and I want to secure sensitive documents, what general considerations should I apply?
Is ssh enough?
These would be documents that need to be accessed by people inside and outside of the company, so the options seem to be, put them on an FTP server, or give everyone VPN access and create accounts for them all. This may not be a practical option, depending on the number of people.
Of course, some middle ground would be to create a single VPN/Network user for the external group, and keep it inside the firewall.
*Ponders* |