Variety of tools from Citrix, Symantec, McAfee, Oakley, Absolute Software and others bolster remote security
With roughly 250,000 residents, Virginia’s Arlington County is one of the smallest in the country. The county government prides itself on creating a supportive, family atmosphere for its 3,500 employees, a few hundred of which work remotely. But when it comes to cyberthreats, Chief Information Security Officer David Jordan lays down some strict house rules.
With roughly 250,000 residents, Virginia’s Arlington County is one of the smallest in the country. The county government prides itself on creating a supportive, family atmosphere for its 3,500 employees, a few hundred of which work remotely. But when it comes to cyberthreats, Chief Information Security Officer David Jordan lays down some strict house rules.
“We work really hard to educate our employees . . . to make them feel responsible about the cybersecurity piece of their job,” says Jordan, whether those employees work in a government office, telecommute, or are out in the field issuing permits or inspecting fire codes with their laptop in hand. Jordan personally meets with every new hire during the training process to make individuals aware of Internet threats and the county’s security policies, outlining rules about Web and e-mail usage. Ongoing awareness-raising includes initiatives such as contributions from the IT department to the weekly employee newsletters about the latest e-mail scam or fraudulent Web site.
But when it comes to securing remote employees, it takes more than awareness. The county has layered a number of technologies in order to secure the endpoints, installing Symantec’s Client Security on government-issued computers that offers virus, spyware, and intrusion protection as well as personal firewall features. The computers are physically protected by Absolute Software’s Computrace – “the LoJack of computer hardware” says Jordan, which lets the county trace the location of a computer. In addition, the county secures network access with firewalls and uses SSL for authentication.
While Jordan believes these technologies combined create “a robust remote extension facility,” there’s more to be done, such as adding layers of protection to the information stored in the county’s databases. Such is the case with most organizations trying to secure their remote workers –there’s always room for improvement.
“A lot of organizations still believe that a security strategy is antivirus, and that simply doesn’t work anymore,” says Natalie Lambert, senior analyst at Forrester Research.
“Now attacks are nefarious, extracting corporate information, and there’s a lot of organized crime and going after competitors . . . attacks these days are very targeted.”
Forrester recommends some basic elements for remote PCs to make them “well managed, well secured,” says Lambert. The list includes client management software so that the central IT department can keep control over what’s being installed and executed on remote PCs, as well as basic client security suites with antimalware, personal firewall, and intrusion detection/prevention software. She also suggests full-disk encryption for PCs that travel, so if a laptop containing personal customer or employee information is stolen the company will not be liable should it be taken to court.
One method of giving remote workers a secure, and relatively simple, way to work that’s been gaining popularity is via a terminal server, says Lambert, where remote employees log on to a server and have all their applications and data at hand but don’t cross the network. In this scenario, where all the applications run on data center computers, the aforementioned remote client security software isn’t needed, she says. But once a Web browser is added to that remote PC it becomes vulnerable to Internet threats and needs to be secured like any other computer, Lambert says.
The terminal approach allows for a scenario where the IT department cannot control the endpoints – for example, severe weather prevents workers from getting to the office but employees still want to get work done from their home PCs, says Tom Simmons, vice president of government systems for terminal server maker Citrix. “The concept becomes `Let me secure the application and data, and provide strong authentication requirements depending on the scenario’. . . then it becomes an Internet-generation approach to the problem,” he says.
This approach works well for remote users with limited tasks, such as call-center employees, says Martin Carmichael, CSO of McAfee. But for knowledge workers whose needs change, and with them their applications and access levels, a fully functional remote PC is required, he says.
Carmichael advocates, and McAfee sells, client security software such as the packages recommended by Forrester, but also adds data-leak prevention technology to the list of security requirements. This relatively new category of technology is designed to ensure sensitive corporate data is not being printed out, e-mailed or saved to removable media without the proper authorization, even on remote endpoints, he says.
“The remote user has the ability to transmit information to devices and networks, so you need the technology to eliminate that concern,” says Carmichael. McAfee earlier this month announced its first product in this category.
Simply installing data-loss prevention products at the gateway or network level isn’t enough, echoes Ken Davis, vice president of product development with Oakley Networks, another player in this market. “When it comes to dealing with endpoint workers, you have to start thinking in terms of deploying agent software” on the remote computer, he says. However, Davis admits many IT managers equate agent software with extra work in installing and maintaining those programs.
“But there’s so much damage that can be done when you start to let anyone connect to your network” that installing agents is a small price to pay, he says.
Forrester’s Lambert agrees that data-loss prevention software heightens the security of a remote PC, adding that the software should not only be able to detect when sensitive information is being used incorrectly but also block the action from happening.
But the most important element of remote security is to arm PCs that stay inside corporate offices with the same protection loaded onto remote PCs, she says.
Remote workers pose a threat to office workers because if a remote worker’s notebook becomes infected, should that worker come into the office and plug into the network, perimeter security technology won’t protect all the other workers connected to the LAN, Lambert explains.
“In an ideal world, put all precautions on all machines,” she says.




