Skip to main content
Guidance

Principles for secure privileged access workstations (PAWs)

How to design and securely build management devices for high-risk system maintenance and administration.

Page 8 of 10

Principle 6: Isolate high-risk activity from your PAW

If you enable software or features that could undermine a PAW's security posture and create additional attack surface you should understand the risks of doing so.

Maintaining trust in your PAW is essential but it might sometimes be necessary to enable software or features that could undermine its security posture, and create additional attack surface. Examples here include if you are running vulnerable legacy software, or allowing local system administration to configure the device.

As far as possible, you should avoid enabling such software or features but if it is really necessary, you must fully understand the risks of doing so. An alternative is to implement these actions in a way that isolates it from the PAW. You can use virtualisation to achieve this.




Published

Reviewed

Version

1.0