4.3 Secure Communication Channels
4.3 Secure Communication Channels
A secure communication channel protects information while it moves between people, systems, networks and organisations.
Security is not achieved simply by "encrypting the connection". The communicating endpoints must also be appropriately authenticated, access must be restricted, the channel must be configured securely and activity should be monitored according to risk.
Protect
Protect information against interception and unauthorised modification.
CONFIDENTIALITY + INTEGRITYAuthenticate
Establish confidence in the identities at each end of the channel.
TRUST THE ENDPOINTSControl
Limit what the channel can reach and monitor how it is used.
LEAST PRIVILEGEThe Big Idea
Secure communication requires protection of both the channel and the endpoints.
Secure Channel Memory Aid
Authenticate β Protect β Restrict β Monitor β Terminate
Four Communication Areas
Conferencing, voice services, collaboration platforms and meeting environments.
Secure access by users, administrators and support personnel from remote locations.
Communication over backhaul networks, satellite links and other transport infrastructure.
Connections involving telecom providers, vendors, partners and hardware-support organisations.
What Makes a Channel Secure?
Prevent unauthorised parties from reading information in transit.
Detect unauthorised modification of communication.
Establish confidence in the identity of communicating parties.
Prevent previously captured legitimate communication from being reused improperly.
Ensure the communication service remains available when required.
Authentication to a channel should not automatically provide unrestricted access to everything behind it.
π€ Secure / Trusted Channel Protect the path between known endpoints
A secure communication channel uses appropriate mechanisms to protect information moving between communicating entities.
Depending on the technology and requirement, this may include:
Perfect encryption between a user's laptop and a server does not protect the information if the laptop itself is compromised by malware.
Secure Channel
π Transport Layer Security - TLS Protect application communication
TLS creates a protected communication channel between applications.
It is used by many application protocols, most visibly HTTPS.
TLS Can Provide
A customer connects to:
https://bank.example
TLS can protect information moving between the browser and the web service and allow the client to authenticate the server through its certificate.
TLS can protect communication to a malicious or vulnerable application.
Transport security and application security are different controls.
π Certificate Validation Encryption is more useful when the peer is correctly authenticated
Certificate-based secure channels rely on appropriate validation of the peer's identity.
Validation Can Include
A client receives a certificate warning.
The user is trained simply to click:
"Continue anyway."
The communication might still be encrypted, but confidence that the user is communicating with the intended server has been weakened.
Certificate
π‘οΈ IPsec Protect communication at the IP layer
IPsec provides security services for IP network communication and is commonly used to create VPNs.
Common Uses
Encapsulating Security Payload can provide confidentiality, integrity and authentication-related protection depending on configuration.
Authentication Header provides integrity and authentication protection but not confidentiality.
A site-to-site VPN can protect communication between two gateways, while the internal systems behind those gateways still require their own security controls.
Virtual Private Networks - VPN
A VPN creates a logical protected communication path across another network, commonly the public internet.
Connects an individual remote endpoint to organisational resources.
USER β ORGANISATION
Connects networks or locations through VPN gateways.
NETWORK β NETWORK
VPN
π Full Tunnel vs Split Tunnel Where does remote-user traffic go?
Applicable network traffic is routed through the organisation's VPN connection.
This can provide greater central visibility and policy enforcement but increases infrastructure and bandwidth requirements.
Organisational traffic uses the VPN while other traffic can use the endpoint's local internet connection directly.
This can reduce VPN traffic but creates additional security and visibility considerations.
Architecture should balance protection, visibility, bandwidth, availability and user requirements.
It changes the architecture and therefore changes which endpoint and network controls become important.
Remote Access
Remote access allows users or administrators to interact with systems from outside the normal local environment.
π Secure Remote Access Design Identity, endpoint, channel and destination all matter
Important Controls
A legitimate user can successfully complete MFA from a compromised endpoint.
Endpoint security and session protection therefore remain important.
π Remote Administrative Access Privileged remote channels deserve stronger protection
Remote administration can provide direct control over critical systems and infrastructure.
It should normally receive stronger controls than ordinary end-user access.
Reduce dependence on a single privileged credential.
