an Information Technology Services Policy
The purpose of this policy is to state the requirements for remote access to computing resources hosted at ETSU using remote access technologies.
In order to access computing resources hosted at East Tennessee State University from off campus, use of ETSU remote access services is required. A remote access connection is a secured private network connection built on top of a public network, such as the Internet. Remote access provides a secure, encrypted connection, or tunnel, over the Internet between an individual computer (such as a computer off campus) and a private network (such as ETSU's). Use of remote access allows authorized members of the ETSU community to securely access ETSU network resources as if they were on the campus.
Remote access connections allow an outside computer to connect directly to the University's network. This arrangement provides convenience for the remote worker, but bypasses any firewall restrictions that may be in place. There is a network security risk present when accessing the university's network from an outside source. This risk is particularly pronounced for remote access connections from privately owned computers, as the University cannot ensure the computer has sufficient protection configured (e.g. anti-virus, anti-spyware). The risk posed by ETSU-owned computers is still present, but to a lesser degree.
Information Technology Services (ITS) is responsible for implementing and maintaining the University's remote access services. Therefore, ITS is also responsible for activities relating to this policy. Accordingly, ITS will manage the configuration of the University's remote access service.
ETSU currently implements two separate remote access solutions:
Microsoft Remote Desktop Gateway (RDP) is the recommended choice for most remote access users. This option provides sufficient access for the majority of users and reduces security risks to the university.
ETSU employees, and authorized third parties (customers, vendors, etc.) may, under some circumstances, utilize remote access to access ETSU computing resources for which they have been granted access.
Regular, full-time ETSU faculty or staff employees that have a valid ETSU Domain User Account may request remote access to the ETSU network by completing a Remote Access Request Form. A letter of justification must accompany the request. The letter should address, in sufficient detail, what resources will be accessed through the VPN and and explanation for why the resources cannot be accessed through conventional means. Requests omitting a letter of justification will be returned to the requester as incomplete.
With the exception of Remote Desktop Gateway (see Operational Procedures section) remote access is valid for a set period of time. Requesters should indicate the date remote access should take effect and the date access should expire. Remote access may be granted for a period of up to twelve months, after which remote access for the account will expire. Requesters will be notified via phone or email approximately thirty (30) days before remote access expires. Account holders may resubmit a Remote Access Request Form up to thirty (30) days before the remote access expiration date to continue remote access without disruption.
In order to use remote access, users will need a connection to the Internet from their off-campus location. While dial-up Internet connections may utilize a remote access connection, performance is very slow and is not recommended or supported.
The Chief Information Officer is charged with the responsibility to periodically review this policy and propose changes as needed.