Can your employees access customer systems remotely?
Explanation
Example Responses
Example Response 1
Yes, our support engineers can access customer systems remotely, but only under specific circumstances and with strict controls Remote access is only granted when troubleshooting issues that cannot be resolved through other means, and only after receiving explicit written approval from an authorized customer representative All remote access sessions require multi-factor authentication, are conducted through encrypted VPN tunnels, are limited to the specific systems necessary for troubleshooting, are logged and recorded, and are monitored in real-time by our security team Remote access credentials are unique to each engineer and are rotated every 30 days All remote access sessions are terminated immediately upon completion of the required work.
Example Response 2
No, our employees do not have remote access to customer systems Our service operates on a SaaS model where customers access our application through secure web interfaces All maintenance, updates, and support are performed on our own infrastructure, not on customer systems If troubleshooting is required, we work with customers to gather necessary logs and information through secure file transfer methods, but we never directly access customer environments or systems remotely.
Example Response 3
Currently, our technical support team does have the capability to remotely access customer systems for troubleshooting purposes, but we recognize this presents security risks We are in the process of implementing stronger controls around this access At present, remote access occurs through standard RDP or SSH connections with basic password authentication We do not yet have a formal customer approval process in place, though we typically notify customers before connecting We acknowledge this is an area for improvement in our security program, and we are working to implement multi-factor authentication, session recording, and formal access request procedures within the next quarter.
Context
- Tab
- Case-Specific
- Category
- Payment Card Industry Data Security Standard (PCI DSS)

