Remote access is valuable, but unmanaged tools and weak identity controls create a direct path into important systems. This template defines an enforceable baseline while allowing organisations to document approved exceptions and responsibilities.
Required policy controls
Approved services onlyRemote access must use services approved and centrally managed by the organisation or its authorised IT provider. Unapproved remote-control software is prohibited.
Individual identity and MFAEvery user must authenticate with an individual account and multi-factor authentication. Shared remote-access accounts are not permitted.
Least privilegeAccess is limited to the systems and permissions required for the approved role. Administrator access uses a separate controlled account.
Managed devicesAccess to sensitive or administrative systems is permitted only from devices meeting the organisation's security, encryption, update and monitoring requirements.
Operational requirements
Access approvalThe system owner and IT custodian approve access, document its purpose and set an expiry or review date.
Vendor accessThird-party access is enabled for an agreed purpose and period, monitored where appropriate and removed promptly when no longer required.
Logging and reviewAuthentication and administrative activity is logged where supported. Access rights and installed remote tools are reviewed regularly.
Safe workingUsers prevent unauthorised viewing, do not save sensitive information to unmanaged devices and lock or end sessions when unattended.
Incident and exception handling
Report suspicious activity immediatelyUnexpected MFA prompts, remote-control windows, login alerts or unexplained software must be reported through the urgent incident channel.
Revoke before investigatingWhen compromise is suspected, authorised personnel may disable sessions, accounts or remote services to contain risk while preserving evidence.
Document exceptionsAn exception records the business need, risk, compensating controls, owner, approval and expiry date. Permanent undocumented exceptions are not accepted.
Review the policyReview at least annually and after a significant incident, technology change, insurer requirement or change to remote-work arrangements.
Important contextAdapt and approve this policy for your organisation. It should align with employment arrangements, contractual obligations, privacy requirements, cyber insurance conditions and current technical controls.
