Jacques Sauve, le 30 décembre 2025 à 14 h 45, page 25.
“The organization should ensure that their users join a separate network that is independent of the home network (e.g. guest network)…”
This fails on three levels: technical, operational, and auditability.
1. It assumes control the organization does not have: most organizations do not own or manage employee home routers.
2.“Ensure” implies enforcement, not guidance.
3. You cannot verify compliance without invading privacy.
This is unenforceable for SMBs, especially with a WFH setup.
Modern best practice assumes:
- networks are hostile
- security lives on:
- the endpoint
- identity
- encrypted access
This control is trying to fix endpoint risk with network topology, which is backward.
Commentaires
Voir tous Annuler