UNCLASSIFIED
Enforce a remote access policy requirement that users and devices only gain
access to network services for which they authorisation for;
Grant remote access only for as long as is necessary for business purposes;
Use encryption of suitable strength to secure communication links and the
content that they process against eavesdropping;
Encrypt remote access clients to make them inaccessible if lost or stolen;
Ensure that users accept and comply with the Security Operating Procedures
(SyOPs) for mobile devices such as powering off devices when not in use;
Ensure that users know and accept their personal accountability for guarding
remote access devices against threats and risks in insecure environments
such as snatching, shoulder-surfing, eavesdropping etc;
Provide remote access servers satisfactory security including protection
against unauthorised physical access; assured power supply; secure set-up,
configuration and administration; back-up and recovery procedures;
Present a formal risk assessment and obtain approval from relevant security
agencies before permitting the remote administration of critical infrastructure,
programs and data from overseas locations given the risk posed by threat
actors and sources such as foreign intelligence services to such access;
Ensure that remote access solutions, including contracts with IT suppliers,
comply with applicable legislative or regulatory constraints in particular the
Official Secrets Act, 1964 and the Access to Information Act, 2005 regarding
the handling of information, which is likely to prejudice the security of the
State or interfere with the right to the privacy of any other person;
Submit remote access solutions to a formal security accreditation process to
provide assurance about the adequacy of information security measures e.g.
baseline builds; personnel and physical security controls in the context of the
unique threats, vulnerabilities and risks such solutions face; and
Sanitise and dispose of remote access devices in accordance with the NISF
Secure Equipment Disposal and Re-Use requirements.
32