N.Y. Comp. Codes R. & Regs. tit. 9 § 5317.35

Current through Register Vol. 46, No. 45, November 2, 2024
Section 5317.35 - Remote access requirements

If supported, a MCS may use password-controlled remote access to a MCS so long as the following requirements are met:

(a) remote access user-activity log is maintained depicting logon name, time, date, duration and activity while logged in;
(b) no unauthorized remote-user administration functionality (adding users, changing permissions, etc.) shall be permitted;
(c) no unauthorized access to the database, other than information retrieval using existing functions, shall be permitted;
(d) no unauthorized access to the operating system shall be permitted; and
(e) if remote access is to be continuous, then a network filter (firewall) shall be installed to protect access.

N.Y. Comp. Codes R. & Regs. Tit. 9 § 5317.35

Adopted New York State Register November 16, 2016/Volume XXXVIII, Issue 46, eff. 11/16/2016