Windows – MSTSC RDP over the public internet

internetmstscrdpSecuritywindows

My first question so please be gentle 🙂

I have a client who is insisting that they have to let their third party vendor support access to there server directly from the internet via RDP.

Our policy does not allow direct access to the infrastructure from outside of the data centre for administration except from an approved VPN connection and then virtual desktop there on to the servers.

I am now in the situation where I must give good reasons why it is dangerous to use RDP over the public internet.

any help would be appreciated

Thanks in advance

Stuart

Best Answer

Don't forget that an intruder that compromises that server could also use it as a springboard to attack other customers' facilities behind the firewall. Thus, security risk is not solely confined to the first customer's assets.

Get some justification from the vendor as to why they can't use the VPN. If there is genuinely no alternative to RDP connection direct to the server then they need to take responsibility for any security breaches through that connection. Bear in mind that the vendor has just admitted to security flaws in their application architecture by stating that there is something about the application that precludes the use of the VPN.

Make the access conditional on their signing an agreement indemnifying you against any damage caused by a security breach through the RDP connection. In addition you should require them to obtain suitable professional indemnity or liability cover or provide proof of existing cover with terms that would cover this situation.

In short, make the vendor prove that they can afford to pay for any damages and make their access conditional on a contractual obligation to do so.

Related Topic