The use of VPN (Virtual Private Network) to access your charity desktop from a home computer can be provided through a formal request to the Service Desk.

Accessing charity desktops from personal computers poses specific risks to charity data and services. To reduce these risks, all charity users of VPN access must agree and follow the terms and conditions of use, detailed in this document.

These terms and conditions provide user awareness of the technical controls and sensible working practices required to maintain appropriate levels of security.

You are required to comply with all bullet points listed below. If necessary, seek help from Service Desk to meet these requirements. These terms apply to both charity and personally owned devices.


Conditions of use

· Personal computers used for remote access must be password protected.

· Charity user name and password must not be stored on your computer.

· Internet security and anti-virus software must be up to date and enabled.

· Full system anti-virus scanning must be scheduled weekly.

· Real-time anti-virus scanning must be enabled.

· Updates to anti-virus definition files must be scheduled daily.

· Windows updates must be enabled and set to auto-update.

· Home wireless network must have encryption enabled (WPA or WPA2).

· Charity data must not be created on, or transferred to personal computers or external storage.

· Charity data must not be created on, or transferred to cloud storage platforms (e.g. Dropbox, Google Drive), or e-mailed to personal e-mail accounts.

· Personal devices must not be used for charity purposes in public areas where screen content can easily be seen.

· If personal computing equipment is no longer being used for remote access, or is being disposed of, then the VPN client must be uninstalled.

· Personal computing equipment used for charity purposes must be kept in secure locations.

· All security concerns or incidents must be reported to Service Desk.

· If VPN access is no longer required then this must be communicated to Service Desk, who will remove the account.