Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > Can home PCs provide a way for viruses and spyware to enter a corporate LAN?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Can home PCs provide a way for viruses and spyware to enter a corporate LAN?

Joel Dubin EXPERT RESPONSE FROM: Joel Dubin

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 13 June 2008
Our enterprise is considering the use of remote access control software to allow employees to access their corporate PCs from their home PCs. Because home PCs are untrusted and we have no control over them, does this give a route into the corporate LAN for any viruses or spyware that may be on that home computer?

>
EXPERT RESPONSE
By all means, any unprotected home PC with access to a network represents a potential threat to your security.

Why? Well, unlike desktops inside the company, there is no control over an employee's home PC. There is probably -- or should be -- protection for desktops and workstations in the office: antivirus software, host-based firewalls, antispyware protection and more, depending on the organization's risk profile. A home PC might not have the same controls that meet the company's internal IT security standards.

To make matters worse, if the employees are using VPN software on their home PCs to access the network, ironically, they're creating a secure connection for malware to access the network. The malware is just as protected from malicious access as is the legitimate data being sent over the wire.

The protection of the network from insecure home PCs is a whole field in itself called network access control (NAC) and endpoint security, which is beyond the scope of this brief discussion. Suffice it to say that NAC involves software controls on endpoints, monitoring systems on networks and blocking insecure devices from networks, like home PCs. NAC involves both software and hardware controls and is more of a process than a single product that does it all.

Ideally, a NAC system should not only scan and check for any devices trying to connect to the network, but it should also check them to make sure they have the adequate security controls to meet IT security standards. For example, if the device doesn't have updated antivirus software or the latest operating system patches, an endpoint security solution would either block the device from the network or download the patches and updates before allowing access.

Home PCs are only one endpoint security headache for security administrators. Many employees nowadays work remotely with laptops, BlackBerrys and other PDAs, all of which need to be secured and given proper access controls before being allowed to connect to the network. Just add home PCs to the list of devices that would need to be secured in an endpoint security program.

The best idea, if practical for your company, is only to allow access to the network with company-provided equipment. Such equipment should have a standard build, uniform throughout the enterprise, and should have company-mandated controls meeting specific IT security standards. Again, if practical and within budget, it's better to avoid use of home computers for business use and instead issue remote employees laptops. Anything less may mean gambling with the security of the entire organization.

More information:


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Identity Management and Access Control
What are the options for a mechanical (not electrical) door security system on a server room door?
What's the difference between access control mechanisms and identity management techniques?
What courses can improve fundamental knowledge of infrastructure systems (Active Directory, LDAP, etc.)?
What tools provide user provisioning and single sign-on for PeopleSoft- and Unix-based products?
Should a new user have to confirm his or her email address before gaining access?
What should an enterprise look for in a password token, and in a vendor?
Is it possible to write a batch file that allows user access to the local admin group for a short time?
IAM best practices for employees with varying degrees of access to the same computer
What are some good pre-boot biometric user authentication tools or strategies?
If the encryption on the Mifare Classic RFID has been cracked, are smart cards insecure?

Network Access Control
What are the security risks of opening all the ports on an internal router?
Should an ISP keep corrupted machines off of a network?
As hype subsides, NAC moves ahead
NAC's future
Product review: Novell's ZENworks Endpoint Security Management 3.5
NAC growth sluggish as companies consider network security options
Should void user IDs be preserved in an audit history?
Endpoint Security
Emerging Technologies
Recent Releases

Creating a Security Culture
IT security pros focus on internal threats during tough economy
Security policy being bypassed by employees, survey finds
IT security pros face challenge during economic crisis
What are some tips on protecting my security budget in a tight economy?
How to get information security buy-in from the executive team
Which is the biggest threat to data: Insider activity or outsider activity?
Sound compliance policies, practices reduce legal costs
Unified communications trigger data leakage dangers, survey finds
What are the top five concepts or lessons on security management?
Security Awareness Training Essential Part of Infosec Program

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Honeynet Project  (SearchSecurity.com)
single-factor authentication (SFA)  (SearchSecurity.com)
trusted computing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
Targeted Security Channel Tips for Resellers, Integrators and Consultants
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts