Description

The university authorizes, monitors, and controls any remotely executed (i.e. nonlocal) maintenance and diagnostic activities.

Applicability

  • The owner of an information resource, or designee, is responsible for implementing this Control.

Implementation

  • 1

    It is the responsibility of the information resource owner, or designee to:

    • 1.1

      Approve and monitor nonlocal maintenance and diagnostic activities;

    • 1.2

      Allow the use of nonlocal maintenance and diagnostic tools only as consistent with university policy;

    • 1.3

      Employ strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions;

    • 1.4

      Maintain records for nonlocal maintenance and diagnostic activities; and

    • 1.5

      Terminate session and network connections when nonlocal maintenance is completed.