Compliance Node Overview
For many organizations, their employees, contractors, business partners, vendors, and other users utilize enterprise telework technologies to perform work from external locations, using remote access technologies to interface with an organization’s non-public computing resources. The nature of telework and remote access technologies-permitting access to protected resources from external networks and often externally controlled hosts-generally places them at higher risk. All components of these solutions, including organization-issued and bring your own device (BYOD) client devices, remote access servers, and internal resources, should be secured against expected threats as identified through threat models. Major security concerns include the lack of physical security controls, the use of unsecured networks, the connection of infected devices to internal networks, and the availability of internal resources to external hosts. This publication provides information on security considerations for several types of remote access solutions and makes recommendations for securing telework, remote access, and BYOD technologies. It also gives advice on creating related security policies, which should be based on the assumption that external environments contain hostile threats. An organization should assume that external facilities, networks, and devices contain hostile threats that will attempt to gain access to the organization’s data and resources. Organizations should plan policies that define permitted forms of remote access, restrictions on client devices, and how servers are secured and configured to enforce these policies.
Pillar: Cybersecurity · Authority: National Institute of Standards and Technology · Version: 1.0.0 · Last updated:
Primary source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-46r2.pdf
SHA-256 integrity: bf3a54c9be783deb410814fcab40aeb4c9a89b50b16ec46ca8a45d51af1260cc
Primary Citations — 8 traced to source
- Executive Summary: Plan telework-related security policies and controls based on the assumption that external environments contain hostile threats.
- Executive Summary: A telework security policy should define which forms of remote access the organization permits, which types of telework devices are permitted to use each form of remote access, and the type of access each type of teleworker is granted.
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access