Separate privileged administration from everyday user identities.
Provide a controlled administrative entry point before sensitive systems are reached.
Privileged Access Management can control privileged credentials, approvals and sessions.
Administrative activity should be attributable and appropriately monitored.
Administrative interfaces should not necessarily be reachable from every endpoint or network.
Every administrator can connect directly from a personal laptop over the internet to the management interface of every production server.
Administrators authenticate strongly to a controlled privileged access environment and reach only systems they are authorised to manage.
Privileged Remote Access
β¨οΈ Secure Administrative Protocols Avoid exposing management credentials and commands
| Prefer | Avoid Where Secure Alternative Exists | Why |
|---|---|---|
| SSH | Telnet | SSH provides protected remote terminal communication. |
| HTTPS | HTTP administration | HTTPS protects browser-based management communication using TLS. |
| Secure Management Protocols | Unprotected legacy management | Administrative credentials and commands require protection. |
Administrative sessions may contain passwords, configuration information and commands capable of changing the security posture of entire systems.
πͺ Jump Hosts / Bastion Hosts Provide a controlled path into sensitive environments
Benefits
Concentrating privileged access through one system makes that system especially important to harden, patch and monitor.
π― ZTNA & Resource-Level Remote Access Access the required application rather than the whole network
Zero Trust Network Access can provide controlled access to specific resources based on identity, device and policy context.
A remote user connects to a network and may then be able to discover or interact with many resources within that network.
The user receives access to the specific application or service required by policy.
Remote Access
The effectiveness depends on architecture, implementation, identity, endpoint posture, policy and monitoring.
Communication Is More Than Data Files
Modern organisations rely heavily on voice, video, messaging, screen sharing, meeting rooms and collaboration platforms.
βοΈ VoIP: Signalling vs Media Setting up the call and carrying the conversation are different functions
Establishes, modifies and terminates communication sessions.
SIP is a common signalling protocol.
Carries the actual voice or video content.
RTP is commonly associated with real-time media transport.
Protecting call signalling while leaving the actual voice stream exposed does not provide complete communication confidentiality.
VoIP
ποΈ Voice & Video Risks Real-time communication has confidentiality and availability requirements
Unprotected communication may expose conversations.
Attackers may attempt to manipulate or take over communication sessions.
Weak identity controls may allow an attacker to impersonate a trusted participant.
Real-time communication can be highly sensitive to service interruption.
Even protected content may reveal metadata about who communicates and when.
An attacker controlling a microphone, camera or conferencing device may bypass channel protection entirely.
π₯ Collaboration Platform Security Protect meetings, rooms, recordings and participants
Security Considerations
Determine who may join sensitive meetings.
Control invitations, meeting links, waiting rooms and guest access.
Restrict who may present sensitive information.
Apply appropriate access and data-protection controls to shared content.
Meeting recordings create stored information that may require classification, access control and retention.
Guests and partners may introduce different trust and information handling considerations.
Conferencing-room computers, microphones and cameras are endpoints and require lifecycle security.
Central platform configuration should follow organisational security policy.
A confidential executive meeting is protected by an encrypted conferencing service.
However:
- the joining link is posted publicly;
- participants are not authenticated;
- any participant can record;
- recordings are retained indefinitely.
The encrypted channel alone does not make the meeting secure.
βΊοΈ Communication Recordings Data in transit can become data at rest
Recording Controls
Meeting Recording
Protect the Underlying Transport
Organisational data may traverse infrastructure that the organisation does not completely own or control.
π Backhaul Networks Carry aggregated communication toward core infrastructure
Backhaul communication transports traffic from access or remote infrastructure toward more central network infrastructure.
Security Considerations
An organisation should understand the security guarantees actually provided by the carrier or network technology rather than assuming that a service is secure because it is described as private.
π°οΈ Satellite Communications Large geographic reach creates different communication risks
Signals may be receivable across a broad geographic footprint.
Sensitive information should receive appropriate cryptographic protection.
Radio-frequency interference can threaten availability.
Some satellite architectures introduce significant communication delay.
Communications may depend on infrastructure outside direct organisational control.
