1. Home
  2. Applications
  3. Citrix ICA Client – What Leaks?

Citrix ICA Client – What Leaks?

0
0

A common question I receive as Security Product Manager for XenApp and XenDesktop is “what information is left behind after the Citrix ICA client executes?” This happens most often for PCI DSS and HIPAA audits and the question is normally one of audit “scope.”The answer is that no screen or keyboard data is ever written to persistent endpoint storage

This post describes in detail the small bits of information that are written to the endpoint and describes the technique for reproducing the study.

PCI DSS and HIPAA with XenApp and XenDesktopRunning applications on hosted XenApp and XenDesktop machines, where only those data center resident hosted machines have

Running applications on hosted XenApp and XenDesktop machines, where only those data center resident hosted machines have vision to protected networks and databases and where end users have no network connection to databases, greatly reduces “scope”. The security assessment can focus on the potential areas of “high loss” and give lower focus to endpoint computers.The NetScaler Gateway Module ICA Proxy provides separation of networks and only ICA traffic makes it across the Gateway. The end user machine has no IP network connectivity to the host XenApp or XenDesktop computer and more importantly, the end user machine has no IP connectivity to the database server holding credit card or patient data. The ICA screen and keyboard data

The NetScaler Gateway Module ICA Proxy provides separation of networks and only ICA traffic makes it across the Gateway. The end user machine has no IP network connectivity to the host XenApp or XenDesktop computer and more importantly, the end user machine has no IP connectivity to the database server holding credit card or patient data. The ICA screen and keyboard data is wrapped inside TLS on its path to and from the gateway so there is little risk of exposure on the main corporate network. This is huge win for security.

Read the entire article here, Citrix ICA Client – What Leaks?

via the fine folks at Citrix Systems, Inc.

Categories:
Citrix Systems Citrix (NASDAQ:CTXS) aims to power a world where people, organizations and things are securely connected and accessible to make the extraordinary possible. Its technology makes the world’s apps and data secure and easy to access, empowering people to work anywhere and at any time. Citrix provides a complete and integrated portfolio of Workspace-as-a-Service, application delivery, virtualization, mobility, network delivery and file sharing solutions that enables IT to ensure critical systems are securely available to users via the cloud or on-premise and across any device or platform. With annual revenue in 2015 of $3.28 billion, Citrix solutions are in use by more than 400,000 organizations and over 100 million users globally. Learn more at www.citrix.com.

Featured Resources:

Related Articles:

| LATEST FEATURED RESOURCES

White Papers

‘All You Need to Know About Microsoft Windows Nano Server’ Veeam White Paper

Now updated for Windows Server 2016 GA release! You probably heard about Windows Nano Server already … but what is it exactly, and how do you get started with it? What value will it bring to your environment? Nano Server is a headless, 64-bit only deployment option for Windows Server 2016. Microsoft created this component specifically with […]

Downloads

Download Commvault VM Backup and Recovery: end-to-end VM backup, recovery and cloud management

Commvault’s ability to provide end-to-end VM backup, recovery and cloud management creates a significantly better way to build, protect and optimize VMs throughout their lifecycle. Our best-in-class software for VM backup, recovery and cloud management delivers a number of significant benefits, including: VM recovery with live recovery options; backup to and in the cloud; custom-fit […]

On-Demand Webinars

Architecting for today’s desktop environments – FSLogix On-Demand Webinar

October 19, 2017 Webinar with David Young, Solutions Architect and Product Champion, and Brandon Lee, Solutions Marketer. Video Recording of a live demo of FSLogix and an overview of the latest release of FSLogix Apps featuring Roaming XenApp Email Search and OneDrive App along with Skype for Business Global Address List and Device Based Licensing. […]

Latest Videos

Current State of EUC – E2EVC Video

Session from @E2EVC 2017 Orlando. For event information please visit www.e2evc.com/home. For slides, additional info etc please contact the presenter directly on Twitter. For best video and sound quality do visit the event! This video is from the fine folks at E2EVC Conference

Views All IT News on DABCC.com
Views All IT Videos on DABCC.com
Win a Tesla P100D

Visit Our Sponsors