Secure Remote Work: IT Equipment & Data Protection Agreement

1. Employee Information and Remote Work Arrangement

This section collects your personal details and remote work setup information to establish a secure and compliant remote working arrangement. All fields marked as mandatory must be completed to process your agreement.

 

Employee ID Number

Full Name

Department

Job Title

Primary Remote Work Location Address

Contact Phone Number

Work Email Address

Emergency Contact Name and Phone

Emergency Contact Phone

Expected Percentage of Work Conducted Remotely (0-100%)

Remote Work Agreement Start Date

IT Equipment Assignment and Verification

Acknowledge Receipt

Asset Tag Number

Equipment Type

Manufacturer

Model Number

Serial Number

Replacement Value

Condition at Issue

A
B
C
D
E
F
G
H
1
 
 
 
 
 
 
 
2
 
 
 
 
 
 
 
3
 
 
 
 
 
 
 
4
 
 
 
 
 
 
 
5
 
 
 
 
 
 
 
6
 
 
 
 
 
 
 
7
 
 
 
 
 
 
 
8
 
 
 
 
 
 
 
9
 
 
 
 
 
 
 
10
 
 
 
 
 
 
 

Are you receiving any additional equipment not listed above?

 

Please list additional equipment with details (type, model, serial number if applicable):

3. Equipment Responsibility and Security Acknowledgement

By acknowledging below, you accept full responsibility for the security, maintenance, and proper use of all assigned equipment. This includes protection against theft, damage, and unauthorized access.

 

I acknowledge that I have physically received and inspected all equipment listed in Section 2 and confirm it is in proper working condition.

 

Please describe any issues or defects found during inspection:

I understand that I am personally responsible for the security of all company equipment in my possession at all times.

I agree to immediately report any loss, theft, or damage to IT equipment to the IT Security team.

Do you have personal insurance that covers company equipment in your home?

 

Please provide insurance provider and policy number:

 

Please consider obtaining appropriate insurance coverage. You remain liable for equipment replacement costs in case of negligence.

 

I agree to return all company equipment within 5 business days upon termination of employment or upon request by the company.

4. Data Access Classification and Handling Procedures

Your role may require access to sensitive company information. This section defines your data access level and associated handling responsibilities based on the classification scheme.

 

What is the highest classification level of data you will access remotely?

 

Describe the specific security measures you will implement to protect Confidential Business Information (e.g., encryption, secure storage, access controls):

 

Describe the enhanced security protocols you will follow for Restricted Sensitive Data (e.g., dedicated secure workspace, additional encryption, no local storage):

Select all data handling activities you perform as part of your remote work duties:

Do you handle personal data of customers, clients, or employees?

 

Specify the types of personal data handled and the purpose of processing:

Do you have access to financial or payment-related data?

 

Describe the nature of financial data access and additional security measures implemented:

5. Authentication, Authentication Management, and Access Controls

Strong authentication is critical for securing remote access. This section verifies your understanding and implementation of access control requirements.

 

I use unique, complex authentication codes for each work-related account and system.

 

Explain your current authentication practices and your plan to achieve compliance:

I have enabled Multi-Factor authentication (MFA) on all work accounts that support it.

 

List accounts without MFA and reason for non-compliance:

How frequently do you update your work account authentication credentials?

I always lock my computer screen when stepping away from my workspace, even for brief periods.

Do you use a authentication manager to store work-related credentials?

 

Specify the authentication manager application:

 

Using an approved authentication manager is strongly recommended for secure credential storage.

6. Home Office Physical Security and Workspace Environment

The physical security of your remote workspace is essential to protect company assets and information. Please assess and document your workspace security measures.

 

Is your primary work area located in a separate, lockable room with restricted access?

 

Describe the physical security measures in place to protect your workspace and equipment (e.g., privacy screens, security cables, locked cabinets):

Can unauthorized persons (including family members) access your work computer or view your screen during work hours?

 

Identify who has potential access and describe mitigation controls implemented:

Do you have a secure, lockable storage solution for physical documents or removable media?

 

Describe your plan for securing physical documents:

Who shares your remote work location? Select all that apply:

Do you have a means to secure your laptop when not in use (e.g., cable lock, safe)?

 

Describe your plan for securing equipment when unattended:

7. Network Security and Internet Connectivity

Secure network connectivity is fundamental to protecting company data. This section assesses the security posture of your internet connection and network configuration.

