Here we are again, in a period of confinement due to Covid-19. I thought it was time to evaluate its telecommuting policies.

28 questions to assess your teleworking policy

It’s important to remember that telecommuting refers to any work performed outside the traditional office setting. This includes, of course, working from home, but also at friends’ homes, in a café, in a library, and for some, in another country on a temporary trip.

Here are 28 questions, in no particular order, to help you evaluate your teleworking policy:

1. Is the teleworking policy written and distributed?

The policy needs to be written down somewhere, in a PDF file, on a website or whatever, but it needs to be accessible and distributed to people so that they can access it easily. Don’t assume that team members know where it is and will find it on their own. Management must provide it to the people concerned.

It’s difficult to conceive of such a policy as a simple e-mail – but as a document, complete, reviewed and shared.

2. Is the teleworking policy recent and dated?

Would you trust a document that’s several years old and no longer corresponds to your company’s reality, either in terms of technology or business processes?

A document unsuited to the organization will not be respected.

Also, a document that is too old sends the signal that this policy is not important.

3. Is the owner of the document named?

Who is responsible and accountable for the teleworking policy? If not, who do I talk to about my work?

Clearly identifying the owner allows you to quickly identify the person responsible for its application, otherwise the policy will not be respected.

4. Is the policy approved?

This point is a little more nuanced depending on company size, since in most cases, managers will be the approving officers.

As an employee looking at the policy, is there any way to make sure that the version you’re looking at is the latest approved version, i.e. the one you’ve reviewed and agreed with?

A document can undergo changes, revisions and adjustments over time, which is an excellent thing. However, this new version must be presented, reviewed and approved by the company’s management for official communication.

5. Are the teleworking policy objectives clear?

A documented and approved teleworking policy is a good thing, but what is the purpose of these new rules?

Why should I follow these instructions?

Link the policy to the organization’s compliance objectives. For example, if there are any laws, regulations or standards that apply to it, they should be defined and act as a reminder.

6. Is there a scope to the teleworking policy?

The scope section should be quickly identified at the top of the document, since this policy item helps define what is covered and what type of work is allowed when teleworking, what type of employee is affected?

Is the employee concerned by this document that the employer wants to have read and signed?

7. What are the criteria for teleworking?

Is there a procedure that allows me to do work without asking permission?

The policy should indicate the contexts in which work can be done, or conversely, the contexts in which a person must be in the office, for example: “Telecommuting is permitted at all times except for monthly team meetings, at a time determined between you and management”.

In the very context of COVID19 , some employment contracts have included criteria allowing telecommuting from the outset.

8. Are roles and responsibilities defined?

The purpose of this section of the policy is to identify the people who can either help me configure my workstation or help me make decisions.

9. Are there any security measures associated with teleworking locations?

Are there any security measures I need to take in relation to the workspace? For example, I need to make sure that the person sitting next to me in the café can’t read the confidential data I’m working on.

For example, the use of disk encryption protocols to prevent theft.

10. Are there any environmental requirements?

The policy could frame the type of places, my workspace, to see to an ergonomic place. Prevent injuries related to using a laptop in an inappropriate posture. Who is responsible in the event of physical injury?

Perhaps ban telecommuting if the employee doesn’t have the space to do his or her job properly. I have the image of a technician in technical support who doesn’t have headphones to protect him from ambient noise.

11. What are your communication needs?

Team members need specific tools, such as a high-performance computer, in order to carry out their telecommuting tasks, but other needs in terms of tools, software, licenses, connectivity, internet speeds, telephony requirements, etc., also need to be assessed.

12. Is it worth using a bridge to connect to the corporate network?

In certain situations, remote connections via a bridge between two networks can be useful to prevent data sharing, or act as a filter between a computer that does not belong to the organization and those of the organization. If used, these systems should be documented and secured according to the teleworker’s needs.

We therefore need to assess whether a virtual environment is required to prevent the storage of information on the remote workstation.

13. Have the risks associated with children and other family members having access to the workstation been assessed?

Teleworking access is either via a computer supplied by the company, with the company’s security configurations (software and settings). But in some cases, a personal computer, used by all family members, is used to do work. We need to assess whether these cases of use are permitted, and whether these permissions or prohibitions need to be included in the teleworking policy.

