Remote Access Policy

 

Policy No:1.20                                                                                                                        Printable Version

 

PURPOSE

 

This policy describes the security requirements for remote access connections to The Fake Chicken Company internal computers and networks.  It covers a wide variety of technologies and methods of effecting the connection.

 

SCOPE

 

This policy affects any organisation making remote or automated connections to The Fake Chicken Company internal computers and networks.

 

POLICIES 

1.    USER RESPONSIBILITIES

1.1    Authentication

 

1.1.1   All users   accessing systems by remote access must comply with The Fake Chicken Company Password and Authentication Policy.

 

 

Access Control Policy

Password and Authentication Policy

 

... and more

 

1.2   Access Rights and Privileges

 

1.2.1  External or Remote Users must not permit unauthorised persons, including members of their immediate family, to access The Fake Chicken Company network from computers under their control.

 

 

Computer Systems and Equipment Use Policy

 

... and more

         

Top

1.3    Anti-Virus Protection

 

1.3.1  Users of The Fake Chicken Company computer systems and networks, whether located in-house or remotely, must adhere to the company Anti-Virus Policy.

 

 

Anti-Virus Policy

 

... and more

 

1.4    Information

 

1.4.1  The collection, creation, use, dissemination and storage of information relating in any way to The Fake Chicken Company business activities must be carried out with regard to the Information Management Policy and the Legal Compliance Policy. 

 

 

Information Management Policy

Legal Compliance Policy

         

... and more

 

Top

1.5    Connection Policies

 

1.5.1  Third party users must only use the remote connection to The Fake Chicken Company networks and systems during the hours specified in the Remote Access Agreement.

 

            Explanation

         Hours of use have  been  agreed and authorised as part of the Remote Access Agreement. Any third party associated with the Agreement connecting to The Fake Chicken Company networks and systems outside the hours agreed are operating in breach of the Agreement.

 

 

Remote Access Agreement

Remote Access Application Form

 

... and more

1.6    Audit Trails and System Logs

 

1.6.1  The Fake Chicken Company reserves the right to monitor the use of the remote access connections

 

            Explanation

         Authorised staff from The Fake Chicken Company or a designated agent may, from time to time, monitor remote connections and employ any tools and applications it may deem appropriate...

 

 

Acceptable Use Policy

 

... and more

 

         

1.7    Equipment Use

 

1.7.1  Equipment provided to facilitate the remote access of The Fake Chicken Company computer systems and networks will be operated and maintained as per the Computer Systems and Equipment Use Policy.

 

 

Computer Systems and Equipment Use Policy

 

... and more

 

1.8    Access Granted to Customers

 

1.8.1

Before systems are made available to customers a formal proposal containing details such as the description of the service to be provided, why the information should be made available, benefits of customer access, costs and risks associated with providing the service and special requirements for access should be approved by a senior manager and the CIO.

 

 

 

... and more

               Top

2.      MANAGEMENT RESPONSIBILITIES

2.1    Approval

 

2.1.1  Applications for Remote Access must be approved by the Manager of the Division responsible for the costs that will be incurred and the IT Manager.   

 

 

 

... and more

 

2.2    Connection Policies

 

2.2.1  Third party organisations requiring remote access are responsible for their staff using the system as prescribed in The Fake Chicken Company Acceptable Use Policy for Computer Systems and Networks. 

 

 

Acceptable Use Policy

 

... and more

  

2.3    System Support and Maintenance

 

2.3.1  For  the  purposes of  support and maintenance, authorised The Fake Chicken Company staff or their agents will be granted access to the premises documented in the Remote Access Agreement.

 

 

Computer Systems and Equipment Use Policy

 

... and more

 

3.      INFORMATION SYSTEMS STAFF RESPONSIBILITIES

3.1    Approval

 

3.1.1  External goods and service suppliers that have sold The Fake Chicken Company hardware, software, or communication services are not automatically granted repeated access to The Fake Chicken Company internal computers and/or networks.  

 

          Explanation

         Vendors  must either go through the approval process described above, or set up a separate Remote Access Agreements for any systems maintenance processes. Temporary remote access privileges for vendors may, however, be enabled...

 

 

Access Control Policy

 

... and more

 

Top

3.2    Access Rights

 

3.2.1  Vendor access is disabled by default.  The person acting on behalf of the vendor must phone the Information Systems Helpdesk to have the connection enabled before they can log-in.  Access will be granted on the basis of proof of identity and will be enabled for that session only.   

 

 

Access Control Policy

Password and Authentication Policy

Special Access Policy

 

... and more

3.3    Encryption

 

3.3.1  Whenever a computer connection is established between The Fake Chicken Company and a device operating remotely that transmits, or is likely to transmit  confidential or secret information, the link must be encrypted unless the security of the link can be otherwise assured. 

 

 

Encryption Policy

 

... and more

 

3.4    Connection Policies

 

3.4.1  Systems installed and configured for external users to remotely connect to The Fake Chicken Company computer systems and networks should not permit telnet or any other type of real-time in-bound remote access via the Internet unless authorised by the IT Manager.

 

 

          Firewall Management Policy

          Network Management Policy

 

... and more

Top

3.5    Audit Trails/System Logs

 

3.5.1  The Fake Chicken Company has the right to view logs and audit any system, equipment or device that remotely connects to the internal computers and networks of The Fake Chicken Company including computers that may have been purchased by employees, contractors, temporary workers and other third parties. 

 

 

Acceptable Use Policy

 

... and more

 

3.6    System Support and Maintenance

 

3.6.1  System support is limited to those components specified in the Remote Access Agreement or as agreed separately with external users.

 

 

 

... and more

3.7    Set up of External Users

 

3.7.1   Only authorised personnel  from The Fake Chicken Company may establish  or make arrangements for remote access connections and only once the Remote Access Application Form and Remote Access Agreement have been signed by both parties.   

 

 

Application for Remote Access

Remote Access Agreement

... and more

3.8    Training of Staff

 

3.8.1  Remote users accessing the computer systems and networks of The Fake Chicken Company must be fully trained in the operation of the systems they are required to use.

 

 

          Computer Systems and Equipment Use Policy

 

... and more

 

 2004 All Rights Reserved Kaon Security Ltd