It covers the entire session lifecycle: request, authorization, identity verification, endpoint checks, connection path, least-privilege access, monitoring, termination, review, and removal.
A secure design minimizes remote access and brokers justified connections through an IDMZ. Named accounts, phishing-resistant multi-factor authentication, time limits, approved tools, session oversight, and operations-team awareness reduce risk. For some maintenance paths, an OT-initiated or callback connection can provide a compensating control. Control assets should not be exposed directly to the internet.
Key points
Establish the business needRecord the requester, target, task, approver, permitted actions, timing, operational state, and accountable internal owner before access is enabled.
Control identity and endpointUse unique identities, strong MFA, managed access devices or hardened jump hosts, and separate privileged from routine activity.
Limit the route and sessionPermit only required assets and protocols, use temporary credentials or rules, supervise high-impact work, record appropriate evidence, and expire access automatically.
Prepare for troubleGive operations a safe way to observe and terminate a connection, define escalation and fallback communications, and verify that emergency disconnection will not create a more dangerous state.
Important limitationA VPN encrypts a path but does not make the user, endpoint, credentials, requested action, or destination trustworthy. Remote containment or loss of connectivity can also affect availability and safety, so response actions require tested operational procedures.