NIST BYOD FEDERAL COMPLIANCE. AWS VIRTUAL DESKTOP INTERFACE. NIST Publication 800-53 Cybersecrity

Опубликовано: 04 Октябрь 2024
на канале: ProfessorBlackOps - CyberSecurity for the people
173
38

NIST BYOD FEDERAL COMPLIANCE. AWS VIRTUAL DESKTOP INTERFACE. NIST Publication 800-53 Cybersecrity
This document provides the IRS mandatory security requirements should an agency choose to use virtual desktop technologies (VDI) and is applicable to VDI environments in which agency-owned, non-agency owned and personally owned equipment may be used as the client for the virtual desktop.

Additional security requirements apply to an agency that is approved by IRS to use non-agency owned and personally owned equipment to access federal tax information (FTI) through a VDI environment. The agency must demonstrate that despite the operational location of the client, FTI remains subject to the safeguard requirements and the highest level of attainable security. Please reference Publication 1075, Section AC-20 Use of External Systems PDF for the detailed requirements.

VDI is the practice of hosting a desktop operating system within a virtual machine (VM) running on a centralized server. A VDI provides users access to enterprise resources, including a virtual desktop from locations both internal to and external to the agency’s networks.

In a VDI environment a user can access FTI by connecting to their virtual workstation via a vendor specific agent, connection client or through an Internet browser from practically any mobile device with Internet access. This can offer significant savings to agencies from a cost perspective and also from a management perspective, allowing agencies to largely centralize patch management and deploy standard desktop configurations.