Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > Can home PCs provide a way for viruses and spyware to enter a corporate LAN?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Can home PCs provide a way for viruses and spyware to enter a corporate LAN?

Joel Dubin, past SearchSecurity.com expert EXPERT RESPONSE FROM: Joel Dubin, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 13 June 2008
Our enterprise is considering the use of remote access control software to allow employees to access their corporate PCs from their home PCs. Because home PCs are untrusted and we have no control over them, does this give a route into the corporate LAN for any viruses or spyware that may be on that home computer?

>
By all means, any unprotected home PC with access to a network represents a potential threat to your security.

Why? Well, unlike desktops inside the company, there is no control over an employee's home PC. There is probably -- or should be -- protection for desktops and workstations in the office: antivirus software, host-based firewalls, antispyware protection and more, depending on the organization's risk profile. A home PC might not have the same controls that meet the company's internal IT security standards.

To make matters worse, if the employees are using VPN software on their home PCs to access the network, ironically, they're creating a secure connection for malware to access the network. The malware is just as protected from malicious access as is the legitimate data being sent over the wire.

The protection of the network from insecure home PCs is a whole field in itself called network access control (NAC) and endpoint security, which is beyond the scope of this brief discussion. Suffice it to say that NAC involves software controls on endpoints, monitoring systems on networks and blocking insecure devices from networks, like home PCs. NAC involves both software and hardware controls and is more of a process than a single product that does it all.

Ideally, a NAC system should not only scan and check for any devices trying to connect to the network, but it should also check them to make sure they have the adequate security controls to meet IT security standards. For example, if the device doesn't have updated antivirus software or the latest operating system patches, an endpoint security solution would either block the device from the network or download the patches and updates before allowing access.

Home PCs are only one endpoint security headache for security administrators. Many employees nowadays work remotely with laptops, BlackBerrys and other PDAs, all of which need to be secured and given proper access controls before being allowed to connect to the network. Just add home PCs to the list of devices that would need to be secured in an endpoint security program.

The best idea, if practical for your company, is only to allow access to the network with company-provided equipment. Such equipment should have a standard build, uniform throughout the enterprise, and should have company-mandated controls meeting specific IT security standards. Again, if practical and within budget, it's better to avoid use of home computers for business use and instead issue remote employees laptops. Anything less may mean gambling with the security of the entire organization.

More information:


BROWSE BY TAG
Identity Management and Access Control,   Security Awareness Training and Internal Threats,   Information Security Management,   NAC and Endpoint Security Management,   Enterprise Network Security,   Client security,   Secure Remote Access,   Expert Archive: Identity Management and Access Control,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Identity Management and Access Control
Is Identity Management as a Service (IDaaS) a good idea?
How to log in to multiple servers with federated single sign-on (SSO)
How to confirm the receipt of an email with security protocols
Learn about enterprise strategy for server virtualization single sign-on
Employee information security awareness training for new IAM systems
Can you combine RFID tag technology with GPS to track stolen goods?
Is there a free enterprise-caliber password-management tool?
Cryptosystem attacks that do not involve obtaining the decryption key
Can any firm or organization get a digital signature certificate?
Should the CTO have domain administrator access?

Security Awareness Training and Internal Threats
Health Net healthcare data breach affects1.5 million
Massive T-Mobile UK security breach involves insiders
Secure your remote users in 2010
Layoffs prompt insider threat fears, cybersecurity survey finds
How to use Internet security threat reports
Creating a HIPAA employee training program
Successful rogue antivirus hinges on social engineering
External attacks start with unintentional mistakes, survey finds
Security technologies fail to address insider threat management
Data breach avoidance begins with security basics, panel says

Client security
InZero Systems launches hardware-based security gateway
DLP technology challenges security costs
Endpoint protection best practices manual: Combating issues, problems
Kaspersky update for SMBs in wake of free Microsoft Security Essentials
Microsoft makes free antivirus software widely available
Security best practices in hotels
Best Antimalware Products
Perimeter defense in the era of the perimeterless network
Microsoft Security Essentials (MSE) shows no vision, expert says
Smart tactics for antivirus and antispyware

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
dumpster diving  (SearchSecurity.com)
Honeynet Project  (SearchSecurity.com)
insider threat  (SearchSecurity.com)
National Computer Security Center  (SearchSecurity.com)
pretexting  (SearchCIO.com)
shoulder surfing  (SearchSecurity.com)
single-factor authentication (SFA)  (SearchSecurity.com)
social engineering  (SearchSecurity.com)
Total Information Awareness  (SearchSecurity.com)
trusted computing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts