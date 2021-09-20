Weigh the pros and cons of technologies, products and projects you are considering.

Secure remote access is one of the most critical aspects of networking and security today -- even more so because of the COVID-19 pandemic, which forced employers to expand and fortify their remote work capabilities. Companies need to provide employees and business partners remote access to resources, such as applications and data, without compromising security. In this guide, we examine how businesses should rethink key aspects of their secure remote access strategies, set policies accordingly and get to know the entirety of the secure remote access ecosystem.

What is secure remote access? What it means to provide secure remote access has changed considerably in the past few years as a result of new technologies and the pandemic. At its most basic, secure remote access is having location-agnostic connectivity among enterprise users and centralized applications, resources and systems, whether cloud-based or on premises. The following technologies can contribute to secure remote access: VPNs;

intrusion prevention systems/intrusion detection systems;

Secure Access Service Edge (SASE)/software-defined perimeter;

firewalls;

cloud access security brokers;

zero-trust network access;

virtual desktop infrastructure; and

identity and access management (IAM). Some of these technologies are explained in deeper detail below.

Who is responsible for secure remote access? Although remote access tools such as VPNs and firewalls are typically under the purview of network teams, in this new era, cybersecurity teams tend to lead and manage the policies, processes and technologies associated with ensuring secure remote access. Cybersecurity teams assess and mitigate the risks of remote access, including the following: password sharing;

software that violates an organization's security standards;

unencrypted personal devices and lack of cyber hygiene; and

minimal to no patching. Their responsibilities involve combating the top cybersecurity risks by strengthening and measuring the effectiveness of access controls, monitoring and managing remote access activities, keeping remote access rules current and testing remote access operations.

The diminishing power of VPNs One tactic organizations use to combat the vulnerabilities associated with working remotely -- especially if employees are using consumer-grade systems -- is to reestablish VPN standards. This entails enforcing basic protections such as strong passwords, multifactor authentication, role-based access and encryption. That said, many experts believe VPNs have not scaled well to meet the accelerated needs of secure remote access for a hybrid workforce. As a result, VPNs will likely be replaced with more nimble technology over time.

Setting secure remote access policies A hallmark of secure remote access is the underlying policy that safeguards access to and the use of enterprise resources, such as data, databases, systems and networks. Cybersecurity expert Paul Kirvan recommended defining the following procedures and processes, among others: criteria for granting employees remote access;

technologies used for remote access and minimally required security features;

types of IT resources to be remotely accessed;

network resources needed for remote access;

IT employees charged with executing remote access security activities;

emergency procedures in case of remote access security compromise; and

integration of remote access security with other data protection activities. Remote access security policy template This free, editable remote access security policy template provides suggested wording for the policy and identifies areas to be completed by the policy author(s). The template can be modified in any way your policy development team sees fit.







