Remote maintenance shall only occur after prior approval, monitoring to avoid unauthorised access, and approval of the outcome of the maintenance activities as described in approved processes or procedures.
The organization shall make sure that strong authenticators, record keeping, and session termination for remote maintenance is implemented.
The organization shall require that diagnostic services pertaining to remote maintenance be performed from a system that implements a security capability comparable to the capability implemented on the equivalent organization's critical system.