Security of Unified Collaboration Tools

Get Started. It's Free
or sign up with your email address
Rocket clouds
Security of Unified Collaboration Tools by Mind Map: Security of Unified Collaboration Tools

1. Web Conferencing

1.1. Take ownership of the process of selecting the web conferencing solution.

1.2. Ensure that the underlying network itself is secured.

1.3. Disable or strongly audit read/write desktop mode, if supported by the product. This mode allows other meeting participants to access the host desktop.

1.4. Execute nondisclosure documents covering conferences that disclose confidential material or intellectual property.

1.5. Ensure that unique passwords are generated for each conference to prevent reuse of passwords for inappropriately attending conferences.

1.6. Consider requiring a VPN connection to the company network to attend conferences.

1.7. Define a process for selecting the product and using the product.The following four steps should be completed:

1.7.1. 1. Define the allowed uses of the solution.

1.7.2. 2. Identify security needs before selecting the product.

1.7.3. 3. Ensure that usage scenarios and security needs are built into the request for proposal (RFP).

1.7.4. 4. Include security practitioners in the planning and decisionmaking process.

2. Video Conferencing

2.1. Device-level physical encryption keys that must be inserted each time the system is used and that are typically exchanged every 30 days

2.2. Additional password keys that limit access to a device’s functions and systems

2.3. Session keys generated at the start of each session that are changed automatically during the session

2.4. Traffic transmitted on secure data networks that also use advanced encryption technologies

3. Instant Messaging

4. Desktop Sharing

4.1. Always use the latest version of the products.

4.2. Install all updates.

4.3. If the solution will only be used in a LAN, block the port number used by the solution at the network perimeter.

4.4. For mobile users, disable automatic listening on the device. This will prevent an open port in an untrusted network.

4.5. Regularly review security logs for evidence of port scans.

4.6. Secure access to configuration files used by the solution. Implement encryption.

4.7. Control administrative access to the solution.

4.8. Ensure logging settings that establish an audit trail.

4.9. Train users on its proper usage.

4.10. Remove the software from computers on which it should never be used, such as secure servers.

4.11. Implement policies to prevent its installation unless administrative approval is given.

5. Remote Assistance

5.1. Always use the level of encryption required by your industry.

5.2. Many remote assistance tools do not provide sufficient auditing capabilities, which are critical in industries like banking and healthcare. If auditing is an issue in your industry, choose a product with the ability to capture the detail you require for legal purposes.

5.3. Limited access control

5.4. Consider crafting a standard message that a user sees and must acknowledge before allowing the connection, stating the extent of liability on your part for issues that may arise after the remote session.

6. Presence

6.1. Select a product that uses a secure protocol. One example is Extensible Messaging and Presence Protocol (XMPP) over TLS, while another is Session Initiation Protocol for Instant Messaging and Presence Leveraging Extensions (SIMPLE).

6.2. Select a product that uses your company’s Public Key Infrastructure (PKI) for authentication. Certificate-based authentication, when possible, is the best.

6.3. Encrypt the communications both internally and across the Internet.

6.4. Ensure that the product performs authentication of both presence sources and subscribers.

6.5. If the system supports presence groups, use grouping to control the viewing of presence information among groups.

7. Email

7.1. It uses three standard messaging protocols. Each of them can be run over SSL to create a secure communication channel. When they are run over SSL, the port numbers used are different. Here are the 3 protocols:

7.1.1. Internet Message Access Protocol (IMAP) is an application layer protocol used on a client to retrieve email from a server.IMAP4 allows a user to download a copy and leave a copy on the server. IMAP4 uses port 143. A secure version also exists, IMAPS (IMAP over SSL), and it uses port 993.

7.1.2. Post Office Protocol (POP) It allows for downloading messages only and does not allow the additional functionality provided by IMAP4. POP3 uses port 110. A secure version that runs over SSL is also available; it uses port 995.

7.1.3. POP and IMAP are client email protocols used for retrieving email, but when email servers are talking to each other, they use Simple Mail Transfer Protocol (SMTP), a standard application layer protocol. This is also the protocol used by clients to send email. SMTP uses port 25, and when it runs over SSL, it uses port 465.

8. Telephony

8.1. Prevent physical access to the cabling plant.

8.2. Secure or disable all maintenance ports on the PBX(Private Branch Exchange).

9. VoIP

9.1. Physically separate the phone and data networks.

9.2. Secure all management interfaces on infrastructure devices (for example, switches, routers, gateways).

9.3. In high-security environments, use some version of a secure phone (to provide end-to-end encryption).

9.4. Deploy network address translation (NAT) to hide the true IP addresses of the phones.

9.5. Maintain the latest patches for operating system and VoIP applications.

9.6. Disable any unnecessary services or features.

9.7. To prevent performance issues, especially during DoS attacks on the network, employ 802.11e to provide QoS for the VoIP packets when they traverse a wireless segment, just as you would provide QoS on all wired segments.

9.8. Ensure that the SIP servers, which are the servers responsible for creating voice and video sessions, are protected by a firewall.

10. Collaboration Sites/Social Media

11. Cloud-Based Collaboration

11.1. Ensure that you completely understand the respective security responsibilities of the vendor and your organization.

11.2. If handling sensitive information, ensure that either the vendor is providing encryption or that you send data through an encryption proxy before it is sent to the provider.

11.3. Require strong authentication on the collaboration site. If the vendor also provides data loss prevention (DLP) services, strongly consider using these services.

11.4. When databases are also in use, consider implementing database activity monitoring (DAM).

12. Remote Access

12.1. If an organization allows remote access to internal resources, the organization must ensure that the data is protected using encryption when the data is being transmitted between the remote access client and remote access server.

13. Dial-up

13.1. A dial-up connection uses the public switched telephone network (PSTN).Have the remote access server call back the initiating caller at a preset number.

13.2. Do not allow call forwarding as this can be used to thwart this security measure.

13.3. Set modems to answer after a set number of rings to thwart war dialers. These are automated programs that dial numbers until a modem signal is detected.

13.4. Consolidate the modems in one place for physical security and disable modems that are not in use.

13.5. Use the strongest possible authentication mechanisms.

14. VPN

14.1. SSL

14.2. Point-to-Point Tunneling Protocol

14.3. (PPTP) Layer 2 Tunneling Protocol (L2TP)

15. BYOD

15.1. Create BYOD policies

15.2. Identify the allowed uses of personal devices on the corporate network.

15.3. Create a list of allowed applications on the devices and design a method of preventing the installation of applications not on the list (for example, software restriction policies).

15.4. Ensure that high levels of management are on board and supportive.

15.5. Train users in the new policies.