14. Are there any controls for accessing the shared WIFI network, and configuring it to prevent eavesdropping?

Regardless of the computer used, whether an organization’s or a personal computer, its connection methods must have a minimum of configurations to ensure the confidentiality of information in transit. Such as WPA2 PSK strong or WPA3 on more recent devices.

15. Are there any clarifications regarding the intellectual property of the work carried out?

Clarify issues relating to the intellectual property of the results of work carried out at home, especially in situations where the time is not measured or carried out on a company computer.

So who owns the result of the work created by the telecommuting individual?

16. Does the organization have access to private equipment in the event of a breach?

What criteria does management impose in order to gain access to equipment in the employee’s home, for example in the event of a security breach or other incident requiring further investigation?

17. Who pays for and manages tool licenses and copyrights?

Again, depending on the type of system allowed for telecommuting, it is necessary to determine who pays the license fees or other copyrights, and the terms and conditions. For example, the organization may only pay the fees on its own computers, or it may allow license transfers to a personal computer.

18. Is there a list of protective tools required?

The computer system used for telecommuting must be equipped with a minimum of protection tools, such as antivirus, disk encryption, firewall, password manager, automated updates, etc. So what are these necessary tools and configurations?

19. If the equipment belongs to the organization, is it permitted to use the equipment for personal reasons?

Also, can my children use the computer to play their games? Can I do my tax return and store information about myself on the computer?

Employees may have an expectation of privacy on a company computer. Determining whether data will remain private, or whether management can search my computer?

20. What is the definition of permitted work?

Is it permissible to do any type of work outside the office? At any time and with any kind of information, regardless of its classification (public, internal, confidential).

What type of information do I have access to?

21. What communication methods are permitted?

Earlier, we determined our communication needs and the speed of our Internet provider. But how do we connect the data?

If the use of a private link (VPN) is recommended, are there any other requirements, such as having a cell phone to obtain a code by SMS or other methods?

In more advanced cases, I’m thinking of “Slip-Tunnel” or “Strict” configurations to define the path that data takes from one network to the other. Do you allow Internet communications when the VPN is in place? This openness allows viruses to spread from one network to another.

22. Have we proposed protection against eavesdropping?

Determine the measures to be taken regarding eavesdropping on others, e.g. if the job involves handling confidential data, prevent family members from eavesdropping on conversations, don’t make these communications on a train or in a café.

23. Are there any guidelines for third-party use of the equipment (family or visitors)?

When can a family member use my work computer? A work computer is no longer just a “laptop” type of computer system, but could be a tablet, cell phone, etc.

So do you leave your phone with a stranger just long enough to make a call?

24. Who is responsible for hardware and software maintenance?

Determine responsibilities in terms of hardware and software maintenance. Who pays for the hardware, and how often can it be changed?

It’s important to clarify each party’s responsibility in managing the equipment. For example, a breakdown on my personal computer prevents me from working. The organization must send me a computer within 5 days. Do I get paid during these 5 days?

If a software program malfunctions on my personal computer, should the company provide technical assistance to determine the causes and, above all, repair the incompatibilities between my company software and my children’s games?

25. Are there any insurance needs?

Should the employee inform his personal insurance company that there are company information systems on his premises, and if not, what measures should be taken to prevent incidents?

26. What are the procedures for safeguarding business continuity?

Include the employee’s computer in the organization’s business continuity procedures. This is an important part of maintaining the business.

27. Does the organization have the right to monitor and audit remote systems?

Determine the employer’s right to monitor the employee’s workstation and his right to audit it.

28. What are the procedures for terminating access rights?

Document procedures for terminating or changing jobs, e.g. does the IT team have the necessary access to remotely remove rights and information from a company-owned workstation?

Conclusion

A teleworking policy will help organizations streamline processes and increase productivity. It also helps employees balance their lives by giving them the option of working from home on a temporary or permanent basis. What’s more, teleworking provides a good disaster recovery plan for both the company and its employees, who can continue to work in the event of a disaster or emergency at the company office.


Despite all these points, many other questions remain unanswered, such as :

  • How access is controlled;
  • How we manage the information assets under our control;
  • What is our data classification method?
  • How to draw up a business continuity plan.

I hope the items described in this article will help you revise your telecommuting policy!