Remote Work and Remote Access Policy
Purpose
This policy defines minimum cybersecurity requirements for working away from company premises and accessing company systems remotely.
Approved Remote Access
Remote access should use approved methods such as:
- Company VPN
- Zero-trust access service
- Managed remote desktop solution
- Approved cloud application
- Managed remote support platform
Directly exposing administrative services to the internet should be avoided where practical.
Authentication
Remote access should require:
- Individual accounts
- MFA
- Strong authentication
- Additional protection for administrator access
Devices
Remote workers should use approved devices that meet company security requirements.
Devices should have:
- Current security updates
- Endpoint protection
- Screen locking
- Encryption where appropriate
- Controlled administrator rights
Home Networks
Employees should take reasonable precautions with home networks.
Recommended measures include:
- Changing default router passwords
- Using current Wi-Fi security
- Applying router updates
- Avoiding unknown or insecure networks
Public Wi-Fi
Sensitive work on public Wi-Fi should use approved secure access methods.
Where practical, employees should prefer trusted networks or mobile hotspots.
Remote Administration
Administrative access should receive stronger controls.
Where possible:
- Require VPN or zero-trust access
- Restrict source devices
- Require MFA
- Avoid direct public RDP or SSH
- Log administrator activity
Privacy While Working Remotely
Employees should prevent unauthorized people from:
- Viewing sensitive information
- Using company devices
- Accessing printed company records
- Listening to confidential discussions
Data Storage
Remote work does not change company data handling requirements.
Company information should remain in approved systems and should not be moved to personal storage for convenience.
Lost Devices and Security Problems
Remote employees must promptly report:
- Lost devices
- Suspicious login prompts
- Unexpected MFA requests
- Device theft
- Malware warnings
- Unusual system behavior
- Data exposure
Practical Rule
Remote work should not mean weaker security.
The same access, device, data, and reporting rules should apply wherever the employee is working.