Skip to main content

Secure Remote Access

Description

Secure Remote Access represents the capability allowing administrators to securely access the Scheol Lab infrastructure from external networks.

This capability is implemented through controlled entry points such as a bastion host and centralized identity management.

The objective is to ensure that all administrative access is authenticated, logged and restricted according to least-privilege principles.


Asset Identification

AttributeValue
Asset IDBUS-ACC-01
CI TypeBusiness
Asset NameSecure Remote Access
Asset CategoryAdministrative Access Capability
OwnerSecurity Role (Sec)
StatusPlanned
LocationInfrastructure perimeter
Primary FunctionControlled administrative access to infrastructure

Asset Dependencies

Dependency TypeAssetStatus
Access PlatformTeleport BastionPlanned
Identity PlatformIdentity Management PlatformPlanned
InfrastructureProxmox HostActive

Relationships

RelationshipTarget CI
UsesTeleport Bastion
UsesIdentity Management Platform
Supports capabilityGovernance & Documentation

Asset Classification

CriteriaLevel
Confidentiality🟥 High
Integrity🟥 High
Availability🟨 Medium

Criticality score: 🟥 High


Responsibilities

RoleResponsibility
Security Role (Sec)Access policies and authentication controls
Operations Role (Ops)Infrastructure hosting the access platforms

Security Controls (High-Level)

  • Strong authentication mechanisms
  • Role-based access control
  • Access logging and monitoring
  • Secure remote access protocols

Security Considerations

Potential risks include:

  • Unauthorized remote access
  • Credential compromise
  • Insufficient access monitoring

Controls focus on authentication security, logging and least-privilege access.

Methodological References:

  • ISO 27001 - Control 5.1 Policies for information security ; Control 8.2 Privileged access rights.
  • NIST CSF - PR.AC Identity Management, Authentication and Access Control.
  • EBIOS RM - Access control related assets.