Security Policy
  • Data Protection Standard
  • General
    • Acceptable Encryption Policy
    • Acceptable Use Policy
    • Data Breach Response Policy
    • Data Classification Policy
    • Disaster Recovery Plan Policy
    • Email Policy
    • Password Construction Guidelines
    • Password Protection Policy
    • Security Response Plan Policy
  • Network Security
    • Remote Access Policy
    • Remote Access Tools Policy
  • Server Security
    • Database Credentials Coding Policy
    • Information Logging Standard
    • Server Security Policy
Powered by GitBook
On this page
  • 1. Overview
  • 2. Purpose
  • 3. Scope
  • 4. Policy
  • 4.1 Requirements
  • 5. Policy Compliance
  • 5.1 Compliance Measurement
  • 5.2 Exceptions
  • 5.3 Non-Compliance
  • 6. Related Standards, Policies and Processes
  • 7. Revision History

Was this helpful?

  1. Network Security

Remote Access Policy

1. Overview

Remote access to our corporate network is essential to maintain our Team’s productivity, but in many cases this remote access originates from networks that may already be compromised or are at a significantly lower security posture than our corporate network. While these remote networks are beyond the control of GetCraft policy, we must mitigate these external risks the best of our ability.

2. Purpose

The purpose of this policy is to define rules and requirements for connecting to GetCraft's network from any host. These rules and requirements are designed to minimize the potential exposure to GetCraft from damages which may result from unauthorized use of GetCraft resources. Damages include the loss of sensitive or company confidential data, intellectual property, damage to public image, damage to critical GetCraft internal systems, and fines or other financial liabilities incurred as a result of those losses.

3. Scope

This policy applies to all GetCraft employees, contractors, vendors and agents with a GetCraft-owned or personally-owned computer or workstation used to connect to the GetCraft network. This policy applies to remote access connections used to do work on behalf of GetCraft, including reading or sending email and viewing intranet web resources. This policy covers any and all technical implementations of remote access used to connect to GetCraft networks.

4. Policy

It is the responsibility of GetCraft employees, contractors, vendors and agents with remote access privileges to GetCraft's corporate network to ensure that their remote access connection is given the same consideration as the user's on-site connection to GetCraft.

General access to the Internet for recreational use through the GetCraft network is strictly limited to GetCraft employees, contractors, vendors and agents (hereafter referred to as “Authorized Users”). When accessing the GetCraft network from a personal computer, Authorized Users are responsible for preventing access to any GetCraft computer resources or data by non-Authorized Users. Performance of illegal activities through the GetCraft network by any user (Authorized or otherwise) is prohibited. The Authorized User bears responsibility for and consequences of misuse of the Authorized User’s access. For further information and definitions, see the Acceptable Use Policy.

4.1 Requirements

  1. Secure remote access must be strictly controlled with encryption (i.e., Virtual Private Networks (VPNs)) and strong pass-phrases. For further information see the Acceptable Encryption Policy and the Password Policy.

  2. Authorized Users shall protect their login and password, even from family members.

  3. While using a GetCraft-owned computer to remotely connect to GetCraft's corporate network, Authorized Users shall ensure the remote host is not connected to any other network at the same time, with the exception of personal networks that are under their complete control or under the complete control of an Authorized User or Third Party.

  4. Use of external resources to conduct GetCraft business must be approved in advance by DevSecOps and the appropriate business unit manager.

  5. All hosts that are connected to GetCraft internal networks via remote access technologies must use the most up-to-date anti-virus software, this includes personal computers.

  6. Personal equipment used to connect to GetCraft's networks must meet the requirements of GetCraft-owned equipment for remote access as stated in the Hardware and Software Configuration Standards for Remote Access to GetCraft Networks.

5. Policy Compliance

5.1 Compliance Measurement

The DevSecOps Team will verify compliance to this policy through various methods, including but not limited to, periodic walk-throughs, video monitoring, business tool reports, internal and external audits, and inspection, and will provide feedback to the policy owner and appropriate business unit manager.

5.2 Exceptions

Any exception to the policy must be approved by Remote Access Services and the DevSecOps Team in advance.

5.3 Non-Compliance

An employee found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.

6. Related Standards, Policies and Processes

Please review the following policies for details of protecting information when accessing the corporate network via remote access methods, and acceptable use of <Company Name>’s network:

7. Revision History

Date of Change

Responsible

Summary of Change

October 2020

GetCraft DevSecOps Team

Initial version

PreviousSecurity Response Plan PolicyNextRemote Access Tools Policy

Last updated 4 years ago

Was this helpful?

Acceptable Encryption Policy
Acceptable Use Policy
Password Policy
Hardware and Software Configuration Standards for Remote Access to GetCraft Networks