UNCLASSIFIED
5.10
Defend against random and targeted attacks by requiring users to power off
devices when not in use; never to leave devices unattended; requiring that
users store devices separately from credentials, amongst other measures;
Minimise data aggregation risks by ensuring that user devices only store
data required to perform approved business activities at any given time;
Adopt anti-virus or anti-malware procedures including stand-alone systems
(i.e. ‘sheep dips’) to scan portable and removable media for malicious code
before their use for data import and export; and
Make sure that users are conversant with mobile device incident response
and reporting procedures such as when to report device loss to the Police.
Remote Access Security
Remotely connecting a computer either to another computer or to a network over
public networks such as the Internet increases staff flexibility and productivity.
Staff with remote access can perform general work activities, access e-mail and
transfer files. However, remote access presents unique security challenges to
organisations. Firstly, remote access calls for additional security measures given
that it occurs over insecure public networks. Secondly, because remote access
occurs in exposed environments such as homes or when travelling, it increases
exposure to risks such as theft of equipment and information, the unauthorised
disclosure of information, unauthorised remote access to internal systems or
misuse of facilities. Therefore, in accordance with ISO/IEC 27002, organisations
must not authorise remote access or teleworking unless satisfied that suitable
security arrangements and controls are in place and that the measures comply
with relevant information security policies. Good remote access security can help
achieve the following mandated information security outcomes.
IS9 – All organisations must implement appropriate security measures to
mitigate remote access risks. As a minimum requirement, organisations must:
(a) adopt a formal remote access policy; (b) assess the risks, threats and
vulnerabilities of remote access; (c) use security controls e.g. encryption to
protect data whilst at rest and in transit; (d) educate users about remote access
risks; (e) security accredit remote access solution handling classified data; and,
(e) align remote access policy with incident management plans.
To achieve the security outcomes mandated above, organisations must:
Adopt a formal remote access policy that defines roles and responsibilities
for management, users, administrators and security personnel guided by
business needs, conditions, threats and the impacts of security breaches;
Demonstrate that adequate authentication, access control, communication
and availability measures are in place to reduce the risks of unauthorised
access, disruption and modification of remote access solution servers, clients
and applications in accordance with ISO/IEC 18028-4;
31