Remote Working Security Policy
Updated 7 August 2026
1. Introduction
1.1. The DWP Remote Working Security Policy is part of a suite of policies designed to implement and manage a consistent set of security controls across the Department for Work and Pensions (DWP) and its supplier base. For the purposes of this policy, the term DWP and Department are used interchangeably.
1.2. Security policies considered appropriate for public viewing are published on GOV.UK at: DWP procurement: security policies and standards - GOV.UK.
1.3. Where applicable, security policies cross-reference each other so they can be confidently used together. They contain both mandatory and advisory elements, described in consistent language as set out in the terminology section below.
2. Purpose
2.1. The purpose of the policy is to set proportionate, mandatory controls for protecting DWP’s information and assets when working remotely, including while travelling.
3. Scope
3.1. This policy applies to all DWP employees, agents, contractors, third parties, consultants, suppliers and their sub-contractors who work remotely on behalf of DWP. This includes individuals who access, process, store or handle DWP information, or who manage or support DWP systems, hardware or services. From this point forward, this group will collectively be referred to as ‘users’.
3.2. This policy does not replace any legal or regulatory requirements.
3.3. All remote working, including contractual home-working agreements, must be undertaken following a formal arrangement approved by the relevant line manager.
3.4. This policy applies to all remote working locations, including home, public spaces, hotels, and work-related travel.
4. Terminology
4.1. The following terminology is used within this policy:
-
“must” is used to denote a mandatory requirement that always needs to be complied with
-
“should” is used to denote elements that are expected to be implemented where possible but are not strictly mandatory
-
“may” and “could” are used for elements that are optional or desirable
5. Definitions
5.1. Data is defined as information, including facts, figures, images, sounds, symbols and observations, about people, events, objects and systems.
5.2. Remote working is defined as using, accessing, handling or disposing of DWP information or other DWP assets outside DWP business locations, including when travelling on official business.
5.3. Users are defined as individuals who undertake remote working.
6. Policy statements
Fundamental requirements
6.1. When working with DWP’s assets either at work or in a non-work location, users must:
- take personal responsibility for understanding and complying with DWP security policies
- use only DWP approved, procured and configuration-managed systems, applications, software and devices (for example, USBs, laptops, tablets, and mobile devices) for all official business, including remote working, and follow DWP standards and instructions when using them
- only use DWP-approved secure remote access methods and must not use personal or non-DWP approved Virtual Private Networks (VPNs) on DWP devices, in line with DWP Security Standard – Remote Access (SS-016)
- be aware that whilst personal devices, such as laptops and tablets, can be used for DWP training courses, this is subject to the conditions in the DWP Acceptable Use Policy (see section 8. Devices, systems and networks)
6.2. Users must not work remotely overseas.
- where there is a legitimate business requirement to travel overseas for work purposes, users must, in all cases, obtain prior approval in accordance with the Travel Abroad: Staff Advice And Notification guidance and comply with relevant human resources (HR) guidance on working abroad
- DWP devices, including smartphones, may only be taken overseas for official business where this process has been followed and approval has been granted by the Personnel Security Team. Device use may be restricted in certain countries
Planning to work remotely
6.3. When planning to work in a remote location users must:
- take account of the sensitivity, security classification, and value of the information they will handle. They must consider whether they can comply with DWP’s policy requirements for protecting government information. For further details, see the DWP Security Classification Policy
- ensure only essential documents or files are removed from the office and they are securely handled
- obtain line manager’s approval before accessing or transporting DWP assets outside DWP offices, where the arrangements differ from agreed working patterns or present increased security risk
- consider the increased risks of remote working, and decide whether it is appropriate to take additional security measures, such as:
- using a screen filter or privacy screen on the device
- taking a DWP device rather than hard copies of documents
- applying data minimisation principles to the assets involved. This means users must access only DWP data or assets that are necessary to complete the task
Travelling with DWP assets
6.4. When in transit with DWP assets users must keep any IT equipment and sensitive information with them wherever possible. Where a stop-off is required and items are heavy, they may be left in the vehicle but must be stored out of sight (for example, in the boot). At the end of the journey, remove DWP assets and store them securely at home or securely at a DWP site.
6.5. Laptops must be powered off when not in active use to ensure encryption controls are effective and prevent unauthorised access.
Working remotely
6.6. When working remotely users must be vigilant to reduce the risk of mishandling data which could lead to a security breach. Users must:
- never leave DWP equipment or assets unattended in a public place
- not use unauthorised third parties to service, repair or modify DWP IT equipment. All faults must be handled through DWP-approved processes
- not allow any unauthorised personnel to access any departmental information or assets, including DWP approved portable devices and other DWP approved desktop PCs
- avoid accessing or discussing sensitive information in locations where it may be overheard by unauthorised individuals. Apply the ‘need to know’ principle at all times and maintain situational awareness, including the presence of listening devices (for example Alexa, Siri, and Google)
- follow the policy requirements set out in the DWP Acceptable Use Policy for using devices, systems and networks remotely. Devices must not be connected to the internet via Captive Portals
- not use personal printers or storage devices to process, store or output DWP information, unless explicitly approved. The use of personal Bluetooth headsets, keyboards and mice is permitted only in accordance with the DWP Acceptable Use Policy
- follow baseline security behaviours by using approved storage solutions and securely disposing of sensitive information. See Handling Information Baseline Behaviours for more information
- create, use, share, store and dispose of information only where there is a clear business need, and in accordance with the Information Management Policy, Information Asset Inventory Guidance and Retention Guidance
- position their DWP device in a way that reduces the risk of unauthorised access, such as shoulder surfing
- not connect DWP equipment to vehicles, using either USB or Bluetooth. These connections can download information from the device or upload malicious software. Please refer to DWP Acceptable Use Policy on devices, systems and network
- use approved mains power adapters (plug) for charging DWP devices, to eliminate data transfer risks associated with USB-enabled charging
