Remote Work and Remote Access Policy

Purpose

This policy defines minimum cybersecurity requirements for working away from company premises and accessing company systems remotely.

Approved Remote Access

Remote access should use approved methods such as:

  • Company VPN
  • Zero-trust access service
  • Managed remote desktop solution
  • Approved cloud application
  • Managed remote support platform

Directly exposing administrative services to the internet should be avoided where practical.

Authentication

Remote access should require:

  • Individual accounts
  • MFA
  • Strong authentication
  • Additional protection for administrator access

Devices

Remote workers should use approved devices that meet company security requirements.

Devices should have:

  • Current security updates
  • Endpoint protection
  • Screen locking
  • Encryption where appropriate
  • Controlled administrator rights

Home Networks

Employees should take reasonable precautions with home networks.

Recommended measures include:

  • Changing default router passwords
  • Using current Wi-Fi security
  • Applying router updates
  • Avoiding unknown or insecure networks

Public Wi-Fi

Sensitive work on public Wi-Fi should use approved secure access methods.

Where practical, employees should prefer trusted networks or mobile hotspots.

Remote Administration

Administrative access should receive stronger controls.

Where possible:

  • Require VPN or zero-trust access
  • Restrict source devices
  • Require MFA
  • Avoid direct public RDP or SSH
  • Log administrator activity

Privacy While Working Remotely

Employees should prevent unauthorized people from:

  • Viewing sensitive information
  • Using company devices
  • Accessing printed company records
  • Listening to confidential discussions

Data Storage

Remote work does not change company data handling requirements.

Company information should remain in approved systems and should not be moved to personal storage for convenience.

Lost Devices and Security Problems

Remote employees must promptly report:

  • Lost devices
  • Suspicious login prompts
  • Unexpected MFA requests
  • Device theft
  • Malware warnings
  • Unusual system behavior
  • Data exposure

Practical Rule

Remote work should not mean weaker security.

The same access, device, data, and reporting rules should apply wherever the employee is working.