; they do not address credential theft, inactive accounts, permission overlap or on-premise abuse vectors inside the organization.
- T1078.004prevents — A.6.7's remote-working policy, training, device controls, authentication hardening, and network restrictions (including MFA considerations and remote access mechanisms) reduce the likelihood of credential compromise or abuse for cloud accounts accessed from remote sites, but do not address on-premises compromise vectors, misconfigurations, privilege escalation inside the cloud, or creation of additional credentials.
- T1098.005prevents — A.6.7's policy, training, authentication hardening, device provisioning rules, and remote-access restrictions (including MFA considerations and forbidding uncontrolled private devices) constrain the self-enrollment and registration paths that enable T1098.005, but do not block all vectors such as credential-compromised enrollment or post-access Intune/Entra registration.
- T1110prevents — A.6.7 requires topic-specific remote-working policy, MFA-capable authentication mechanisms, device controls, training, and network restrictions that raise the bar for remote brute-force attempts (especially those leveraging external remote services or public networks), but leaves single-factor remote access, home/public network use, and non-remote brute-force vectors (offline, internal post-compromise) unaddressed.
- T1110.001prevents — A.6.7's policy, training, authentication hardening (esp. against single-factor), device controls, network restrictions, and remote-access mechanisms directly raise the bar on password guessing from remote sites, home/public networks, and unmanaged endpoints; the named remainder is non-remote guessing vectors and on-prem services that fall outside the remote-working scope.
- T1110.003prevents — A.6.7's policy, training, authentication mechanisms, MFA consideration, remote-access rules, device controls and network restrictions (firewalls, secure configs) stop many password-spraying vectors that rely on weak remote logins from unmanaged/home/public sites, but leave slices such as internal network spraying, SSO bypasses, or non-remote vectors untouched.
- T1110.004prevents — A.6.7's policy, training, MFA-aware auth requirements, device controls, and remote-access mechanisms (e.g. VDI, screen locks, firewalls) reduce credential-stuffing success on remote sessions and home networks, but do not stop the technique outright on all vectors or enforce password uniqueness.
- T1111prevents — A.6.7's policy, training, device controls, remote-access mechanisms, and MFA-aware authentication guidance (k) reduce the likelihood and surface of remote-work MFA interception vectors such as keyloggers, insecure out-of-band channels, and public-network exposure, but do not stop all described techniques (e.g., SMS provider compromise or hardware-token prediction).
- T1123detects — A.6.7 explicitly requires audit, security monitoring, and information security event reporting for remote working environments, which would surface anomalous audio-capture activity on monitored remote endpoints; this is only a slice of the technique's full scope across all platforms and non-remote scenarios.
- T1133detects — A.6.7 explicitly lists audit, security monitoring, information security event reporting, and device location tracking as measures to consider, which can surface anomalous remote access or persistence attempts, but these are optional considerations rather than a mandated detection mechanism and do not address all vectors such as unauthenticated exposed services or Tor hidden services.
- T1133prevents — A.6.7's policy, training, authentication hardening, network restrictions, device controls and remote-access mechanisms directly constrain several vectors in T1133 (weak single-factor auth, exposed unauthenticated services, insecure home/public networks, and unmanaged private equipment) but leave intact others such as valid-account compromise, Tor hidden services, and already-exposed container APIs.
- T1137.001prevents — A.6.7's remote-working policy, training, device controls, macro-aware authentication rules, and restrictions on privately-owned equipment and home/public networks constrain some vectors for planting or loading a malicious Office template/macro (especially on managed remote devices), but do not stop an adversary who already has code execution from modifying templates on the endpoint or hijacking search order/registry.
- T1187detects — A.6.7 explicitly lists audit and security monitoring plus information security event reporting as measures to consider for remote working; these surface anomalous authentication or outbound SMB/WebDAV to untrusted external resources, but the control is scoped only to remote-worker environments rather than enterprise-wide detection of the technique.