7. Accountabilities and Responsibilities
7.1. The DWP Chief Security Officer is the accountable owner of this policy.
7.2. The Head of Security Policy is responsible for reviewing and maintaining this policy.
7.3. Line Managers are responsible for ensuring that:
- employees are made aware of the relevant security policies and HR policies linked within this document, which support working securely in remote locations
- equipment is appropriately authorised for remote working, departmental assets are accounted for, and a record maintained prior to issue and use of all DWP approved devices
- employees are made aware of potential risks often associated with remote working, for example:
- the loss or theft of IT equipment or sensitive and personal data
- the inadvertent or deliberate disclosure of sensitive, operational information
- unsecured storage of information and user credentials, such as usernames and passwords
- tampering, where IT equipment / information is left unattended
7.4. Users must always take personal responsibility to understand and comply with relevant DWP security policies including, but not limited to this policy, the DWP HR Contractual Home Working Policy and associated HR Occasional and Regular Remote / Home Working Procedures, the DWP Acceptable Use Policy, and Travelling Overseas Policy where circumstances are relevant.
8. Compliance
8.1. Everyone within the scope of this policy must adhere to all the policy statements. Individual queries about implementing policies should be raised to the Security Advice Centre. If a business area is unable to comply with a policy statement, this must be raised to the Security Policy and Standards Team as soon as possible via the Security Policy Team, who will engage with teams to explore solutions and determine whether an exception to policy should be requested.
8.2. DWP defines a security incident as ‘the attempted or actual unauthorised access, use, disclosure, modification, loss, or destruction of a DWP asset in violation of security policy’. Where an individual is aware of a security incident, they must raise this immediately and be available to be contacted for further information so that the risk to DWP assets can be understood, controlled and resolved. DWP employees report security incidents via the DWP Security Incident Referral Webform. Third parties and suppliers must report security incidents using the Security Incident Report Form contained in appendix G of the DWP Security Incident Management Standard (SS-014).
8.3. Failure to report a security incident, potential or otherwise, could result in disciplinary action and, in the most severe circumstances, result in dismissal.
8.4. DWP’s Security and Data Protection Team will regularly assess compliance with this policy and may need to inspect physical locations, technology systems, design and processes and speak to people to facilitate this. All DWP employees, agents, contractors, consultants, business partners and service providers will be required to facilitate, support, and when necessary, participate in any such inspection.
9. Version Control (changes from previous published version)
| Paragraph | Changes made and reason |
|---|---|
| Whole document | Structure updated (Overview – Introduction, added Purpose, Terminology, Definitions, reordered layout). Align with current DWP policy template and improve usability / consistency. |
| 1 Introduction | New section added to provide policy context, cross-referencing, and publication approach. Improve clarity and align with standard policy framing. |
| 2 Purpose | New explicit purpose statement introduced. Provide a clear, concise statement of policy intent. |
| 3 Scope | Expanded scope to include wider user groups (for example, suppliers, third parties) and clearer application of remote working. Ensure completeness and reflect broader DWP user base. |
| 4 Terminology | New terminology section added (must / should / may definitions). Standardise interpretation of policy requirements. |
| 5 Definitions | Added formal definitions (data, remote working, users). Improve clarity and remove ambiguity. |
| 6.1 | Consolidated and clarified core user responsibilities. Added reference to personal device use for training. Explicit prohibition on non-DWP VPNs and reference to SS-016. Improving control clarity and technical alignment. |
| 6.2 | Overseas working statement refined. Wording tightened and approval requirements. Improve clarity and reflect current HR / security approach. |
| 6.3 | Expanded planning requirements, including risk consideration and additional security measures (for example, privacy screens, data minimisation). Strengthen risk-based approach to remote working. |
| 6.4 | Travel guidance updated to allow proportionate flexibility (for example, heavy items in vehicles). Make guidance more practical and usable. |
| 6.5 | Added explicit requirement to power off laptops to enforce encryption controls. Introduced as a new technical control. |
| 6.6 | Expanded remote working controls (for example, captive portals, restrictions on personal printers / storage, vehicle connections, and charging risks). Address emerging risks and provide clearer expectations. |
| 7 Accountabilities | Updated roles (for example, Head of Security Policy added) and simplified user accountability wording. Reflect current governance structure and reduce duplication. |
| 8 Compliance | Expanded compliance section to include incident reporting routes, escalation, and assurance activity. Provide clearer process and strengthen compliance framework. |
| Removed content | Duplicated or less precise wording removed or consolidated. Improve clarity, reduce repetition, and streamline policy. |