Restrictions on Telework Client Devices and Remote Access Levels

1 - I can do better 2 - Jury's out 3 - Pretty darn good 4 - Splendiferous 5 - Awesometastic by 0 people | Log in to rate

Ranked #19,878 in Tech & Geek, #389,623 overall

Restrictions on Telework Client Devices and Remote Access Levels

A telework security policy can limit the types of client devices that teleworkers are allowed to use. For a variety of reasons, including security policies and technology limitations, organizations often limit which types of devices can be used for remote access.

For example, an organization might permit only organization-owned PCs to be used. Some organizations have tiered levels of access, such as allowing organization-owned PCs to access many resources, teleworker-owned PCs to access a limited set of resources, and consumer devices and third-party PCs to access only one or two resources, such as Web-based email.

This allows an organization to limit the risk it incurs by permitting the most-controlled devices to have the most access and the least-controlled devices to have minimal access.

 

Each organization should make its own risk-based decisions about what levels of remote access should be permitted from which types of devices. Factors that organizations should consider when setting telework security policy for this include the following:

Sensitivity of telework 

Some telework involves access to sensitive information or resources, while other telework does not.

Organizations may have more restrictive requirements for telework involving sensitive information, such as permitting only organization-controlled telework devices to be used.

The level of confidence in security policy compliance 

Meeting many of an organization's security requirements can typically be ensured only if the organization controls the configuration of the telework devices.

For personally owned devices, some requirements can be verified by automated security health checks conducted by the remote access server on devices attempting to connect, but other requirements cannot be verified by the organization by automated means.

Making users aware of their responsibilities can help to improve security on personally owned telework devices, but will not result in the same degree of security policy compliance as mandatory security controls enforced on organization-controlled telework devices.

Even the most conscientious users may fail to properly maintain the security of their personally owned devices at all times because of the technical complexity or effort involved or their lack of awareness of new threats.

Internet Security Suites 

McAfee Total Protection 3 User 2010

Amazon Price: $56.49 (as of 12/08/2009) Buy Now

Kaspersky Internet Security 7.0 3-user [OLD VERSION]

Amazon Price: $33.97 (as of 12/08/2009) Buy Now

Anti Virus Firewall Antispam F/Mac & Pc W/Virtualization Sw

Amazon Price: $81.24 (as of 12/08/2009) Buy Now

Cost 

Costs associated with telework devices will vary based on policy decisions. The primary direct cost is issuing telework devices and client software to teleworkers.

There are also indirect costs in maintaining telework devices and in providing technical support for teleworkers.

Another consideration related to cost is telework frequency and duration; an organization might justify purchasing telework devices for individuals who telework regularly (e.g., one day per week from home, frequent business travel), but not purchasing telework devices for individuals who telework only occasionally for short durations, such as quickly checking email from home a few evenings a month.

Telework location 

Risks will generally be higher for devices used in a variety of locations than in just a home environment. Also, in some cases the organization can determine the teleworker's location (i.e., identify whether the device is on an authorized home network), in which case policies could be enforced based on location.

Technical limitations 

Certain types of devices may be needed for particular telework needs, such as running specialized programs locally.

Also, if an organization has a single type of remote access server, and that server can only allow connections through a custom client that is installed on the telework device, then only the types of devices that can support the client are allowed.

Remote Access Software 

Pcanywhere Host and Remote 12.5 1 User CD Ret

Amazon Price: $134.95 (as of 12/08/2009) Buy Now

Media Pk Pcanywhere Host and Remote 12.5 Device

Amazon Price: $25.49 (as of 12/08/2009) Buy Now

Apple Remote Access Personal Server 3.0

Amazon Price: (as of 12/08/2009) Buy Now

Compliance with mandates and other policies 

Organizations may need to comply with telework-related requirements from mandates and other sources, such as a Federal department issuing policy requirements to its member agencies. An example of a possible requirement is restrictions on performing telework in certain foreign countries.

by PentAngeli

Hello, I am BCM, I have been a writer and blogger online for many years.

My main areas of expertise are automation,computers and renewable energy.... (more)

Explore related pages

Create a Lens!