- T1189detects — A.6.7 explicitly requires audit, security monitoring, and information security event reporting for remote working environments, which surfaces anomalous activity (including drive-by indicators on remote endpoints) but only within the scoped remote-working slice rather than all platforms or non-remote browsing.
- T1189prevents — A.6.7's policy, training, device controls, network restrictions, firewalls, malware protection, and remote-access mechanisms (e.g. VDI, MFA) can stop many remote-user browsing paths that realize T1189, but the control is scoped only to approved remote-working setups and does not govern on-premises endpoints or all web-browsing behavior.
- T1200detects — A.6.7 requires audit, security monitoring, physical security, and event reporting that can surface unauthorized hardware additions at remote sites, but this is scoped only to the remote-working slice of the technique rather than the class as a whole.
- T1200prevents — A.6.7's policy, physical-security rules, equipment-provision mandate, visitor-access restrictions, and remote-site hardening directly constrain many hardware-addition vectors (e.g., rogue devices on home/public networks, unauthorized peripherals at remote sites), but cannot stop an adversary from physically introducing hardware at an uncontrolled remote location or during travel.
- T1204prevents — A.6.7's policy, training, equipment rules, network restrictions, malware protection, and remote-access authentication requirements reduce the chance a remote user will be socially engineered into executing malicious payloads or enabling RATs, but do not stop the technique outright (especially non-remote vectors or user error).
- T1204.001prevents — A.6.7's policy, training, remote-access rules, device controls, network restrictions, and malware protection reduce the chance a remote user will click a malicious link, but do not stop the social-engineering vector or the click itself.
- T1204.002prevents — A.6.7's policy, training, equipment rules, network restrictions, malware protection, and remote-access hardening (e.g. MFA, device controls) reduce the chance a remote user will open a malicious file, but do not stop the social-engineering lure or execution itself and leave many delivery vectors untouched.
- T1204.004prevents — A.6.7's remote-working policy, training, rules on family/visitor access, secure equipment, communication security, and malware/firewall measures reduce the chance a remote user will be socially engineered into pasting malicious commands from untrusted sites or emails, but do not stop the social-engineering vector itself or block execution once the user pastes.
- T1210prevents — A.6.7's remote-working policy, training, device controls, network restrictions, firewalls, malware protection, and secure remote-access mechanisms (e.g. VDI, MFA) reduce the likelihood and surface of remote-service exploitation when the adversary is operating from an approved remote endpoint, but do not stop exploitation of internal vulnerable services once an adversary is already inside the network.
- T1218.005detects — A.6.7 explicitly requires audit, security monitoring and training on secure remote conduct, which can surface anomalous mshta.exe usage or remote-launched HTA payloads when the activity occurs inside the monitored remote environment, but the clause sets scope by business needs rather than mandating universal process-level detection of this specific LOLBin technique.
- T1219detects — A.6.7 explicitly requires audit, security monitoring, and information security event reporting for remote working, which surfaces anomalous or unauthorized use of remote access tools post-compromise; this is a genuine but minority slice of the technique (e.g., only where remote sessions align with monitored remote-worker policy rather than arbitrary post-compromise C2 or built-in modules).
- T1219prevents — A.6.7's policy, training, equipment rules, network restrictions, firewalls/malware protection, secure remote mechanisms and authentication requirements constrain legitimate remote access tools from being installed/used unsanctioned or from insecure environments, stopping many adversary abuse paths, but cannot block all post-compromise or EDR-feature abuse of authorized tools.
- T1219.001prevents — A.6.7's remote-working policy, training, network restrictions, device controls, and secure remote-access mechanisms (including authentication hardening) constrain many developer/remote IDE tunneling scenarios on organizational assets, but do not stop an adversary from abusing IDE tunneling on a already-compromised internal machine or from a fully-authorized remote developer workstation.
