Skip to main content
Guidance

Principles for secure privileged access workstations (PAWs)

How to design and securely build management devices for high-risk system maintenance and administration.

Page 10 of 10

Principle 8: Control data entering and leaving the PAW solution

You should carefully manage data that is both imported to and exported from your PAW environment.

If you can’t trust files that are downloaded and then opened on your PAW device, they could be malicious and exploit your PAW.

Similarly, if a PAW is compromised, an attacker could abuse how your PAW exports data to exfiltrate sensitive information. For these reasons, you should carefully constrain and control how data is imported and exported from your PAW solution. 

Building an effective process for important and exporting data is critical to enable your engineers to carry out their duties. Where this is not in place, users may resort to shadow IT. 

An effective solution to manage your data effectively also helps you migrate away from the use of higher-risk transfer methods, such as removable media. Where it’s not possible to remove these methods from your environment, you should still apply the controls described in this principle. RITICS has guidance on managing removable media for ICS and OT environments that can support you here.



Published

Reviewed

Version

1.0