Ground stations and supporting systems become part of the security architecture.
Satellite
π Private Carrier Connectivity Separation and encryption are different properties
Organisations may purchase private connectivity from telecommunications providers.
Such services can provide useful routing separation and service guarantees.
Two offices communicate through a private carrier service.
The organisation determines that highly sensitive data requires cryptographic confidentiality even from the carrier infrastructure.
An additional encrypted channel such as IPsec may therefore be used over the underlying transport.
Private vs Encrypted
Your Network Boundary Can Extend Into Someone Else's Organisation
Business partners, telecom providers and hardware vendors may require connectivity to organisational systems.
Every external connection creates a trust relationship that should be understood and controlled.
π€ Third-Party Connectivity Controls Do not provide more connectivity than the business relationship requires
Connectivity should exist because a legitimate business need has been identified.
Third-party identities should be appropriately authenticated.
Vendors should reach only the resources required for their task.
Third-party access should not create unnecessary paths into other environments.
Sensitive communication should receive appropriate protection in transit.
External access should be visible and attributable.
Permanent connectivity should not be created where temporary access satisfies the requirement.
Access should be removed promptly when the relationship or need ends.
A trusted external connection can provide an attack path if the connected organisation is itself compromised.
π§ Remote Vendor & Hardware Support Support access is often privileged access
Hardware and software vendors sometimes require remote access to troubleshoot or maintain systems.
A vendor receives:
- a permanent shared administrator account;
- 24/7 unrestricted connectivity;
- direct access to all production systems;
- no activity monitoring.
Vendor support receives:
- individual authenticated access;
- MFA;
- access only when approved and required;
- a controlled jump host or PAM path;
- access only to relevant systems;
- logging and session monitoring;
- automatic expiration where appropriate.
Vendor Access
π Telecommunications Providers Understand which security controls belong to the provider and which remain yours
Questions to Ask
The organisation still needs to understand whether the provided service satisfies its confidentiality, integrity and availability requirements.
Third-Party Connection Lifecycle
Connectivity should have an owner and lifecycle.
β° Persistent vs On-Demand Connectivity Do not create permanent attack paths unnecessarily
Remains continuously available.
Appropriate where constant business communication is genuinely required.
Enabled only when an approved requirement exists.
Can reduce unnecessary exposure for occasional support or maintenance access.
A hardware vendor performs maintenance twice per year.
A permanent unrestricted VPN available 365 days a year may introduce much more exposure than an approved, time-limited support session.
Where Does Encryption Begin and End?
The location of cryptographic endpoints determines which parts of the communication path are protected.
TLS terminates at a reverse proxy.
The organisation must separately decide how communication from the proxy to the backend application should be protected.
Ask: encrypted from where to where?
Encryption Question
π End-to-End vs Hop-by-Hop Protection Understand who can see the communication along the path
Information remains protected between the intended communicating endpoints.
Individual communication links are protected, but information may be decrypted and re-protected at intermediate systems.
Both links are encrypted, but the gateway may have access to the plaintext between the two cryptographic sessions.
Protection Scope
π Keys, Certificates & Trust Secure channels depend on secure cryptographic identity
Cryptographic communication can be undermined if its key or trust material is compromised.
Important Considerations
A VPN gateway uses strong encryption.
Its private authentication key is stolen.
The mathematical algorithm may remain secure while trust in the gateway's identity has been compromised.
π’ Communication Availability A perfectly encrypted channel is useless if nobody can use it
Availability Considerations
Avoid dependence on one VPN or communication appliance.
Critical connectivity may require provider diversity.
Different providers may still share the same cable route.
Secure communication infrastructure needs sufficient bandwidth for legitimate demand.
Public communication gateways can become denial-of-service targets.
Failed tunnels and communication degradation should be detected quickly.
Confidentiality and integrity often receive the most attention, but availability is equally relevant when communication supports critical operations.
An Employee Works From Home
MFA protects authentication.
The secure channel protects communication.
Endpoint security protects the laptop.
Authorisation controls what the employee can reach.
Monitoring helps identify misuse or compromise.
A Vendor Needs Emergency Access
A network-hardware vendor needs to troubleshoot a critical production router.
