by Steve Taylor and Joanie Wexler

Do you have a security policy for telecommuters?

Opinion
Jul 22, 20032 mins

* Security risks for at-home workers

Much ado is made about network and computer security, as well it should be. However, any security expert will tell you that safeguarding your data has at least as much to do with people, policy and physical security measures as it does with technology.

Which brings us to the issue of the growing population of teleworkers. There are, of course, many advantages to setting up at-home workers. These benefits include lower real-estate costs for employers and, according to a number of studies, higher productivity on the part of knowledge workers. But there are also some potential security tradeoffs if you don’t have appropriate policies and user education in place.

For example, consider the case of a contractor we recently interviewed. This fellow was working from a home office and had his VPN connection to one of his clients open. The beauty of a VPN – like its vulnerability – is that you can function as if you were local to all the IT resources.

In this case, the fellow had his printer selected for printing locally at the client’s office – a setting left over from the last time he was working on site. The next thing he knew, he was printing from his home office over the VPN at this client site. Trouble was, this contractor had multiple clients, and the material he was printing was confidential – to another client.

This instance is almost the opposite of what you’d traditionally think of as a breach: sending confidential data into the wrong network, rather than extracting it from a network. And this is just one of a few issues to consider when setting policies and rules for at-home user network connections: that a user must disable a VPN connection under certain work circumstances, which you should make very explicit.

We’ll look at a couple more teleworking vulnerabilities next time.