Security Best Practices

6 min read Updated Sep 23, 2026

Introduction

This guide provides security best practices for deploying and using GuacamoleID. Following these recommendations helps ensure maximum protection for your devices and sensitive data.

Authentication Security

Face Profile Best Practices

Creating Strong Profiles

  1. Good Lighting: Register profiles in well-lit conditions
  2. Multiple Angles: Look slightly left, right, up, down during registration
  3. Consistent Expression: Use a neutral expression
  4. Remove Obstructions: Take off sunglasses, move hair from face

Profile Management

  1. Multiple Profiles: Create profiles for different lighting conditions
  2. Regular Updates: Re-register if appearance changes significantly
  3. IR When Available: IR profiles are more secure and reliable
  4. Limit Profile Count: Only create necessary profiles

Profile Security

  1. Don't Share Profiles: Each user should have their own profiles
  2. Protect Registration: Register in private, secure locations
  3. Review Periodically: Audit profile list for unauthorized additions
  4. Secure Backup: If using cloud sync, ensure account security

Anti-Spoofing Configuration

Environment Minimum Level Recommended Level
Home/Personal Passive Passive
Office Passive Active
High Security Active Depth Vision
Financial/Healthcare Depth Vision Depth Vision

Anti-Spoofing Guidelines

  1. Never Disable: Always have at least Passive enabled
  2. Use Depth When Available: IR cameras provide best protection
  3. Test Periodically: Verify anti-spoofing is working
  4. Monitor Logs: Watch for spoofing attempts

Block Screen Security

Configuration Recommendations

Blocking Speed

Risk Level Recommended Speed
Low Risk Medium
Standard Fast
High Risk Very Fast

Block Screen Options

  1. Key Press to Windows Lock: Always enabled
  2. Camera Preview: Consider disabling in high-security environments
  3. Registration Button: Disable in high-security deployments
  4. Custom Background: Avoid showing sensitive information

Physical Security Integration

  1. Screen Position: Face away from windows and common areas
  2. Privacy Filters: Use physical privacy screen filters
  3. Camera Coverage: Ensure camera sees anyone approaching
  4. Clean Desk Policy: Lock screen when leaving

Device Security

Device Configuration

  1. Full Disk Encryption: Enable BitLocker or equivalent
  2. BIOS Password: Prevent unauthorized boot changes
  3. Secure Boot: Enable secure boot in BIOS
  4. Firmware Updates: Keep BIOS/UEFI current

Software Security

  1. Windows Updates: Enable automatic updates
  2. Antivirus: Use enterprise-grade protection
  3. Firewall: Enable Windows Firewall or better
  4. Application Updates: Keep GuacamoleID updated

Network Security

  1. VPN: Use VPN on untrusted networks
  2. WiFi Security: Only connect to secure networks
  3. Network Monitoring: Enable network protection features
  4. Remote Access: Secure any remote access methods

Account Security

Web Portal Security

  1. Strong Password: Use complex, unique password
  2. Two-Factor Authentication: Enable 2FA if available
  3. Session Management: Log out when finished
  4. Secure Access: Only access from trusted devices

Password Guidelines

Requirement Minimum Recommended
Length 8 characters 12+ characters
Complexity Mixed case + numbers Mixed case + numbers + symbols
Uniqueness Unique to GuacamoleID Unique + password manager
Change Frequency Annually Every 6 months

Account Recovery

  1. Recovery Email: Keep recovery email secure and current
  2. Security Questions: Use strong, non-guessable answers
  3. Backup Codes: Store recovery codes securely
  4. Contact Info: Keep phone/email updated

Organizational Security

Deployment Security

  1. Secure Distribution: Use signed installers
  2. Configuration Management: Deploy with secure defaults
  3. License Security: Protect license keys
  4. Enrollment Process: Secure device enrollment

