Remote Access - Authorized Job Requirement, Tele-Commuting and Work-At-Home
Overall guidelines.
In cases where employee remote access is a job requirement but the situation is not covered by remote access to central web-enabled services, Harvard will provide a Harvard-owned computer and pay for Internet connectivity. Exceptions to this policy must be approved by the Harvard CIO.
Harvard-Owned Computer.
All remote access to Harvard confidential information not covered by remote access to central web-enabled services must be done using a Harvard-owned and managed computer. Such computers will be inventoried and configured by local technical support groups and will conform to normal Harvard Central Administration standards. The computer must have standard, licensed software installed, including Norton Anti-Virus Protection software, Advanced VPN (including Sygate security) software, SMS or other standard remote management and support tools. Local technical support groups will decide if employees will have administrative rights on the Harvard-provided computer. This computer is for the exclusive use of the employee and must not be used by others.
As of 2007, disk encryption on UIS DLS supported computers used for authorized remote access will be required. Customers with laptops used for this purpose, will be required to schedule time with DLS, to bring in their machines for the encryption software to be installed. In the event that the encryption password is lost by a user, s/he will have to bring in the computer to a DLS depot for issue resolution.
Internet connectivity.
Harvard will pay for broadband Internet connectivity to ensure an appropriate level of performance. A hardware router/personal firewall will be included and configured for additional security -- the specific firewall and firewall configuration are subject to local department IT practice. When configuring the router, any wireless feature should be disabled if not needed. If wireless is needed, the SSID must not be broadcasted.
Support:
If department purchases personal computing support from UIS Desktop and LAN Support (DLS) full phone support will be available within standard business hours (7:30 am – 8 pm Monday-Thursday, 7:30 am – 6:00 pm Friday). If phone or remote support fails, the employee must bring in the computer system for problem resolution. No on-site home support provided.
Other considerations.
Employees must follow University mandates on passwords and data protection. (See http://security.harvard.edu.) They must also follow the restrictions in the Harvard Personal Manual on installing software on the Harvard-provided computer. (See http://harvie.harvard.edu/policiesandcontracts/staff/persmanual/sec2/sec2privacy.shtml) Specifically including the restriction that no software is permitted to be installed on the Harvard-provided computer without specific prior approval. A password protected screen saver, which came with the computer, must be used. The timeout on the screen saver is determined by local technical support. The employee must not use the same password on the screen saver as the employee uses to access non-PIN-enabled Harvard applications or the employee uses for their PIN.
|