Current through Register Vol. 46, No. 45, November 2, 2024
Section 5317.35 - Remote access requirementsIf supported, a MCS may use password-controlled remote access to a MCS so long as the following requirements are met:
(a) remote access user-activity log is maintained depicting logon name, time, date, duration and activity while logged in;(b) no unauthorized remote-user administration functionality (adding users, changing permissions, etc.) shall be permitted;(c) no unauthorized access to the database, other than information retrieval using existing functions, shall be permitted;(d) no unauthorized access to the operating system shall be permitted; and(e) if remote access is to be continuous, then a network filter (firewall) shall be installed to protect access.N.Y. Comp. Codes R. & Regs. Tit. 9 § 5317.35
Adopted New York State Register November 16, 2016/Volume XXXVIII, Issue 46, eff. 11/16/2016