Security Basics mailing list archives
Re: Remote desktop access policy
From: "Josh Haft" <pacmansyu () gmail com>
Date: Fri, 18 Jan 2008 10:05:41 -0600
On Jan 18, 2008 7:33 AM, WALI <hkhasgiwale () gmail com> wrote:
Hi guys...do you have any remote desktop policy clauses that you can share? I am having difficulties in trying to tell people the hazards of haphazardly asking IT guys the perils of asking access to their desktops when the come in via VPN. Everyone wants to have a VPN client and then to a remote desktop session to their desktop. How can I tell them the threats of doing so? Are there any threats? Should I restrict such usage? For one, it makes a lot of economic sense to switch off PC once a user leaves his/her desk for the day.
Are you referring to regular users connecting via VPN, or administrators? Normal users generally don't take the same precautions that administrators do. They might leave the connection open for an extended period of time, exposing your internal network to anyone that has access to their VPN connected client. I generally view it as a bad idea for users to have VPN access, but there's always a business case to be made... Depending on the VPN software you use, you'll definitely want to limit which devices a connecting user has access to. We don't have a formal policy dictating who gets VPN/RDP access, rather it's approved on an individual case basis. I would, however, be interested in a policy. We don't have users switch off their computers when they leave since we have updates go out at night and then auto-reboot the machine.
Current thread:
- Analyzing Suspicious Attachment Al Cooper (Jan 17)
- Re: Analyzing Suspicious Attachment Albert R. Campa (Jan 17)
- RE: Analyzing Suspicious Attachment Brett Kennedy (Jan 17)
- Remote desktop access policy WALI (Jan 18)
- RE: Remote desktop access policy Petter Bruland (Jan 18)
- AW: Remote desktop access policy Johannes Lemmerer (Jan 18)
- Re: Remote desktop access policy Josh Haft (Jan 18)
- Re: Remote desktop access policy The Security Community (Jan 18)
- Re: Remote desktop access policy Kurt Buff (Jan 19)
- Re: Remote desktop access policy WALI (Jan 21)
- Re: Remote desktop access policy Kurt Buff (Jan 21)
- RE: Analyzing Suspicious Attachment Brett Kennedy (Jan 17)
- Re: Analyzing Suspicious Attachment Albert R. Campa (Jan 17)
- Re: Remote desktop access policy Gleb Paharenko (Jan 18)
- Re: Remote desktop access policy Kurt Buff (Jan 19)
- Re: Analyzing Suspicious Attachment brian . bevers (Jan 17)
