Remote Access Services Implementation Requirements

All UC Berkeley IT Resources and all devices connected to the UC Berkeley network or cloud services must comply with the Minimum Security Standard for Networked Devices (MSSND). The Implementation Requirements below describe how to comply with the MSSND Remote Access Services Requirement.

Background and Description of Risk

Services that provide remote access to systems (e.g., desktop, shell), allow remote administration of applications or services, or provide access to the UC Berkeley network from the public Internet are high-value targets for attackers. When these services are open to the Internet, attackers may be able to compromise credentials, the system and its data, or put other systems at risk.

Implementation Requirements

Remote desktop, interactive shell, terminal-level access, and similar remote access services, as well as remote administrative access, may not be publicly accessible from the Internet. The following controls are required for these and similar types of remote access to IT Resources[1][2][3]:

  1. Firewalls or other network-based access controls that restrict access from the public Internet as much as possible. 
  2. Multifactor authentication (MFA).
  3. Access logging.

These requirements can be met by either:

A. Using Campus-Approved Remote Access Services

-or-

B. Using Unit-Approved Remote Access Services

For situations where Units need alternatives to the pre-approved campus solutions in option A above, Units may establish internal policy and procedures for the approval of remote access configurations within the Unit. Policies and procedures must:

  • Be documented;
  • Meet minimum campus requirements for implementation of the controls listed above, plus any additional requirements the Unit includes to manage risk;
  • Include a process to review remote access configurations prior to approval. The review process must, at a minimum, validate compliance with the Unit’s documented policy;
  • Include informing the Information Security Office (security@berkeley.edu) of Unit-approved remote access implementations in order to ensure they are not blocked from the campus network.

Notes:

  • [1] Applies to UC IT Resources when connected to a UC Berkeley network, or when storing, processing, or accessing Institutional Information hosted at any location, regardless of the location or ownership of the IT Resources.
  • [2] Administrative access in this context refers to higher level admin/sys admin access, such as root or superuser-level control of a system or a server’s data stores – consistent with the definition of “Privileged Account” in the IT Policy Glossary. Examples include the ability to administer, configure, manage, code, provide access to, etc. a system. It is not intended to address interfaces limited to allowing user-level access, such as webpage editing.
  • [3] These are minimum requirements only. Additional controls are required when P3, P4, or A4-level systems, data, or services are involved. See the campus Minimum Security Standards for Electronic Information (MSSEI) for details. 

Exceptions

Remote access configurations that do not meet one of the options above require a policy exception or may be blocked from the campus network. Compensating controls for exceptions should include network restrictions, MFA, and audit logging.

Scope Clarification

Examples of situations where this requirement applies:

  • A workstation (desktop, laptop, etc.) or server with remote desktop services (such as RDP or VNC) open to the Internet
  • Units/departments operating a VPN service
  • An SSH server that allows connections from the public Internet
  • Administrator-level access to a server or web application

Examples of situations where this requirement does not apply:

  • Remote access is restricted to a limited number of trusted hosts 
  • Remote access is restricted to one off-campus IP address or a small range of off-campus IP addresses
  • Access is from one campus host to another
  • The installation of routers, switches, and other network devices that extend the internal network without providing external access 
  • Attended connections that are initiated from the campus network (e.g. outbound remote desktop, video conference screen sharing, etc.) [4]
  • Remote support sessions that are initiated by the person requesting the support [4]
  • Remote access only from eduroam (this is a campus network)
  • Interfaces limited to allowing user-level access, such as webpage editing

[4] NOTE: Third-party services used to facilitate remote access must follow applicable Procurement data security policies and procedures.