S 4.63 Security-related requirements for telecommuting computers

Initiation responsibility: IT Security Officer, Top Management

Implementation responsibility: Head of IT, Administrator

The security-related requirements for the telecommuting computer are based on the protection requirements of the data to be processed on the telecommuting workstation and of the data that can be accessed by the telecommuter through the communications computer of the organisation. The higher the protection requirement, the more safeguards need to be taken to guarantee this protection is available. General security objectives for telecommuting computers include the following:

The security objectives, and therefore the security requirements placed on the telecommuting computer, are derived from the protection requirements of the data to be processed on the telecommuter workstation. It must be documented which of the security-related functionality described in the following need to be available on a telecommuting computer and how this functionality is implemented.

The following functionalities are therefore useful on a telecommuting computer:

The functionality needed by the telecommuting computer according to the security requirements must be selected from the functionality listed above. A suitable operating system must then be selected as a platform based on the functionality chosen. If the operating system does not support all required functionality, then additional products must be used to provide it. If possible, every telecommuting computer in an organisation should be identically equipped in order to simplify maintenance and support. Module S 1.10 Standard software should be considered for the security-related suitability tests.

The overall system must be configured by the administrators so that the maximum level of security can be reached.

Review questions: