Cybersecurity recommendations for people who need to do Telework

Due to the health crisis caused by the coronavirus "Covid-19" many public administrations and companies are promoting teleworking. This is a list of the main protection measures that will allow you to carry out teleworking without jeopardizing the security in the processing of your organization's information.

  1. Follow the instructions of the technology manager of your company or entity. The communication channel for notifying incidents and resolving doubts must be well identified and the information must be kept out of control.
  2. Use only the tools and applications authorized by your company or entity. Even if as an Internet user you know of programs or web pages that may allow you to perform certain tasks, do not use them unless with the approval of the technology manager of your company or entity.
  3. You need to know the procedures that your company or entity routinely uses in their dealings with suppliers, customers, and partners. He suspects strange behavior, as many computer crimes often falsify identities to send messages to company workers and confuse them to steal information, passwords, and so on. Above all, do not rely on hypothetical messages requesting to renew passwords (unless confirmed by the technical references of the company or entity) and avoid downloading files of unknown origin.
  4. If the entity enables remote access and new applications, it sets up passwords that are truly complex. If you want to get a good password you can use generators such as the following: https://www.lastpass.com/password-generator. Also check if any of the passwords you used above have been compromised in any information leak or security breach (you can do this on the following website: https://haveibeenpwned.com/).
  5. To improve remote access control, ask your technical support for a second authentication factor. This will ensure that even if you get the password or your password stolen, you will also need your mobile phone, your email or an external USB key to access it.
  6. The computer you use for teleworking will have access to the confidential information of your company or entity, so it is important that it is only used by authorized users. Therefore, during the period that this computer remotely accesses your company or entity, it avoids the uses of leisure or personal as well as that of other family members.
  7. During the period of teleworking, you should limit Internet access to ensure that no risk of downloading content dangerous to the system is assumed. This also means ensuring that private computers used for teleworking have an active antivirus system and the system and applications are updated with the latesteres versions.
  8. All the office documentation that you generate on the private computer that you use to work remotely and is not saved on the work server will probably not have a system. còpia automated backup. Therefore, it is recommended that you take the precaution of making backup copies through, for example, private USB memories.
  9. Avoid remote access to business services from untrusted WiFi networks. That is, it avoids, if not necessary, public sharing networks that are not known and authorized. Your home WiFi network should have a complex and robust password that can prevent external sabotage.
  10. You need to make sure that your business or entity is already complying with standard security requirements, such as backups: duplicate backups and have two different types of media and locations.

This set of recommendations has been developed based on documents that have been openly published by the Catalan Association of Telecommunications Engineers (Telecos.cat) and the consultants Genís Margarit Contel and Cristina Ribas Casademont. From the AOC we thank them for helping us in such a way in these very complicated times.erescommitted to guaranteeing the security of public sector information systems, and therefore ensuring their proper functioning when it is most needed, such as the emergency situation we are experiencing.

Published in