Each subscriber organization establishes its own policies for determining which employees may work at home or in other remote workplace locations. Any remote work arrangement should include policies that:
Are in writing.
Provide authentication of the remote user through the use of ID and password or other acceptable technical means.
Outline the work requirements and the security safeguards and procedures the employee is expected to follow.
Ensure adequate storage of files, removal, and non-recovery of temporary files created in processing sensitive data, virus protection, and intrusion detection, and provide physical security for government equipment and sensitive data.
Establish mechanisms to back up data created and/or stored at alternate work locations.
Remote RPMS users shall:
Remotely access RPMS through a virtual private network (VPN) whenever possible. Use of direct dial-in access must be justified and approved in writing and its use secured in accordance with industry best practices or government procedures.
Remote RPMS users shall not:
Disable any encryption established for network, internet, and Web browser communications.