2020-04-10
CISA Releases Temporary Telework Security Guidance
The US Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) has issued temporary telework guidance "to help agencies leverage existing resources to secure their networks" as the number of federal employees working from home has increased. The Trusted Internet Connections 3.0 Interim Telework Guidance has five security objectives: manage tragic, protect traffic confidentiality, protect traffic integrity, ensure service resilience, and ensure effective response.
Editor's Note
While this guidance is set to expire at the end of 2020, and is U.S. Government focused, it provides an approach to accessing cloud and on-premise services with sufficient visibility to ensure security and compliance requirements are met, irrespective of your industry or having a formal TIC.

Lee Neely
The Trusted Internet Connect 3.0 update is still in draft but added a lot of much-needed flexibility to make it clear how agencies can do remote user access and use cloud services and still stay secure and stay compliant. Between the Managed Trusted Internet Protocol Services (MTIPS) offered by TIC ISPs on the government EIS and other contracts, and the numerous FedRAMP certified cloud-based Security as a Service offerings, government agencies have both guidance and options to make long lasting improvements in both security and productivity for remote work forces.

John Pescatore
Read more in
CISA: TRUSTED INTERNET CONNECTIONS 3.0 INTERIM TELEWORK GUIDANCE (PDF)
Fifth Domain: DHS releases new network security guidance for telework
FCW: CISA looks to help secure federal telework
FNN: Path for agencies to more easily use cloud services paved by TIC pilots
Nextgov: CISA Offers Ways to Lessen Lag for Teleworkers Without Sacrificing Security