IAM-36—Remote Maintenance: Audit
>Control Description
Organization documents and maintains records for vendor remote maintenance, diagnostic activities, and permissions granted. A listing of vendor remote maintenance connections is documented as well.
Theme
Process
Type
Preventive
Policy/Standard
Remote Access Procedure>Implementation Guidance
1.Ensure vendor remote access is documented and that they include: -Maintenance activities -Diagnostic activities -Permissions granted 2. Ensure that there is no unauthorized access be vendor or third parties.
>Testing Procedure
1. Inspect documents and records for vendor remote access. 2. Review the records and ensure that they include: -Maintenance activities -Diagnostic activities -Permissions granted 3. Review the list of vendor remote connections and ensure that there is no unauthorized access.
>Audit Artifacts
E-IAM-49
>Framework Mappings
Cross-framework mappings provided by Adobe CCF Open Source under Creative Commons License.
Ask AI
Configure your API key to use AI features.