# What is Secure Remote Access?

> Secure remote access is the governed capability for an authorized person or system outside an operational trust boundary to reach specified OT resources for an approved purpose.

- Canonical URL: https://yellowcube.eu/glossary/secure-remote-access/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It covers the entire session lifecycle: request, authorization, identity verification, endpoint checks, connection path, least-privilege access, monitoring, termination, review, and removal.

A secure design minimizes remote access and brokers justified connections through an IDMZ. Named accounts, phishing-resistant multi-factor authentication, time limits, approved tools, session oversight, and operations-team awareness reduce risk. For some maintenance paths, an OT-initiated or callback connection can provide a compensating control. Control assets should not be exposed directly to the internet.

### Key points

- **Establish the business need:** Record the requester, target, task, approver, permitted actions, timing, operational state, and accountable internal owner before access is enabled.
- **Control identity and endpoint:** Use unique identities, strong MFA, managed access devices or hardened jump hosts, and separate privileged from routine activity.
- **Limit the route and session:** Permit only required assets and protocols, use temporary credentials or rules, supervise high-impact work, record appropriate evidence, and expire access automatically.
- **Prepare for trouble:** Give operations a safe way to observe and terminate a connection, define escalation and fallback communications, and verify that emergency disconnection will not create a more dangerous state.
- **Important limitation:** A VPN encrypts a path but does not make the user, endpoint, credentials, requested action, or destination trustworthy. Remote containment or loss of connectivity can also affect availability and safety, so response actions require tested operational procedures.

### Related terms

[Industrial demilitarized zone (IDMZ)](<https://yellowcube.eu/glossary/industrial-demilitarized-zone/>) · [Multi-factor authentication (MFA)](<https://yellowcube.eu/glossary/multi-factor-authentication/>) · [Privileged access management (PAM)](<https://yellowcube.eu/glossary/privileged-access-management/>) · [Least privilege](<https://yellowcube.eu/glossary/least-privilege/>) · [Network segmentation](<https://yellowcube.eu/glossary/network-segmentation/>) · [Operational technology (OT) security](<https://yellowcube.eu/glossary/operational-technology-security/>)

### Sources

[NIST SP 800-82 Rev. 3: Guide to Operational Technology Security](https://csrc.nist.gov/pubs/sp/800/82/r3/final) · [CISA: Configuring and Managing Remote Access for Industrial Control Systems](https://www.cisa.gov/sites/default/files/2023-01/RP_Managing_Remote_Access_S508NC.pdf) · [CISA: Primary Mitigations to Reduce Cyber Threats to Operational Technology](https://www.cisa.gov/sites/default/files/2025-05/fact-sheet-primary-mitigations-to-reduce-cyber-threats-to-operational-technology-508c.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

