Home > Financial Services Information Security Tips > Security Architecture Insider > Steps to secure your remote users
Financial Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY ARCHITECTURE INSIDER

Steps to secure your remote users


Bradley Dinerman, Contributor
09.09.2008
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


In most cases, businesses do not realize the repercussions of providing remote access for users, and they do little to protect themselves from threats that result from this remote access.

The higher levels of remote access, such as that which comes from a VPN, extend the LAN to include the employee's home computer, network and Internet connection. By default, many financial businesses employ Microsoft's VPN tool, which is included at no additional cost with Windows NT/2000 servers and is straightforward to configure.

A typical IT administrator will verify that corporate workstations are running current antivirus applications, will hopefully have a firewall in place to protect the LAN from external threats, and may even have set acceptable use policies regarding such items as password strength or music-download software/spyware. But has the administrator done the same for the employees' home computers? More often than not, the answer is "no." This creates a problem when the employee's children (or the employee) are running games, downloading software and opening email with the subject "congratulations, you're a winner."

A financial company can implement security and save dollars, dollars and more dollars of lost revenue due to security compromises by insisting that the home employee, including the CEO and other executives, follow some simple rules:

  • Antivirus (AV) software: Insist that the user maintain the latest version of AV software and keep the definitions up to date. Ask the user to provide the make/version of the software for you. If it doesn't match the corporate standard, purchase it for that employee. At only $25-$50 per installation, it's petty cash for insurance.


  • Firewall: While it would be wonderful for each employee to own a hardware-based, stateful-packet inspection firewall, it can be a costly solution. Instead, purchase a trusted software-based system.


  • VPN: Does the user connect by VPN? Whether it's a hardware-based tool or a Microsoft Windows-based tool, instruct the user how to configure it so that it becomes the default gateway to the Internet. This will protect the corporate LAN from being accessed by an Internet "guest" through the user's computer while the user is connected to the VPN.


  • Technical assistance: If practical, inspect the home computer for all required software, security patches and settings as if it were a computer that you had built at the office. That way you can "sign off" on it as a secure system.


  • Guidelines: Finally, knowledge, knowledge and more knowledge. Provide guidelines and make the employee an informed one through acceptable use policies. Ask the employee to sign a document stating that he understands the risks of remote access. A hand-written signature goes a long way to cultivating a level of responsibility from the employee once he knows the consequences of inaction.

Bradley Dinerman is an MCSE in Windows NT and 2000 and a Certified SonicWall Security Administrator (CISSA). He is the founder and chair of the New England Information Security User Group and is a founding director of Boston User Groups, Inc. Brad is the vice president of information technology at MIS Alliance in Newton, Mass., and holds a Ph.D. in physics to help him determine how long it will take his monitor to be launched across the local highway.


Rate this Tip
To rate tips, you must be a member of SearchFinancialSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Security Architecture Insider
Multifactor authentication options to secure online banking
Security benefits of virtual desktop infrastructures
How to secure data backup
Too many encryption methods make secure communications difficult
How to streamline role-based access control
Five considerations for choosing network access control products
Fighting fraud: Understanding technology and threats
How to shift to centralized authentication and ease compliance
Winning the war: Personal information protection
Why financials must implement Web application security best practices

VPNs and secure remote access for financial institutions
Security benefits of virtual desktop infrastructures
Integrating firewalls into your financial enterprise systems
Top NAC challenges include cost, interoperability issues
New remote access system cuts costs
Disaster recovery, security drive financial firm to Private IP
SSL VPN use is all about security
How remote access control products affect Windows file permissions

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Finance Sector Security - Anti-Phishing, Remote Access Security, Firewall Systems
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts