Страницы

Sunday, May 3, 2020

Communication security

NSA security guide: How to choose safe conferencing and collaboration tools


NSA logo
The US National Security Agency (NSA) published last week a security assessment of today's most popular video conferencing, text chatting, and collaboration tools.
The guidance contains a list of security criteria that the NSA hopes companies take into consideration when selecting which telework tool/service they want to deploy in their environments.
The NSA document is not only meant for US government and military entities but the private sector as well.
The idea behind the NSA's initiative is to give military, public, and private organizations an overview of all of a tools' features, so IT staff don't make wrong decisions, expecting that a tool provides certain features that are not actually living up to the reality.
Per the NSA's document, the assessed criteria answers to basic questions like:
  1. Does the service implement end-to-end (E2E) encryption?
  2. Does the E2E encryption use strong, well-known, testable encryption standards?
  3. Is multi-factor authentication (MFA) available?
  4. Can users see and control who connects to collaboration sessions?
  5. Does the tool's vendor share data with third parties or affiliates?
  6. Do users have the ability to securely delete data from the service and its repositories as needed (both on client and server-side)?
  7. Is the tool's source code public (e.g. open source)?
  8. Is the service FedRAMP approved for official US government use?

No comments:

Post a Comment