- T1219.002detects — A.6.7 explicitly requires audit, security monitoring, and information security event reporting for remote working, which surfaces anomalous or unauthorized use of remote desktop software as part of its monitoring scope
- T1219.002prevents — A.6.7's policy, training, equipment rules, network restrictions, authentication hardening, and remote-access mechanisms (e.g. VDI, screen locks, MFA considerations) constrain or block many legitimate-desktop-support vectors for adversary C2, but do not eliminate all (e.g. allowed RMM tools, public-network use, or insider-enabled sessions).
- T1219.003prevents — A.6.7's policy, physical security, equipment provisioning, network restrictions, training, and remote-access mechanisms (e.g. no private equipment, device controls, authentication hardening) constrain many legitimate-hardware installation and bypass vectors in remote-working environments, but do not stop post-compromise physical installation or use of allowed KVM-style peripherals on managed or unmanaged endpoints.
- T1485recovers — A.6.7 explicitly requires procedures for backup and business continuity as part of remote-working policy and measures, which directly enables recovery from data destruction on remote endpoints or during remote sessions (the named slice the control reaches); it does not address on-prem servers, cloud infrastructure, or non-remote destruction.
- T1486recovers — A.6.7 requires procedures for backup and business continuity as part of remote-working policy and support, which can restore data after ransomware encryption; this is limited to remote-worker data and does not address the full scope of network-wide or cloud-object encryption on all platforms.
- T1490recovers — A.6.7 explicitly requires procedures for backup and business continuity plus suitable equipment/storage for remote workers, which directly supports recovery of data and systems after T1490 has deleted or disabled recovery features (e.g. restoring from unaffected remote/offsite backups), but this is only a slice of the technique's surface (on-prem, cloud, network-device, and local-execution vectors remain unaddressed).
- T1498recovers — A.6.7 requires procedures for backup and business continuity as part of remote-working policy and support, which can restore availability of information and services after a network DoS has ended, but the control is scoped only to remote workers and does not address general network or infrastructure recovery.
- T1499recovers — A.6.7 explicitly requires procedures for backup and business continuity as part of remote-working measures, which directly supports state restoration after an availability-impacting event such as endpoint DoS.
- T1528prevents — A.6.7's remote-working policy, training, device controls, network restrictions, MFA emphasis, and secure remote-access mechanisms (e.g. VDI, screen locks, remote wipe) reduce the likelihood of token theft via compromised remote environments, public networks, or social engineering, but do not address container/CI/CD/Kubernetes service-account token theft, IMDS token requests after VM compromise, or OAuth phishing registration flows.
- T1530prevents — A.6.7's remote-working policy, training, device controls, network restrictions, authentication hardening and equipment rules constrain how remote users access and expose cloud-stored data, directly addressing the misconfiguration and credential-leak vectors named in the T1530 prose, but leave the bulk of provider-side IAM, bucket policies and API-level enforcement untouched.
- T1534prevents — A.6.7's policy, training, device controls, network restrictions, MFA emphasis, and remote-work rules reduce the chance an already-compromised internal account can be leveraged for further internal phishing (via device control, credential reuse, or chat/email vectors), but do not stop the initial compromise stage or all possible internal delivery paths.
- T1539detects — A.6.7 explicitly requires audit, security monitoring, information security event reporting, device location tracking and remote-wipe capabilities when remote working is permitted; these surface anomalous remote access or stolen-session use after the fact, but only for the remote-working slice of the technique and only where the organization has chosen to allow remote work.
- T1539prevents — A.6.7's remote-working policy, training, device controls, network restrictions, malware protection and authentication hardening (esp. against single-factor) constrain cookie theft vectors that occur on remote endpoints or links, but leave local-browser malware, JS injection, and MitM proxies on non-remote paths untouched.
- T1546.002detects — A.6.7 explicitly lists audit and security monitoring plus device location tracking/remote wipe as measures to consider for remote working, which can surface anomalous screensaver-based persistence on remote endpoints; this is a genuine but minority slice of the class (remote-only, not on-premises or non-remote endpoints).
