S 5.33 Secure remote maintenance

Initiation responsibility: Head of IT, IT Security Officer

Implementation responsibility: Administrator, Head of IT

The remote maintenance of IT systems poses special security risks. When performing remote maintenance, the differentiation as to whether internal or external maintenance personnel accesses the IT systems must be made. For administrators to be able to help IT users quickly without having to physically go to the location where the particular IT system is installed, the IT support personnel will often use remote maintenance accesses. For security reasons, it makes sense to avoid using external personnel for remote maintenance. If this is not possible, additional security safeguards are unavoidable.

The IT system to be maintained must provide the following security functions:

Furthermore, additional functions can be implemented on the IT system to be maintained:

External remote maintenance

Remote maintenance using external networks or by third parties is particularly critical. For security reasons, it makes sense to avoid using external personnel for remote maintenance. If this is not possible, the following aspects must be considered in addition to the security safeguards mentioned above:

According to S 3.55 Non-disclosure agreements (NDAs), contractual provisions relating to data secrecy must be included in the contract concluded with the external maintenance personnel. It is especially important to specify that data stored externally in the context of maintenance must be deleted carefully after completing the maintenance work. Likewise, the duties and qualifications of the external maintenance personnel must be defined carefully.

Review questions: