Zero Trust Security needs around Remote Access
As the whole world has been taken over by COVID-19 pandemic, and the recovery is still far insight, remote access to applications and data has become the new normal for employees of every company.
The security needs around enabling remote access to enterprise application needs is a primary topic that of interest to me these days.
This brings the focus around addressing these questions.
- How to enable Remote Access to employees, partners, and contractors securely?
- How to keep the IT cost low and productivity high without having to invest in additional desktops and mobile devices? Can we allow users to use their personal/BYOD?
- How do we make sure the devices and endpoints are safe, and they meet the IT compliance needs, so they are no data breach and security attacks on enterprise assets?
These questions are not new when it comes to application security, even though these are the main drivers for a digital workplace, which is the new buzz word for digital transformation at every enterprise. Though the adoption of digital workplace benefits includes increased employee productivity, reduces overall cost reductions, and improves employee trust, the concepts around zero-trust security have remained the same. The evolution around Zero trust security is to take more and more attributes around the identity and the endpoints to defend, secure, and protect applications and the enterprise data on your network.
Digital workspace is a rapidly evolving market and is the green field that enterprises are experimenting with zero-trust security. This market expected to grow $54.2Billion by 2027, with a CAGR of 11.3%.
As I understand, digital workspace is an integrated technology framework that centralizes the management of the enterprise’s applications, data, and endpoints, allowing users to collaborate and work remotely. It also provides users with the self-service, out-of-the-box experiences that can scale across platforms, locations, and devices, allowing them to work in a digital environment. Adopting a Bring Your Own Devices (BYOD) strategy can help drive the adoption of the digital workplace faster since around the globe, users, on average own at least two personal devices on their own, which they use regularly. Building a bridge between BYOD and Digital workspace is the future.
The topic I want to focus on is zero-trust security needs around Remote Access and the best practices around users and endpoints.
Providing Business Agility
One of the vital business aspects of remote access in a digital workplace environment is providing business agility and continuity for users to operate from any device and get access to their applications and data. This would require that the requirements around Remote Access and security are met so your traffic is protected and data breaches are prevented, so the remote access is efficient.
Here are the best practices to follow around the Zero Trust Security requirements for Remote Access.
They fall into these four main categories.
1. Endpoint protection
Remote Access users are typically provided with a managed desktops or can use an unmanaged BYOD to access company apps or data. This would require that the security posture of these devices be validated to ensure that the endpoint meets all the device trust criteria before they are allowed into the network.
Requires these endpoints are validated to prevent data breaches and are kept monitored to keep track of what these device endpoints are doing so the network stays safe at all times.
2. Authentication
Users from managed devices or an unmanaged BYOD have to be authenticated to identify who the user is before they are allowed into the enterprise network. Depending on the device’s security posture, the context or behavior attributes of the user, multi-factor authentication, and encryption for the endpoint should also be enforced.
Identity and access management solution here is what can help address the needs around identity provisioning and authentication needs around devices and users.
3. Vulnerability Assessment
Enforcing a systematic vulnerability assessment for the security weaknesses to satisfy the compliance needs around a managed device or a BYOD will help to assess the threats and keep the risks to the data and the information systems under control. It evaluates if the endpoint devices and the users are susceptible to any known vulnerabilities, assigns severity levels to those vulnerabilities, and recommends remediation or mitigation, if and whenever needed.
Taking steps to do continuous monitoring of the endpoints to meet the device compliance rules, assessing the risks around user’s behaviors, and session through continuous verification will keep the remediation and mitigation efforts to a minimum at all times.
4. Access Management
Access Management is the process that controls and monitors who gets access to what at all times. Typically enforced through a policy framework around a BYOD that allows policy definitions against, type of devices, type of users with additional user criteria like the user context and behaviors, types of applications, type of data, and more. The fine-grained the policy controls are the fine-grained remote access management can be enforced around the apps and resources that a typical remote user would want to access through his BYOD in a digital workplace.
In conclusion, the COVID-19 pandemic has caused rapid and significant changes in how employees adapt to remote access. There is a shift in enterprise security needs to support remote access to applications and data. This requires the adoption of new technologies that can apply the security controls and do a better analysis of the threats faster and accurately to avoid data breaches.
I recently came across an IDC global survey on how COVID-19 impact on the IT strategy. Here are the four main takeaways that are worth noting, which strengthens the case for a strong Zero Trust security strategy to support business agility.
| # | Takeaways | Worldwide | North America |
| 1 | Encourage working from home and support remote work | 40% | 47% |
| 2 | Support for Mobile devices and applications | 39% | 37% |
| 3 | Make changes to IT security strategy and systems. | 36% | 39% |
| 4 | Move data and applications to the cloud aggressively. | 35% | 34% |
Remote access to employees is here to stay, and it’s proven that productivity has not diminished as more and more employees are working from home.
Facilitating the ability for employees to have the same user experience, whether they are using company-provided devices or a BYOD, has to stay the same without compromising enterprise security.
The bottom line is as enterprises embrace and enable a Digital workspace environment for their remote workers, they need a better and reliable security strategy, so there is no compromise on security and risks.
Posted on August 10, 2020, in Blog. Bookmark the permalink. Leave a comment.

Leave a comment
Comments 0