UNCLASSIFIED 5.10  Defend against random and targeted attacks by requiring users to power off devices when not in use; never to leave devices unattended; requiring that users store devices separately from credentials, amongst other measures;  Minimise data aggregation risks by ensuring that user devices only store data required to perform approved business activities at any given time;  Adopt anti-virus or anti-malware procedures including stand-alone systems (i.e. ‘sheep dips’) to scan portable and removable media for malicious code before their use for data import and export; and  Make sure that users are conversant with mobile device incident response and reporting procedures such as when to report device loss to the Police. Remote Access Security Remotely connecting a computer either to another computer or to a network over public networks such as the Internet increases staff flexibility and productivity. Staff with remote access can perform general work activities, access e-mail and transfer files. However, remote access presents unique security challenges to organisations. Firstly, remote access calls for additional security measures given that it occurs over insecure public networks. Secondly, because remote access occurs in exposed environments such as homes or when travelling, it increases exposure to risks such as theft of equipment and information, the unauthorised disclosure of information, unauthorised remote access to internal systems or misuse of facilities. Therefore, in accordance with ISO/IEC 27002, organisations must not authorise remote access or teleworking unless satisfied that suitable security arrangements and controls are in place and that the measures comply with relevant information security policies. Good remote access security can help achieve the following mandated information security outcomes. IS9 – All organisations must implement appropriate security measures to mitigate remote access risks. As a minimum requirement, organisations must: (a) adopt a formal remote access policy; (b) assess the risks, threats and vulnerabilities of remote access; (c) use security controls e.g. encryption to protect data whilst at rest and in transit; (d) educate users about remote access risks; (e) security accredit remote access solution handling classified data; and, (e) align remote access policy with incident management plans. To achieve the security outcomes mandated above, organisations must:  Adopt a formal remote access policy that defines roles and responsibilities for management, users, administrators and security personnel guided by business needs, conditions, threats and the impacts of security breaches;  Demonstrate that adequate authentication, access control, communication and availability measures are in place to reduce the risks of unauthorised access, disruption and modification of remote access solution servers, clients and applications in accordance with ISO/IEC 18028-4; 31

Select target paragraph3