[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 939
  • Last Modified:

Citrix remote risk assessment

I have been asked to perform a risk assessment for a client who has users connecting to their site through Citrix

I need to provide them with a report that list the security vulnerbilities and risk from doing so.
I have never done a security risk aassessment and not sure where to begin.

What tools do I need and what to look for?
0
Tcarollo
Asked:
Tcarollo
  • 2
2 Solutions
 
Ron MalmsteadInformation Services ManagerCommented:
Microsoft Security Baseline Analyzer 2.0 for starters....that will show you typical vulnerabilities for the OS.
Hit Windows update site, to list available updates for the OS as well.

More importantly you need to look at the domain "password policy", complexity, and lockout duration.
Is "passthrough" authentication allowed  on the citrix box ?
Who maintains, and documents who has permission to logon to citrix in Active Directory ?
Are client drives, com ports, audio, or client printer mapped at logon ?
Is there Group Policy applied to the Citrix box ?
Who is an Administrator on the local users and groups for the citrix server ?
Is there a published desktop, or published Apps ?
Is there accounting software on the citrix server, and if so, is the program folder locked to Accounting Group only ?
Is outlook express being used on the server ? If not, there should be permissions on the program folder for only local admins.
Are users allowed to use internet explorer on the server ? If not, lock it down.
If it is a windows 2003 box, is "advanced security configuration" turned on for internet browsing ?
Group policy for trusted, restricted, internet sites ?
Group plicy for Site Zone security settings ?
Can users install print drivers ?
Can users logon with RDP as well ?

Some of the above may help you get started.
good luck.
0
 
TcarolloAuthor Commented:
That is a great start, thanks for all of that info.
My part of the audit doesn't start for a couple weeks.
I will keep in touch and ask more questions if you don't mind.

0
 
Ron MalmsteadInformation Services ManagerCommented:
ask away.
0
 
LBACISCommented:
These will do the trick and with the exception of GFI they are free.
                             
                                                Nessus, NEWT, GFILanGuard
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now