Security Basics mailing list archives
SSL VPN Risk Assessment
From: blagoon () gmail com
Date: 7 Mar 2008 15:54:43 -0000
Hi all, I was tasked to do a risk assessment on our SSL VPN deployment. And I came up with the following: - Authentication: Single factor is too weak, we'll be to use a hard token for a 2nd factor. - End Point Security: we need to verify the integrity of the connecting host (company asset, antivirus, patches), install cache cleaner and force inactive session timeouts. - Access control: limit full vpn access, implement resource profiles for different group of users, or only RDP to users' desktop in the office. But apparently it is not enough for my manager, and asked to expand this report. Any suggestions on areas I might have missed? Thanks,
Current thread:
- SSL VPN Risk Assessment blagoon (Mar 07)
- Re: SSL VPN Risk Assessment Nick Owen (Mar 07)
- Re: SSL VPN Risk Assessment Pierre Cadieux (Mar 11)
- <Possible follow-ups>
- RE: SSL VPN Risk Assessment Eric Pinkerton (Mar 11)
