36 MAC Pt. 1, R. 4.2
Remote Access Management
Cite as 36 Miss. Admin. Code Pt. 1, R. 4.2
Remote Access Management
A. Each agency must terminate all VPNs in the Enterprise VPN Solution managed by
ITS.
1. Agencies can request an exception to this requirement for the following:
i. Terminating one or more VPNs using another method other than the
Enterprise VPN Solution.
ii. Accessing a Virtual Desktop Infrastructure from the Internet without a
VPN.
2. Agencies are required to provide documentation that justifies that the
exception is required for meeting applicable security compliance
requirements.
3. In any case where ITS approves an exception, the exception only applies to a
singular VPN, unless otherwise specified, and said VPN must be built to meet
or exceed all controls specified within the Enterprise Security Policy.
B. All connections from any entities (state or third party) that reside on the outside of the
Enterprise State Network must be made via a virtual private network (VPN)
connection (using industry-standard IPSec or SSL protocols) or via a third-party
circuit that terminates at the ITS data centers in a DMZ on the Enterprise Perimeter
Firewall.
1. Determine amount of access to enterprise resources based on: up-to-date anti-
malware software installed, configuration compliance with the agency’s
secure configuration process, and ensuring the operating system and
applications are up-to-date.
2. Require multi-factor authentication for remote network access.
3. Require users to authenticate to enterprise-managed VPN and authentication
services prior to accessing enterprise resources on end-user devices.
C. All connections from any entities (state or third party) that reside on the outside of the
state network must be made via a virtual private network (VPN) connection using
industry-standard IPSec or SSL protocols.
D. VPNs may be client-based or LAN-to-LAN based.
1. Client-based VPNs are VPNs in which software (client) is installed on a
remote user’s computer and a secure connection is made between that VPN
client and a VPN-capable terminating device (i.e. VPN concentrator, firewall,
router, server).
i. All client-based VPNs must require multi-factor authentication.
2. LAN-to-LAN VPNs are VPNs that are created between a VPN-capable device
on a third-party network and a VPN-capable device on the state network.
E. For client-based VPNs, split-tunneling must be disabled on any device (firewall, VPN
Concentrator, etc.) used to terminate VPNs inside the state network.
1. Split tunneling is defined as having the ability to participate in a LAN while
connected to the state Network via VPN. To meet the requirement of disabling
split tunneling, it is required that all network activity for the client PC be
redirected down the tunnel. Both listening services and browsing services
must be redirected to the VPN so that no LAN activity can take place,
regardless of whether it is initiated by the client PC or by another device on
the LAN.
2. Any device (including SSL VPN appliances) that cannot fully disable split
tunneling as it is defined above does not meet the requirements or intent of
this security policy.
F. All remote access across any network, internal or external to the agency environment,
must employ cryptographic mechanisms to protect sensitive data.
G. For both client-based and LAN-to-LAN VPNs, tunnels must be limited with access-
restrictions that are granular enough to restrict all inbound traffic to both IP addresses
and specific TCP/UDP ports. The list of addresses and ports allowed must only
include what is necessary for the applications used by the remote users.
H. Authorization for remote execution of privileged commands and remote access to
security-relevant information must be limited to agency-defined needs. A privileged
command is a human-initiated (interactively or via a process operating on behalf of
the human) command executed on a system involving the control, monitoring, or
administration of the system including security functions and associated security-
relevant information. Security-relevant information is any information within the
system that can potentially impact the operation of security functions or the provision
of security services in a manner that could result in failure to enforce the system
security policy or maintain isolation of code and data.
1. To understand and comply with this requirement, each agency should:
i. Identify privileged commands (or activity) authorized for remote
execution.
ii. Identify security-relevant information that can be accessed remotely.
iii. With these identified, it is recommended that firewall rules governing
remote access be used to enforce these restrictions. Further, users with
privileged access should be trained and aware of this policy.
I. All remote access to the Enterprise State Network must be revoked immediately upon
the retirement, resignation, dismissal, end of contract, or all other actions that signal
that the requirements for having a connection are no longer valid.
J. At no time should any employee, vendor or account holder provide their remote
access credentials (user information or password) to anyone. Employees, vendors, or
account holders must be assigned individual accounts.
K. All remote access (VPN and other remote access types) must require multi-factor
authentication.