A Confidential Video Meeting
Only intended participants should join.
Voice and video communication should receive appropriate transport protection.
Sharing should be limited to authorised participants.
Recording should follow information-classification and retention requirements.
Meeting-room systems and participant devices should be appropriately secured.
Sensitive conversations should not be exposed to unauthorised people physically present nearby.
Communication security includes endpoint and physical-context risk as well as network transport.
π CISSP Scenarios Identify the secure-channel principle
A customer enters payment information into a web application and the communication must be protected against interception.
Which technology is commonly relevant?
TLS.
A user ignores a certificate warning and continues to an administrative website.
Which security property has been weakened?
Confidence in authentication of the remote endpoint.
Two office networks need protected IP communication across the public internet.
Which solution is particularly relevant?
Site-to-site IPsec VPN.
One employee connects securely from home to organisational network resources.
Which type of connectivity?
Remote-access VPN.
All applicable traffic from a remote laptop is sent through the organisation's VPN infrastructure.
Which design?
Full tunnel.
Corporate traffic traverses the VPN, while ordinary internet traffic uses the user's local connection.
Which design?
Split tunnel.
An administrator needs a protected command-line session to a Unix server.
Which protocol?
SSH.
Management proposes Telnet for remote administration across an untrusted network.
Primary concern?
Administrative communication and credentials are not appropriately protected.
Administrators must connect through one hardened system before reaching production servers.
Which control?
Jump host / bastion host.
An administrator successfully authenticates with MFA, but the administrator's laptop is infected with malware.
What does this demonstrate?
Strong authentication does not replace endpoint security.
A VoIP environment protects its signalling messages but the actual voice media remains unprotected.
What is the concern?
Protecting signalling alone does not protect the confidentiality of the conversation.
SIP establishes a voice call.
What role is SIP primarily performing?
Signalling / session establishment.
RTP carries the live voice communication.
What role is RTP performing?
Media transport.
An organisation wants cryptographic protection for real-time media.
Which protocol concept is relevant?
SRTP.
A confidential meeting uses encrypted video communication but anyone possessing the publicly shared meeting link can join.
What is missing?
Appropriate participant access control and authentication.
A sensitive meeting is recorded.
How should the recording now be viewed?
As stored information requiring appropriate classification, access, protection and retention.
A satellite communication system is vulnerable to deliberate radio-frequency interference.
Which security property is most directly threatened?
Availability.
An organisation assumes its private telecom circuit does not require encryption because the connection is not routed over the public internet.
What should security determine?
Whether the service actually satisfies the required confidentiality and integrity guarantees rather than assuming "private" means encrypted.
A hardware vendor needs remote administrative access for two hours.
Security creates a permanent 24/7 administrator VPN account.
Which principle is violated?
Least privilege and time-limited access.
A third party has a VPN into production, but nobody knows which team owns the connection or whether it is still required.
Primary concern?
Poor third-party connectivity lifecycle and governance.
An attacker compromises a trusted business partner and uses the partner's legitimate network connection to attack the organisation.
Which lesson?
Third-party connectivity creates a trust path and should be segmented and limited according to least privilege.
A web connection is encrypted from the customer to a reverse proxy, but communication from the proxy to the backend application is plaintext.
What architectural question was overlooked?
Where encryption terminates and how the remaining communication path is protected.
A secure channel protects communication between two gateways, but an endpoint behind one gateway is compromised.
What does this demonstrate?
Channel security does not replace endpoint security.
An organisation uses two telecommunications providers, but both providers' cables enter through the same street duct.
Which availability concern?
Lack of physical route diversity.
Vendor support sessions use individual identities, MFA, a controlled jump server and session recording.
Which principle is demonstrated?
Controlled privileged third-party access with accountability.
A VPN authenticates successfully, but the remote user can reach every production subnet regardless of role.
What is missing?
Appropriate authorisation and least privilege after authentication.
A collaboration service uses strong encryption, but meeting-room systems have not received security updates for three years.
What is the primary lesson?
Secure communication still depends on secure endpoints.
A company encrypts sensitive communication over a carrier network even though the provider already offers private connectivity.
