# Secure remote administration checklist worksheet

Adapt this planning resource to your environment. Examples are illustrative, not completed checks. Do not record secrets.

- Service / scope:
- Accountable owner:
- Reviewer:
- Environment / version:
- Review date:
- Approval / change reference:
- Next review trigger:

## Choose the access boundary

- [ ] Document which systems may be administered and from which managed devices.
- Environment-specific action:
- Expected result / stop condition:
- Observed result and evidence:
- Owner / due date:

## Control identity and permissions

- [ ] Require named accounts and strong multifactor authentication.
- Environment-specific action:
- Expected result / stop condition:
- Observed result and evidence:
- Owner / due date:

## Make sessions accountable

| Control | Verification question | Your record | Owner | Evidence reference | Status / due date |
| --- | --- | --- | --- | --- | --- |
| MFA | Does the real technician sign-in require it? |  |  |  |  |
| Scope | Can the account reach only approved devices? |  |  |  |  |
| Audit | Can a reviewer identify the operator and task? |  |  |  |  |
| Revocation | Are active and future sessions handled? |  |  |  |  |
| Recovery | Is an independent authorised path available? |  |  |  |  |

## Test removal and failure recovery

- [ ] Remove access when roles change or devices retire, and verify from both the identity layer and the remote-management platform.
- Environment-specific action:
- Expected result / stop condition:
- Observed result and evidence:
- Owner / due date:

## Closure

- Outcome: not started / pass / partial pass / fail
- Exceptions, owner and due date:
- Acceptance / approval:
- Follow-up and cleanup:

Source article: https://happysysadm.com/remote-access/secure-remote-admin-checklist/
