Governance of Enterprise IT - Discussion
NIST issues security guidance for teleworking, establishing remote access Friedman, Sara
ProQuest document link
FULL TEXT March 20, 2020 | Sara Friedman The National Institute of Standards and Technology has issued guidance to help government agencies and private organizations enable their employees to work from home while still maintaining network security. "Organizations should carefully consider the balance between the benefits of providing remote access to additional resources and the potential impact of a compromise of those resources," said NIST in the document from the agency's Information Technology Lab on Wednesday. "To mitigate risk, organizations should ensure that any internal resources they choose to make available through remote access for telework purposes are hardened against external threats and that access to the resources is limited to the minimum necessary." The guidance comes as the Office of Management and Budget is telling federal government departments and agencies "to prioritize all resources to slow the transmission of COVID-19, while ensuring our mission-critical activities continue." NIST suggests four ways that organizations can provide their employees with remote access to their computing resources: tunneling, a portal, direct application access, or remote desktop access. Tunneling involves creating a "secure communications tunnel" between a telework client and a remote access server. This is usually done through creating a virtual private network gateway. The Cybersecurity and Infrastructure Security Agency issued guidance last week on enterprise VPNs, which provides details on technical detail considerations and mitigation tactics. A portal is a server that offers access to one or more applications through a single centralized interface. Most portal architectures today are secure sockets layer VPNs. Direct application access allows users to access individual applications directly that they have their own security in place, such as communications encryption and user authentication. When using a remote desktop access solution, a teleworker can remotely control a particular desktop computer at their office using a telework client device. The NIST guidance also lays out several security concerns that arise when using telework and remote access technologies: * Lack of security controls on telework client devices used outside of an organization's control, such as an employees' home, coffee shops and other businesses. * Unsecured networks susceptible to "eavesdropping" and "man-in the middle attacks" to intercept and modify communications. * Providing external access to internal-only resources. NIST recommends improving the security of telework and remote access solutions by planning out telework security policies and network controls assuming that external environments contain "certain hostile threats." Organizations should also create a telework policy with clear details on telework, remote access and bring your own device requirements. This NIST guidance was developed based on a publication put out by NIST in 2016, "Guide to Enterprise Telework, Remote Access, and Bring Your Own Device (BYOD) Security." On Thursday, NIST published a blog post outlining how individuals can improve network security for their own
workspaces. Other agencies are also taking steps to ensure that their employees and their customers have access to critical services during the COVID-19 crisis. The Cybersecurity Infrastructure and Security Agency issued guidance Thursday with a list of critical infrastructure sectors and functions that need to be considered as essential functions as state and local authorities make decisions on workplace restrictions. House Homeland Security Committee chairman Bennie Thompson has also asked President Trump to direct the Department of Homeland Security on how "to evaluate continuity of operations for critical infrastructure" in a letter Thursday. -- Sara Friedman ([email protected]) DETAILS
Subject: Remote searching; Network security; Virtual private networks; National security; Computer security; Coronaviruses; COVID-19; Disease transmission; Infrastructure; Employees; Telecommuting; Government agencies
Business indexing term: Subject: Infrastructure Employees Telecommuting
Location: United States--US
Company / organization: Name: National Institute of Standards &Technology; NAICS: 541380, 541714, 926150
Publication title: Inside Cybersecurity; Arlington
Publication year: 2020
Publication date: Mar 24, 2020
Publisher: Inside Washington Publishers
Place of publication: Arlington
Country of publication: United States, Arlington
Publication subject: Computers--Computer Security
Source type: Trade Journal
Language of publication: English
Document type: News
ProQuest document ID: 2382562502
Document URL: https://www.proquest.com/trade-journals/nist-issues-security-guidance- teleworking/docview/2382562502/se-2?accountid=158986
Copyright: Copyright Inside Washington Publishers Mar 24, 2020
Database copyright 2023 ProQuest LLC. All rights reserved. Terms and Conditions Contact ProQuest
Full text availability: This publication may be subject to restrictions within certain markets, including corporations, non-profits, government institutions, and public libraries. In those cases records will be visible to users, but not full text.
Last updated: 2023-04-06
Database: ProQuest Central
- NIST issues security guidance for teleworking, establishing remote access