UNCLASSIFIED  Enforce a remote access policy requirement that users and devices only gain access to network services for which they authorisation for;  Grant remote access only for as long as is necessary for business purposes;  Use encryption of suitable strength to secure communication links and the content that they process against eavesdropping;  Encrypt remote access clients to make them inaccessible if lost or stolen;  Ensure that users accept and comply with the Security Operating Procedures (SyOPs) for mobile devices such as powering off devices when not in use;  Ensure that users know and accept their personal accountability for guarding remote access devices against threats and risks in insecure environments such as snatching, shoulder-surfing, eavesdropping etc;  Provide remote access servers satisfactory security including protection against unauthorised physical access; assured power supply; secure set-up, configuration and administration; back-up and recovery procedures;  Present a formal risk assessment and obtain approval from relevant security agencies before permitting the remote administration of critical infrastructure, programs and data from overseas locations given the risk posed by threat actors and sources such as foreign intelligence services to such access;  Ensure that remote access solutions, including contracts with IT suppliers, comply with applicable legislative or regulatory constraints in particular the Official Secrets Act, 1964 and the Access to Information Act, 2005 regarding the handling of information, which is likely to prejudice the security of the State or interfere with the right to the privacy of any other person;  Submit remote access solutions to a formal security accreditation process to provide assurance about the adequacy of information security measures e.g. baseline builds; personnel and physical security controls in the context of the unique threats, vulnerabilities and risks such solutions face; and  Sanitise and dispose of remote access devices in accordance with the NISF Secure Equipment Disposal and Re-Use requirements. 32

Select target paragraph3