Mobile Device And Teleworking Policy¶
mobile device and teleworking Policy
Version history¶
| Version Number | Date | Description | Created By | Approved By |
|---|---|---|---|---|
| 0.1 | 23/Apr/2024 | Initial Copy | [Name] [Name] | |
| 0.2 | 18/Jun/2024 | Approved | [Name] [Name] | [Name] |
| 0.3 | 28/Aug/2026 | Knowledge kernel, AI/agents, control alignment | Knowledge steward | [Name] |
Purpose¶
The purpose of this procedure is to define the process of approving and managing remote access to information systems of tecciance.
Scope¶
This policy applies to all users who need remote access to information systems of tecciance.
Responsibilities¶
The primary ownership of implementing this Policy is with IT. The IT Team shall implement this Policy under the guidance of the Leadership Team and in coordination with Department Heads.
Policy¶
Remote Working / Work from Home Approval¶
-
Approval for remote working or working from home shall be provided against approval from Reporting Manager or in the event of BCP activation.
-
Users shall be provided with Laptops or shall be allowed to use personal devices (BYOD) against the approval. Internet facility for working remotely shall be arranged by the User.
Remote Access
-
Access to information systems of tecciance shall be provided using VPN. VPN Credentials shall be provided to Users (Login / Password) for accessing information systems.
-
For other information systems, which are not covered through VPN, user credentials shall be used as provided for authentication within the information system.
Procedure¶
Approval Process¶
-
Remote Access to Users may be provided on request or during BCP situations wherein the office location is not accessible.
-
Any User who needs remote access should apply through email. The User should raise a 'Remote Access Request’ in email.
-
User should provide minimum information as below, at the time of the request:
-
Duration or period of remote access, Name of Information Systems / Applications to which access is required, Reason for remote access, Details of Laptop / Desktop / Device which would be used for remote access. Reporting Manager of the User shall approve the request. Reporting Manager should confirm/change the applications or period of access at the time of approval.
-
Once the request is approved, the Ticket should be assigned/forwarded to IT Team for execution. In case any Administrative Access is required to be provided through remote access, additional approval should be taken from ISMS Head.
-
During the BCP process, the BCP Team will approve Remote Access for all Users who are affected. Such requests may be tracked through email on a group basis.
Provisioning of Remote Access for Users
-
Once the request is received, the IT Team shall review the request and assign resources for execution. In case of any discrepancy or additional approvals required, the IT Team shall get the same through emails.
-
For execution, IT Team Members shall check the available VPN Licenses which need to be provisioned for the User.
-
If the License is not available, the IT Team shall proceed to add the License subscription for VPN.
-
Once the License is available, the IT Team shall configure the VPN for the User and generate a Login using the User Credentials and default password.
-
The Device (Laptop / Desktop / Mobile Device) details including the MAC Address / IMEI Number shall be tagged to ensure authorized access by authenticated device.
-
The duration of Remote Access should be programmed while providing access so that auto- disabling is possible once the approved duration is completed.
-
Once generated, the IT Team will share the Username (Login Credentials) and Default
-
Password to the User through email. The User will be forced to reset/change the password on the first successful login. Remote Access provisioned shall be updated within Access Control Matrix.
Provisioning of Remote Access for Administrators¶
-
Additional security arrangements shall be made for Administrative Accesses which are required through remote access. Wherever Administrative Access is required to be provided to a User through remote access, Multi-Factor Authentication (MFA) should be enabled.
-
For AWS, Identity and Access Management (IAM) can be used to provide Multi-Factor Authentication.
-
For more details about how to configure IAM on AWS, please refer to the link provided.
Revoking of Remote Access¶
-
Remote Access shall be revoked in either of the below conditions:
-
When the approved time duration of remote access is completed.
-
Request for revocation is triggered by any Reporting Manager before the approved period is completed.
-
Any User separates from the Organization, based on resignation or expiry/termination of Contract / Agreement.
-
Email requests should be raised for revocation of remote access, in any of the above situations.
-
Automatic revocation should be enabled based on the duration specified at the time of provisioning.
-
Email request should be created by the Reporting Manager and IT Team should assign it to Resource for completion. Once access is revoked, relevant changes shall be made within the Access Control Matrix.
Review of Remote Access¶
-
Review of remote access users shall be conducted based on Access Control Matrix. Complete review of Remote Access provided shall be conducted on a Quarterly basis by IT Team.
-
Any discrepancies found during Access Review shall be fixed and captured.
-
Such discrepancies and actions taken shall be reported to the IT Team over emails. Appropriate changes shall be made within Access Control Matrix based on the review.
Reference¶
-
Logical Access Control Policy
-
Key Management Policy
-
Password Management
-
Template – User Access Matrix
-
Records of Remote User / Work from Home Approvals
Definitions¶
Following is an explanation of various terms used within this document:
-
Remote Access: Remote access is the ability for an authorized person to access a computer or a network from a geographical distance. This allows employees to work offsite, such as at home or in another location, while still having access to a distant computer or network, such as the office network.
-
VPN: Virtual Private Network - is a network that is constructed using public wires, usually the internet, to connect remote users to a company's private, internal network. The VPN secures the private network, using encryption and other security mechanisms to ensure that only authorized users can access the network and that the data cannot be intercepted.
-
LT: Leadership Team
-
IST: Information Security Team
Artificial intelligence, software agents, and organizational knowledge¶
This section is added in version 0.3 so the policy applies equally to employees and to software agents, and so reusable knowledge stays provenanced.
Software agents, bots, service accounts, CI jobs, and coding assistants are identities. They are in scope of this policy wherever people are.
Every retrieve or use of organizational knowledge or classified data requires a verified identity, a stated purpose, and a classification ceiling. Missing purpose is deny.
AI may extract, draft, rank, or propose. AI shall not approve access, classify or reclassify information, set reuse rights, waive a control, merge to a protected branch, or treat search ranking as truth.
Approved reusable knowledge is a governed claim with source, owner, lifecycle, applicability, and limitations. Raw chat, tickets, and scanner output are not approved knowledge.
Embeddings, summaries, caches, and compiled agent skills are derivatives. Withdrawal, reclassification, or destruction of a source shall propagate to derivatives.
Secrets, credentials, production data dumps, and Restricted (including client/PHI) material shall not be pasted into public generative-AI services or stored in vector indexes unless an authorized path and agreement exist.
HIPAA-regulated PHI is out of default scope. Enable the HIPAA pack and a business-associate path before any PHI is processed by agents or knowledge indexes.
Change to a must procedure (including knowledge used by agents) is a change under the Change / Release procedure and SOC 2 CC8.1. Agents cannot approve that change.
Remote use of coding agents is subject to the same classification and purpose rules as on-network use.