- T1546.002prevents — A.6.7's policy, training, device controls (screen locks, inactivity timers), remote-access hardening, and physical-security rules for remote environments reduce the feasible attack surface and likelihood of an adversary reaching and altering local screensaver registry values on a remote endpoint, but do not mandate or enforce the specific Windows mechanisms that would block the technique outright.
- T1552.001prevents — A.6.7's remote-working policy, training, equipment rules, communication security requirements, device controls, and restrictions on private equipment and networks reduce the likelihood and exposure of insecure credential files being created or left accessible in remote environments, but do not stop the core technique of searching for or extracting them from files, backups, configs, or containers.
- T1552.008prevents — A.6.7's remote-working policy, training, device controls, network restrictions, and secure-authentication requirements can stop credential sharing or exposure in chat tools when those tools are accessed from remote endpoints, but the technique also occurs on corporate networks, SaaS back-ends, admin portals, and via compromised integrations that the control does not reach.
- T1557detects — A.6.7 explicitly requires audit, security monitoring, and information security event reporting for remote working, which surfaces anomalous network behavior consistent with AiTM (e.g. unexpected DNS changes, downgrade signals, or MITM artifacts) when the remote environment falls inside the monitored scope; it does not guarantee detection of all AiTM vectors on all remote platforms or home networks.
- T1557prevents — A.6.7's policy, training, network security requirements, firewalls/malware protection, secure remote access mechanisms, and authentication hardening directly stop many AiTM vectors (e.g. unsafe home/public networks, weak single-factor auth, downgrade attacks, unauthorized local access) that remote workers would otherwise enable, but leaves residual exposure on unmanaged networks, physical site threats, and non-remote protocol abuse.
- T1557.001prevents — A.6.7's policy, training, network security requirements, firewalls/malware protection, and remote-access mechanisms (e.g. VDI, MFA) can stop name-resolution poisoning and relay on remote-worker endpoints or links, but the technique is a local-network attack that can still succeed on unmanaged home/public networks or non-remote Windows systems.
- T1557.002prevents — A.6.7's policy, training, network security requirements, firewalls/malware protection, and secure remote access mechanisms (including authentication hardening) can constrain ARP poisoning opportunities on home/public networks used in remote work, but this is only a slice of the technique's local-network attack surface across all platforms and does not eliminate the stateless unauthenticated ARP flaw itself.
- T1557.004detects — A.6.7 explicitly lists audit, security monitoring, and information security event reporting as measures to consider for remote working, which would surface evil-twin Wi-Fi anomalies when the remote worker is the victim; this is only a slice of the technique's surface (remote-worker victims in public or home networks) rather than a bounded remainder of a general detection mechanism.
- T1557.004prevents — A.6.7's policy, training, network configuration rules, firewalls/malware protection, and secure remote-access mechanisms (including authentication) reduce the chance a remote worker connects to an evil-twin AP, but do not stop the adversary from hosting the fraudulent AP or coerce all devices/users in public or home environments.
- T1561recovers — A.6.7 explicitly requires procedures for backup and business continuity as part of remote-working policy and measures, which directly enables recovery from disk-wipe availability loss (especially on remote endpoints); the named remainder is non-remote systems and the fact that remote-wipe itself can destroy local backups.
- T1561.001recovers — A.6.7 explicitly requires procedures for backup and business continuity as part of remote-working policy and measures, which directly enables recovery of wiped disk content after the destructive technique has run.
- T1561.002recovers — A.6.7 explicitly requires procedures for backup and business continuity as part of remote-working policy and measures, which directly enables restoration of systems after a disk-structure wipe that renders them unbootable.
- T1563prevents — A.6.7's policy, training, authentication mechanisms, remote-access rules, device controls and network protections (firewalls, malware) constrain the remote-working conditions that make session hijacking feasible, but do not eliminate the possibility of an already-established legitimate session being commandeered.
- T1563.001detects — A.6.7 explicitly lists audit, security monitoring, and information security event reporting as measures to consider for remote working, which would surface anomalous SSH session behavior on monitored remote endpoints; this is only a slice because the clause sets requirements rather than mandating universal instrumentation depth or coverage of all SSH agent hijacking artifacts.
