From the perspective of who manages security audits for global corporations, you have a few options, but first:
Enlighten your senior RDP and FTP risk leadership - it must be their challenge, whether you continue to use them and accept the risk, reduce the risk with additional security controls or replace them with something completely different
Then your options are:
- Raise the exception in the Risk Register - senior management accepts it
- According to @Flimzy - starting a VPN on your remote sites makes the best sense from a technical point of view: you can continue to use FTP, RDP, regardless of what is known about security problems, because you provide a layer of strong security (VPN)
- Replace RDP and FTP with more secure connection mechanisms.
I would definitely not go down the road trying to trick a security audit - all it does is a sobering top management, thinking there are no problems, and may come back to bite you in various costly ways, possibly including personal responsibility!
source share