36 MAC Pt. 1, R. 4.2

Remote Access Management

Year: 2026Length: 800 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 4.2

Remote Access Management A. Each agency must terminate all VPNs in the Enterprise VPN Solution managed by ITS. 1. Agencies can request an exception to this requirement for the following: i. Terminating one or more VPNs using another method other than the Enterprise VPN Solution. ii. Accessing a Virtual Desktop Infrastructure from the Internet without a VPN. 2. Agencies are required to provide documentation that justifies that the exception is required for meeting applicable security compliance requirements. 3. In any case where ITS approves an exception, the exception only applies to a singular VPN, unless otherwise specified, and said VPN must be built to meet or exceed all controls specified within the Enterprise Security Policy. B. All connections from any entities (state or third party) that reside on the outside of the Enterprise State Network must be made via a virtual private network (VPN) connection (using industry-standard IPSec or SSL protocols) or via a third-party circuit that terminates at the ITS data centers in a DMZ on the Enterprise Perimeter Firewall. 1. Determine amount of access to enterprise resources based on: up-to-date anti- malware software installed, configuration compliance with the agency’s secure configuration process, and ensuring the operating system and applications are up-to-date. 2. Require multi-factor authentication for remote network access. 3. Require users to authenticate to enterprise-managed VPN and authentication services prior to accessing enterprise resources on end-user devices. C. All connections from any entities (state or third party) that reside on the outside of the state network must be made via a virtual private network (VPN) connection using industry-standard IPSec or SSL protocols. D. VPNs may be client-based or LAN-to-LAN based. 1. Client-based VPNs are VPNs in which software (client) is installed on a remote user’s computer and a secure connection is made between that VPN client and a VPN-capable terminating device (i.e. VPN concentrator, firewall, router, server). i. All client-based VPNs must require multi-factor authentication. 2. LAN-to-LAN VPNs are VPNs that are created between a VPN-capable device on a third-party network and a VPN-capable device on the state network. E. For client-based VPNs, split-tunneling must be disabled on any device (firewall, VPN Concentrator, etc.) used to terminate VPNs inside the state network. 1. Split tunneling is defined as having the ability to participate in a LAN while connected to the state Network via VPN. To meet the requirement of disabling split tunneling, it is required that all network activity for the client PC be redirected down the tunnel. Both listening services and browsing services must be redirected to the VPN so that no LAN activity can take place, regardless of whether it is initiated by the client PC or by another device on the LAN. 2. Any device (including SSL VPN appliances) that cannot fully disable split tunneling as it is defined above does not meet the requirements or intent of this security policy. F. All remote access across any network, internal or external to the agency environment, must employ cryptographic mechanisms to protect sensitive data. G. For both client-based and LAN-to-LAN VPNs, tunnels must be limited with access- restrictions that are granular enough to restrict all inbound traffic to both IP addresses and specific TCP/UDP ports. The list of addresses and ports allowed must only include what is necessary for the applications used by the remote users. H. Authorization for remote execution of privileged commands and remote access to security-relevant information must be limited to agency-defined needs. A privileged command is a human-initiated (interactively or via a process operating on behalf of the human) command executed on a system involving the control, monitoring, or administration of the system including security functions and associated security- relevant information. Security-relevant information is any information within the system that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce the system security policy or maintain isolation of code and data. 1. To understand and comply with this requirement, each agency should: i. Identify privileged commands (or activity) authorized for remote execution. ii. Identify security-relevant information that can be accessed remotely. iii. With these identified, it is recommended that firewall rules governing remote access be used to enforce these restrictions. Further, users with privileged access should be trained and aware of this policy. I. All remote access to the Enterprise State Network must be revoked immediately upon the retirement, resignation, dismissal, end of contract, or all other actions that signal that the requirements for having a connection are no longer valid. J. At no time should any employee, vendor or account holder provide their remote access credentials (user information or password) to anyone. Employees, vendors, or account holders must be assigned individual accounts. K. All remote access (VPN and other remote access types) must require multi-factor authentication.
36 MAC Pt. 1, R. 4.2: Remote Access Management | Justis AI