### Purpose

This policy defines minimum cybersecurity requirements for working away from company premises and accessing company systems remotely.

### Approved Remote Access

Remote access should use approved methods such as:

- Company VPN
- Zero-trust access service
- Managed remote desktop solution
- Approved cloud application
- Managed remote support platform

Directly exposing administrative services to the internet should be avoided where practical.

### Authentication

**Remote access should require:**

- Individual accounts
- MFA
- Strong authentication
- Additional protection for administrator access

### Devices

Remote workers should use approved devices that meet company security requirements.

**Devices should have:**

- Current security updates
- Endpoint protection
- Screen locking
- Encryption where appropriate
- Controlled administrator rights

### Home Networks

Employees should take reasonable precautions with home networks.

**Recommended measures include:**

- Changing default router passwords
- Using current Wi-Fi security
- Applying router updates
- Avoiding unknown or insecure networks

### Public Wi-Fi

Sensitive work on public Wi-Fi should use approved secure access methods.

Where practical, employees should prefer trusted networks or mobile hotspots.

### Remote Administration

Administrative access should receive stronger controls.

**Where possible:**

- Require VPN or zero-trust access
- Restrict source devices
- Require MFA
- Avoid direct public RDP or SSH
- Log administrator activity

### Privacy While Working Remotely

**Employees should prevent unauthorized people from:**

- Viewing sensitive information
- Using company devices
- Accessing printed company records
- Listening to confidential discussions

### Data Storage

Remote work does not change company data handling requirements.

Company information should remain in approved systems and should not be moved to personal storage for convenience.

### Lost Devices and Security Problems

**Remote employees must promptly report:**

- Lost devices
- Suspicious login prompts
- Unexpected MFA requests
- Device theft
- Malware warnings
- Unusual system behavior
- Data exposure

### Practical Rule

Remote work should not mean weaker security.

The same access, device, data, and reporting rules should apply wherever the employee is working.
