Sign in

A provider connects to your systems

Complete plan

Remote access for an IT provider or integrator, set in six points: a named account, multi-factor authentication, only the rights needed, a limited time, logged connections, and everything removed at the end.

  • 3 min
  • 3-question check
  • English · Français
  • Attestation

You will be able to

  • Give each of a provider's technicians an account in their own name, protected by multi-factor authentication, never a shared account or an internal admin's
  • Limit access to the systems and rights needed, for the time of the job, opened on demand and logged
  • Remove accounts, access and tools at the end of the job or contract, and change the passwords the provider knew

The module

3 min
  1. A provider connects to your systems 2 min
  2. Knowledge check

    3 questions, pass mark 80 %. Explanations after each answer; you can try again.

  3. Attestation

    One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.

Sources
  • ANSSI, Guide d'hygiène informatique (lu en entier via CISO Assistant) : mesure 8 « les comptes d'accès doivent être nominatifs », mesure 13 (authentification à deux facteurs), mesures 6 et 26 (retrait des droits au départ ou au changement de prestataire), mesure 25 (« Le partenaire étant considéré par défaut comme non sûr »)
  • ANSSI, Recommandations relatives à l'administration sécurisée des SI, v3 (mai 2021), section 12 (intitulés lus via CISO Assistant) : R60, R62 (accès distant dédié), R64 (comptes dédiés aux administrateurs tiers), R66 « Activer à la demande les comptes des administrateurs tiers », R67, R69 (contrôle d'accès strict et traçabilité) ; R30, R31, R36, R39
  • Règlement d'exécution (UE) 2024/2690, annexe, 11.2.2(d) (accès des tiers limité « in scope and in duration ») et 6.7.2(d) ; ENISA, guide de mise en œuvre (juin 2025) : « Use temporary access accounts with expiry dates » (lus via CISO Assistant) ; directive NIS 2, art. 21(2)(i) et (j)
  • Commission du commerce du Sénat des États-Unis, « A "Kill Chain" Analysis of the 2013 Target Data Breach » (26 mars 2014) et Krebs on Security (5 et 12 février 2014) : identifiants réseau volés à un prestataire de réfrigération et climatisation, entrée par un système destiné aux fournisseurs, puis terminaux de paiement, environ 40 millions de cartes (lu en extrait de recherche seulement, sources concordantes ; aucun chiffre dans la voix)
  • CISA / NSA, « Guide to Securing Remote Access Software » (6 juin 2023) : extrait de recherche seulement
  • ISO/IEC 27001:2022, annexe A, 5.15, 5.18, 5.19, 8.2, 8.15 (intitulés)

Version 1 · updated October 6, 2026