Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > For a small office, what are the best, least expensive office servers with secure access?
Ask The Security Expert: Questions & Answers
EMAIL THIS

For a small office, what are the best, least expensive office servers with secure access?

Joel Dubin EXPERT RESPONSE FROM: Joel Dubin

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 21 January 2008
We are a small office where eight people with laptops need secure access to the office server. Any recommendations for how we might do this? I know there are different product types and associated costs, but given that we have limited resources and finances to put toward this project, what would you recommend?

>
EXPERT RESPONSE
There are two levels of security corporations need to consider for laptops, regardless of the size of an organization. These are both virtual and physical.

Even small organizations should have some sort of encrypted connection between laptops and the office server. Ideally, this would be some sort of VPN connection, either IPsec or SSL. Since you only have eight users -- a small network indeed -- even these traditional VPN products might be too costly and involved.

Even a simple IPsec network from Cisco Systems Inc., for example, would have to run through a dedicated server or router, which might be more than a company can spare. Even though SSL VPNs, like Citrix, are Web-based and require only a browser to access the network, there's still some overhead in configuring them on a network. Products like those from vendors Aventail and Juniper Networks Inc. will require the installation of additional hardware on a small network.

But there's still hope for the small user. One alternative is GoToMyPC, an online-based SSL VPN using Citrix technology. Another similar service, LogMeIn, uses a laptop's existing firewall and requires little additional configuration. It can also mesh with two-factor authentication like RSA Security's SecurID, a one-time password (OTP) token, for additional security. Both products offer corporate accounts for business users.

Another option to consider is SSL-Explorer from 3SP Ltd., which offers an SSL VPN that doesn't require dedicated hardware. It can be installed on existing hardware and, like LogMeIn, can work with two-factor authentication.

On the physical side, laptops should be locked at all times when out of the office. The DEFCON SCL cable lock from Targus is designed for laptops, and can loop around the leg of a table at any coffee shop or airport lounge.

Finally, use common sense when carrying laptops around. Put them in non-descript briefcases without company logos so they can't be easily identified, and keep them in your possession at all times.

More information:


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Identity Management and Access Control
What are the options for a mechanical (not electrical) door security system on a server room door?
What's the difference between access control mechanisms and identity management techniques?
What courses can improve fundamental knowledge of infrastructure systems (Active Directory, LDAP, etc.)?
What tools provide user provisioning and single sign-on for PeopleSoft- and Unix-based products?
Should a new user have to confirm his or her email address before gaining access?
Can home PCs provide a way for viruses and spyware to enter a corporate LAN?
What should an enterprise look for in a password token, and in a vendor?
Is it possible to write a batch file that allows user access to the local admin group for a short time?
IAM best practices for employees with varying degrees of access to the same computer
What are some good pre-boot biometric user authentication tools or strategies?

SSL
Debian: A niche OS with a not-so-niche security flaw
The Shortcut Guide to Extended Validation SSL Certificates
Product review: Array Networks SPX2000
How to test the security of personal details submitted to a website
Should enterprises implement a mandatory iPhone VPN?
Should iPhone email be sent without SSL encryption?
How to secure an FTP connection
Can Trojans and other malware exploit split-tunnel VPNs to infiltrate a network?
What are the risks of connecting a Web service to an external system via SSL?
What is the most secure way for application developers to manage cookies?

Network Firewalls
Will there be DMZ routing issues if several firewalls serve as the default gateway?
What are the top LAN security issues in a client-server network environment?
Should tunnel connections be initiated from an ISP to a internal data center, or vice versa?
Cisco warns of security appliance flaws
Kaminsky: DNS issue still major threat
Product Review: Sophos Endpoint Security and Control 8.0
PCI DSS 1.2 clarifies wireless, antivirus use
Check Point adds virtual firewall appliance
Researchers develop lightweight Cisco IOS rootkit
Is it possible to allow select access to IP addresses using Windows Server 2003?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
SSL VPN  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
Targeted Security Channel Tips for Resellers, Integrators and Consultants
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts