Skip to main content
Guidance

Principles for secure privileged access workstations (PAWs)

How to design and securely build management devices for high-risk system maintenance and administration.

Page 7 of 10

Principle 5: Reduce the attack surface

The goal is to mitigate risk as much as possible on your PAW, whilst balancing security and usability.

A PAW device should be configured to meet your administrative access needs, while also minimising its attack surface. The goal is to mitigate risk as much as possible on your PAW, while ensuring that administrative tasks can still be carried out effectively.

You should carefully consider every feature, application and connection to a PAW, and make sure they are adequately protected. Disabling unnecessary functionalities or connections prevents a threat actor exploiting them. Any component of a system that connects externally can present a threat. For this reason, you should only allow external connections when access is essential, and manage it very carefully. 

It shouldn’t be possible to directly access any services on the PAW that pose a risk to it. This includes corporate applications, email and communication tools. If you require access to these services, manage it carefully, so that it doesn’t affect the integrity of the PAW. Examples here may include use of isolation and cross domain solution (CDS) technologies.

It’s important that these controls apply to any device that is used to access high privileged or critical service, including when that use is by a third party, and you should make sure that suitable controls are also in place for these users.



The control you choose should be well designed so that it works as intended. Think about how a threat actor could bypass these controls – for example, by using the device proxy settings to restrict internet access. Although this would restrict a device’s ability to connect to the wider internet, it could easily be defeated by a DNS poisoning attack.

If your organisation is in a regulated sector, you must also consider any legal and regulatory requirements where failure or loss of connectivity to the SASE service would disrupt your ability to manage your network(s). 

You should consider if the SASE product offers appropriate resilience for your regulatory requirements.

Where appropriate, you should still put in place contingency plans. This includes having a defined backup route to your services, so that privileged management can still be carried out from trusted PAW devices. 

This backup route should be treated as a break-glass solution, and controlled and monitored appropriately. 

Connectivity technology

To reduce your attack surface, make sure the connectivity methods the PAW uses, such as Wi-Fi or cellular, are adequately secured. 

Public Wi-Fi networks can present a major risk to a PAW device, as they often require use of a captive portal, where the local device connects directly to the local service to authenticate. The requirement for an unsecured connection to the captive portal conflicts with the on-device controls and would require an exception to a critical PAW control. For this reason, you shouldn’t allow connectivity to a captive portal from a PAW. Unless additional controls are put in place to mitigate this risk, consider alternative routes to connect to public Wi-Fi.

For organisations that use cellular networks with a private Access Point Name (APN), be aware that although an APN provides separation, it doesn’t provide encryption within the telecoms network.





Published

Reviewed

Version

1.0