What principle does this demonstrate?
Defence in depth and protection independent of the underlying transport provider.
Remote users can access only the specific applications authorised for them rather than receiving broad network-level access.
Which modern architecture is particularly relevant?
ZTNA / resource-level zero-trust access.
A VPN gateway fails and all remote workers immediately lose access.
What architectural consideration was insufficient?
Communication-channel availability and redundancy.
Recognise the Clue Words
Secure Web Connection
Protected client/server application communication.
TLSNetwork-Layer Protection
Protect IP communication.
IPsecUser β Organisation
Individual remote connectivity.
Remote-Access VPNNetwork β Network
Connect offices or environments.
Site-to-Site VPNEverything Through VPN
Central security path.
Full TunnelCorporate + Local Internet
Two traffic paths.
Split TunnelSecure Command Line
Protected administration.
SSHPrivileged Entry System
Controlled administrative path.
Jump HostManage Privileged Session
Credentials and privileged activity.
PAMAccess Specific Resource
Avoid broad network trust.
ZTNASet Up Voice Call
Session signalling.
SIPCarry Voice / Video
Real-time media.
RTPProtect Voice / Video Media
Secure real-time transport.
SRTPMeeting Recording
Communication becomes stored asset.
Data at RestCarrier Aggregation
Access network toward core.
BackhaulWide Radio Footprint
Interception and jamming.
SatellitePrivate Circuit
Do not assume cryptographic protection.
Verify Security GuaranteesVendor Remote Support
External privileged access.
Third-Party ConnectivityTemporary Maintenance
Do not create permanent access.
Time-Limited AccessEncrypted to Proxy Only
Understand next hop.
Encryption TerminationKnown Endpoints + Protected Path
Secure communication relationship.
Secure Channelβ οΈ Common CISSP Mistakes Encryption is only one piece of communication security
Confidentiality without reliable endpoint authentication may still leave communication vulnerable to impersonation.
Malware at either endpoint may access information before encryption or after decryption.
Successful VPN authentication should not automatically grant access to every resource.
A VPN protects communication.
It does not remove malware from the connected endpoint.
MFA strengthens authentication but does not secure a compromised endpoint or poorly authorised session.
It offers architectural benefits but also introduces capacity, performance and availability considerations.
It changes the security architecture and therefore requires appropriate endpoint and access controls.
Call signalling and media transport are different functions.
Participant access, recording, file sharing and endpoint security still matter.
Once recorded, the meeting becomes stored information requiring protection as data at rest.
Network separation and cryptographic confidentiality are different security properties.
Different carriers may still use shared ducts or other infrastructure.
A legitimate vendor relationship should not imply unrestricted network access.
Temporary business needs should normally result in appropriately time-limited access.
Always determine where cryptographic protection begins and terminates.
The organisation still needs to determine whether the service meets its security requirements.
Quick Reference
| If you see... | Think... |
|---|---|
| Protected browser-to-server communication | TLS |
| Protect IP communication | IPsec |
| Individual working remotely | Remote-Access VPN |
| Connect two networks | Site-to-Site VPN |
| All applicable remote traffic via organisation | Full Tunnel |
| Corporate traffic via VPN, other traffic local | Split Tunnel |
| Protected command-line administration | SSH |
| Controlled administrative entry point | Jump / Bastion Host |
| Privileged credential/session management | PAM |
| Resource-specific remote access | ZTNA |
| VoIP session establishment | SIP / Signalling |
| Live voice/video transport | RTP |
| Protected real-time media | SRTP |
| Video meeting stored afterwards | Recording / Data at Rest |
| Access network to core | Backhaul |
| Wide-area radio communication | Satellite |
| Radio interference causes outage | Jamming / Availability |
| Private carrier circuit | Do Not Assume Encryption |
| Vendor reaches internal systems | Third-Party Connectivity |
| Short support requirement | Time-Limited Access |
| Partner connection has no owner | Connectivity Governance |
| TLS ends at load balancer/proxy | Encryption Termination |
| Different encrypted links at each hop | Hop-by-Hop Protection |
| Protection remains to intended endpoint | End-to-End Protection |
Voice & Collaboration Memory Aid
Remote Access Memory Aid
Third-Party Connectivity Memory Aid
4.3 Master Memory Aid
Voice Β· Remote Β· Data Β· Third Party
The Secure Communication Questions
Key Takeaways
Secure communication channels protect information while it moves between people, systems, networks and organisations.
