Mapping: 8.4.2 Remote Access Connections


8.4.2 : Remote Access Connections

Requirement:


If remote access is authorized for use in the IACS, the asset owner shall have policies and procedures around authorizing, authenticating, encrypting, documenting, logging and monitoring all interactive remote access connections. Documentation for each connection shall include, but not be limited to: a) its purpose, b) the remote access application to be used, c) encryption and authentication technologies used, d) how the connection will be established (for example, via the Internet through a virtual private network (VPN) through a DMZ) with instructions, as necessary, e) the circumstances requiring the connection, f) the length of time the connection needs to be open, including expected inactivity periods, g) the location and identity of the remote client device, application and user, and h) any compliance requirements that need to be met prior to establishing the connection.

Guidance:


Linked Article Note Edit
No linked articles available.