- T1563.001prevents — A.6.7's policy, training, authentication mechanisms, remote-access rules, device controls and network protections (firewalls, malware) constrain the remote-working conditions that enable SSH agent/socket compromise and session hijacking, but do not eliminate the underlying trust relationships or root-level access vectors on Linux/macOS endpoints.
- T1563.002detects — A.6.7 explicitly requires audit, security monitoring, and information security event reporting for remote working sessions, which surfaces anomalous RDP hijacking in scope but only as one slice of a broad governance requirement rather than dedicated RDP-session instrumentation.
- T1563.002prevents — A.6.7's policy, training, authentication hardening, remote-access mechanisms, device controls and network restrictions directly constrain several vectors for stealing or hijacking an active RDP session from a remote worker's environment, but leave untouched hijacks performed from inside the target system by already-privileged local adversaries or via unaddressed RDP configuration flaws.
- T1565.001recovers — A.6.7 explicitly requires procedures for backup and business continuity as part of remote-working provisions, which directly enables recovery from stored-data manipulation once it has occurred.
- T1565.002prevents — A.6.7's policy, training, network security requirements, firewalls/malware protection, secure remote access mechanisms and device controls reduce the opportunity for an adversary to position on a remote-worker's link or device and intercept/alter data in transit, but do not guarantee prevention of all such manipulations (especially those between system processes or on unmanaged home/public networks).
- T1566detects — A.6.7 explicitly requires audit, security monitoring, and information security event reporting for remote working, which surfaces phishing attempts delivered to or executed from remote endpoints or via remote-access channels; this is a genuine but minority slice of the broad technique that also spans non-remote vectors, social engineering outside monitored environments, and pre-delivery evasion.
- T1566prevents — A.6.7's policy, training, rules on remote environments/networks, device controls, and secure remote mechanisms (e.g. MFA, remote wipe) reduce the success rate of phishing that targets remote workers or is delivered via remote channels, but do not stop the delivery or initial receipt of phishing messages themselves.
- T1566.001prevents — A.6.7's remote-working policy, training, device controls, network restrictions, malware protection and authentication requirements reduce the chance a remote user opens a spearphishing attachment or lets its payload run, but do not stop the email from being delivered or the social-engineering lure itself.
- T1566.002prevents — A.6.7's remote-working policy, training, device controls, network restrictions, and secure-authentication requirements reduce the chance that a targeted remote user will click a malicious spearphishing link or have the resulting payload succeed, but do not stop the email from being delivered or guarantee the link will never be followed.
- T1566.003prevents — A.6.7's remote-working policy, training, rules on personal/public networks, device controls, and awareness of threats from family/visitors in non-enterprise environments directly lower the chance remote workers will engage with spearphishing via third-party services on work devices, but this is only a slice of the social-engineering vector (rapport-building, fake accounts, expected content) rather than a bounded remainder.
- T1566.004prevents — A.6.7's policy, training, remote-access rules, MFA considerations, and secure mechanisms directly constrain vishing that targets remote workers or uses voice to extract remote-access credentials, but the control is scoped only to remote-working environments and does not address vishing against on-premises staff or non-remote vectors.
- T1567detects — A.6.7 explicitly requires audit, security monitoring, and information security event reporting for remote working, which can surface anomalous exfiltration over web services from remote endpoints; this is a genuine but minority slice of the technique's surface (remote workers only, not all platforms or non-remote exfil).
- T1567.001detects — A.6.7 requires audit, security monitoring, and information security event reporting for remote working, which can surface anomalous exfiltration (including to a code repo) when performed from a monitored remote endpoint or over monitored remote access channels, but this is scoped only to remote-worker environments rather than all platforms or non-remote exfiltration paths.