 

What type of internet connection do you primarily use for remote work?

 

Do you always use the company VPN when connected to public Wi-Fi?

 

Explain circumstances when VPN is not used and alternative security measures:

 

Describe the security measures implemented by the co-working space and additional controls you use:

I use the company-provided VPN for all work-related activities, including email and file access.

 

Specify which work activities are performed without VPN and justify the exception:

Is your home Wi-Fi network secured with WPA3 or WPA2 encryption?

 

Describe your Wi-Fi security protocol and plan to upgrade if needed:

Have you changed the default administrator authentication on your home router?

 

Explain why the default authentication remains unchanged and timeline for remediation:

Do you use personal devices (smartphones, tablets) to access company resources?

 

List personal devices used for work and confirm they have encryption, passcode, and remote wipe capability enabled:

8. Software Management and Application Usage

Unauthorized software can introduce security vulnerabilities. This section ensures you understand and adhere to the company's software installation policies.

 

I only install software applications that have been explicitly approved by the IT department.

 

List any unapproved software currently installed and describe the business justification:

Software Inventory and Approval Status

Software/Application Name

Version

License Type

IT Approved?

Business Purpose

Installation Date

A
B
C
D
E
F
1
 
 
 
 
 
 
2
 
 
 
 
 
 
3
 
 
 
 
 
 
4
 
 
 
 
 
 
5
 
 
 
 
 
 
6
 
 
 
 
 
 
7
 
 
 
 
 
 
8
 
 
 
 
 
 
9
 
 
 
 
 
 
10
 
 
 
 
 
 

Do you use cloud storage services (personal or corporate) to store or backup work-related files?

 

Specify each cloud service, account type (personal/corporate), and types of work data stored:

Which of the following security measures do you implement on applications containing work data? Select all that apply:

9. Security Awareness Training and Knowledge Assessment

Security awareness is an ongoing requirement. This section verifies your training status and assesses your understanding of key security concepts.

 

I have completed the mandatory Security Awareness Training within the last 12 months.

 

Scheduled completion date for pending training:

Rate your confidence in identifying phishing emails and social engineering attempts (1 = Not confident, 5 = Very confident)

I know the correct procedure to report a suspected security incident or data breach.

 

Describe what you believe is the correct reporting procedure:

Which of the following security threats are you prepared to recognize and respond to? Select all that apply:

Briefly describe the steps you would take if you suspect your work account has been compromised:

10. Security Incident History and Reporting Procedures

Transparency about past incidents helps improve security measures. This section documents any previous security events and confirms your understanding of reporting obligations.

 

Have you experienced any security incidents in the past 12 months while working remotely?

 

What type of incident occurred?

If you experienced an incident, was it reported to IT Security within 1 hour of discovery?

 

Describe the incident response actions taken and lessons learned:

 

Explain the delay in reporting and describe the incident:

I understand that I must report any suspected security incident immediately to IT Security (within 1 hour of discovery), even if I am uncertain about the severity.

Primary IT Security Contact Email / Phone

11. Compliance Acknowledgement and Legal Agreement

This final section confirms your understanding and agreement to comply with all security policies and legal obligations. Your signature makes this agreement legally binding.

 

I have read, understood, and agree to comply with the Remote Work Security Policy and all related IT Security Policies.

I understand my obligations under applicable data protection regulations and commit to handling all data accordingly.

I acknowledge that non-compliance with these security requirements may result in disciplinary action, up to and including termination of employment.

I consent to periodic remote security audits and compliance checks of my work environment, with reasonable prior notice.

I understand that all work performed and data accessed using company equipment remains the property of the company, including intellectual property rights.

Are there any conflicts of interest or personal circumstances that might affect your ability to comply with these security requirements?

 

Describe the conflict of interest or circumstance and proposed mitigation strategy:

Additional comments or special considerations regarding your remote work security setup:

12. Digital Signature and Authorization

By signing below, you acknowledge that all information provided is accurate and complete, and you agree to abide by all terms and conditions outlined in this Remote Work IT Equipment & Data Security Compliance Agreement. This signature is legally binding.

 

Employee Signature

Signature Date and Time

Manager Approval Digital Signature

Manager Approval Date and Time

To configure an element, select it on the form.

To add a new question or element, click the Question & Element button in the vertical toolbar on the left.