Encryption alone is not enough. Secure communication also depends on endpoint authentication, integrity, appropriate authorisation and secure endpoints.
A secure channel should be considered in terms of both endpoints and the path between them.
TLS protects application communication and can provide confidentiality, integrity and endpoint authentication.
Certificate validation is important because an encrypted connection is much less useful if the peer's identity cannot be trusted.
IPsec provides security at the IP layer and is commonly used to create network-layer VPNs.
Remote-access VPNs generally connect an individual endpoint to organisational resources, while site-to-site VPNs connect networks.
Full-tunnel and split-tunnel VPN designs create different visibility, performance and security trade-offs.
Remote access should combine strong authentication, endpoint security, protected communication, least privilege and monitoring.
Privileged remote administration usually warrants additional controls such as MFA, dedicated administrative identities, jump hosts and privileged-access management.
A user successfully completing MFA does not prove that the user's endpoint is secure.
Secure administrative protocols such as SSH should be preferred to unprotected legacy mechanisms when communicating across untrusted networks.
Jump hosts provide controlled entry into sensitive administrative environments but become high-value targets themselves.
ZTNA can provide resource-level access rather than automatically extending broad network access to a remote user.
Voice-over-IP security should distinguish between signalling and the actual media stream.
SIP is commonly associated with signalling, RTP carries real-time media and SRTP provides security protection for real-time media.
Conferencing security includes participant control, screen sharing, file sharing, recordings, endpoints and physical surroundings as well as transport encryption.
Once a meeting is recorded, the recording becomes stored information requiring appropriate access, retention and data-protection controls.
Data communication paths such as backhaul, satellite and carrier infrastructure may be outside direct organisational control.
Satellite communication introduces considerations including broad signal propagation, interception risk, jamming, latency and provider dependency.
Private connectivity does not necessarily mean cryptographically encrypted connectivity.
Third-party connectivity creates an external trust path and should be controlled according to business need and least privilege.
Vendor access should use individual identities, strong authentication, restricted destinations and appropriate monitoring.
Temporary support requirements should not automatically result in permanent remote-access paths.
Third-party connections should have identified owners and be periodically reviewed to determine whether they remain necessary.
Always understand where encryption starts and where it terminates. "The traffic is encrypted" is incomplete without knowing which parts of the communication path are protected.
End-to-end and hop-by-hop protection provide different trust models because intermediary systems may terminate protected sessions.
Cryptographic communication depends on secure key, certificate and trust management throughout the channel's lifecycle.
Secure communication also requires availability through capacity, redundancy, route diversity and fault monitoring.
The CISSP approach is to authenticate the communicating entities, protect the channel, restrict what the connection can reach, monitor its use and remove the connection when the business requirement ends.
π Sources & Further Reading Secure communications, remote access and network-security references
- ISC2 - CISSP Certification Exam Outline
View the current CISSP Exam Outline - NIST SP 800-46 Rev. 2 - Guide to Enterprise Telework, Remote Access, and Bring Your Own Device Security
View NIST remote-access guidance - NIST SP 800-77 Rev. 1 - Guide to IPsec VPNs
View NIST IPsec guidance - NIST SP 800-113 - Guide to SSL VPNs
View NIST remote VPN guidance - NIST SP 800-58 - Security Considerations for Voice Over IP Systems
View NIST VoIP security guidance - NIST SP 800-207 - Zero Trust Architecture
View NIST Zero Trust Architecture - NIST CSRC - Secure Channel
View NIST secure-channel terminology - RFC 9846 - The Transport Layer Security Protocol Version 1.3
View the current TLS 1.3 specification - RFC 4301 - Security Architecture for the Internet Protocol
View the IPsec architecture - RFC 4251 - The Secure Shell Protocol Architecture
View the SSH protocol architecture