- T1567.002detects — A.6.7 explicitly requires audit, security monitoring, and information security event reporting for remote working, which can surface anomalous exfiltration (including to cloud storage) when performed from a monitored remote endpoint or over monitored remote-access channels, but the control's scope is limited to remote-working environments and does not broadly instrument or detect the technique across all platforms or non-remote vectors.
- T1567.004detects — A.6.7 explicitly lists audit, security monitoring, and information security event reporting as measures to consider for remote-working environments, which would surface anomalous outbound webhook traffic from remote endpoints; this is only a slice of the technique's surface (remote workers, not all platforms or non-remote exfil).
- T1589.001prevents — A.6.7's policy, training, device controls, MFA considerations, and remote-access rules reduce credential exposure risks for remote workers (e.g., via secure auth, home-network restrictions, and awareness of family/public threats), but do not stop pre-attack gathering via phishing, breaches, dark-web purchases, or infostealer logs.
- T1598prevents — A.6.7's policy, training, secure remote mechanisms, device controls and awareness of remote/public threats reduce the chance remote workers will divulge credentials or sensitive data to a phish, but do not stop the adversary from sending the message or prevent the social-engineering technique itself.
- T1598.001prevents — A.6.7's policy, training, rules on remote environments/networks, device controls, and awareness of threats from family/visitors/public places reduce the likelihood that a remote worker will fall for a spearphishing lure delivered via third-party services, but do not stop the message from being sent or guarantee the social engineering will fail.
- T1598.002prevents — A.6.7's remote-working policy, training, secure-equipment rules, communication-security requirements, and device controls (screen locks, remote wipe, malware protection) reduce the chance that a remote user will open a spearphishing attachment or divulge the elicited information, but do not stop the adversary from sending the message or guarantee the user will not act on it.
- T1598.003prevents — A.6.7's remote-working policy, training, secure equipment rules, communication security requirements, device controls (screen locks, remote wipe), and restrictions on home/public networks and single-factor auth reduce the chance that a remote worker will click a spearphishing link or divulge credentials from an uncontrolled environment, but do not stop the adversary from sending the message or guarantee the targeted individual will follow the policy.
- T1598.004prevents — A.6.7's remote-working policy, training, communication security rules, authentication hardening, and awareness of threats from family/visitors/public places directly lower the success rate of vishing that targets remote personnel, but the control addresses only the remote slice of the workforce and does not stop the social-engineering technique itself.
- T1669detects — A.6.7 explicitly lists audit, security monitoring, and information security event reporting as matters to consider for remote working, which would surface anomalous Wi-Fi connections or dual-homed bridging used by T1669; this is only a slice because the clause is scoped to remote-worker environments rather than mandating network-wide Wi-Fi monitoring.
- T1669prevents — A.6.7's policy, training, network configuration rules, firewalls/malware protection, and remote-access mechanisms (including authentication) directly constrain insecure use of home/public Wi-Fi that would otherwise enable the adversary's open-network exploitation or credentialed access to the target's Wi-Fi, but leave the physical-proximity, dual-homed-bridge, and post-connection sniffing/AiTM slices untouched.
- T1684prevents — A.6.7's policy, training, rules on family/visitor access, clear-desk, device controls and remote-site physical/comms security reduce the chance a remote worker is successfully socially engineered into disclosing credentials, approving changes or executing payloads, but do not stop the adversary technique itself from being attempted or succeeding via other vectors.
- T1684.001prevents — A.6.7's policy, training, rules on remote environments/networks, authentication mechanisms, and awareness of threats from family/visitors/public places reduce the success rate of remote-targeted impersonation/social-engineering but do not stop the technique itself (especially non-remote vectors or pre-recon phases).
- T1686prevents — A.6.7 requires remote-working policies, training, and security measures (firewalls, malware protection, secure remote access mechanisms, device controls) that can stop an adversary from reaching the privileges or configurations needed to tamper with a firewall from a remote site, but this is limited to the remote-working slice and does not address local or post-compromise tampering on other platforms.
Prevented OWASP Web Top 10 (2025) risks (2)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.