Policy Recommendations

Mandatory Policies

Policy Recommended Setting
Anti-Spoofing At least Passive
Block Screen Enabled
Auto-Lock 5 minutes maximum
Password Fallback Enabled

Role-Based Access

  1. Least Privilege: Grant minimum necessary access
  2. Regular Review: Audit permissions quarterly
  3. Separation of Duties: Distribute admin responsibilities
  4. Access Logging: Enable comprehensive logging

User Training

Essential training topics:

  1. How face recognition works
  2. Importance of anti-spoofing
  3. Recognizing security threats
  4. Reporting security incidents
  5. Privacy and compliance

Data Protection

Biometric Data Security

  1. Encryption: Biometric data is encrypted at rest
  2. Local Processing: Recognition happens on-device
  3. Minimal Storage: Only necessary data retained
  4. Secure Transmission: Encrypted cloud sync

Privacy Considerations

  1. Inform Users: Explain what data is collected
  2. Consent: Obtain proper consent for biometrics
  3. Data Retention: Follow retention policies
  4. Data Deletion: Honor deletion requests

Compliance

Regulatory Frameworks

GuacamoleID can help with compliance for:

  • HIPAA: Healthcare data protection
  • PCI-DSS: Payment card security
  • SOC 2: Security controls
  • GDPR: Data protection (EU)
  • CCPA: Consumer privacy (California)
  • BIPA: Biometric information (Illinois)

Documentation Requirements

Maintain documentation of:

  1. Security policies and configurations
  2. User consent records
  3. Access logs and audit trails
  4. Incident response procedures
  5. Training completion records

Incident Response

Preparing for Incidents

  1. Define Procedures: Document response steps
  2. Assign Roles: Identify response team
  3. Communication Plan: Know who to notify
  4. Testing: Practice incident response

Responding to Security Events

Unauthorized Access Attempt

  1. Review authentication logs
  2. Identify the source/method
  3. Strengthen affected controls
  4. Document the incident
  5. Report per policy

Spoofing Attack Detected

  1. Increase anti-spoofing level
  2. Review affected profiles
  3. Check for successful bypasses
  4. Investigate attack source
  5. Update security measures

Lost or Stolen Device

  1. Remote lock/wipe if possible
  2. Disable device in portal
  3. Revoke associated sessions
  4. Change related passwords
  5. Monitor for unauthorized access

Post-Incident Actions

  1. Root Cause Analysis: Understand what happened
  2. Remediation: Fix vulnerabilities
  3. Documentation: Record the incident
  4. Communication: Notify stakeholders
  5. Prevention: Implement improvements

Monitoring and Auditing

What to Monitor

Category Metrics
Authentication Success/failure rates, patterns
Anti-Spoofing Spoofing attempts, blocks
Access Who accessed what, when
Compliance Policy violations

Log Retention

Log Type Minimum Retention Recommended
Authentication 90 days 1 year
Security Events 1 year 2 years
Admin Actions 1 year 3 years
Compliance Per regulation Per regulation

Regular Audits

Monthly Reviews

  • Review failed authentication attempts
  • Check for unusual patterns
  • Verify security settings
  • Update as needed

Quarterly Reviews

  • Full security configuration audit
  • User access review
  • Policy compliance check
  • Training status update

Annual Reviews

  • Comprehensive security assessment
  • Policy updates
  • Risk assessment
  • Vendor security review

Security Checklist

Initial Deployment

  • [ ] Install latest version
  • [ ] Enable anti-spoofing (Passive minimum)
  • [ ] Configure block screen settings
  • [ ] Set appropriate auto-lock timeout
  • [ ] Enable Windows password fallback
  • [ ] Create face profiles in good conditions
  • [ ] Verify all features working

Regular Maintenance

  • [ ] Check for software updates
  • [ ] Review authentication logs
  • [ ] Audit user access
  • [ ] Verify backup/recovery works
  • [ ] Test anti-spoofing effectiveness
  • [ ] Update profiles if appearance changed

High-Security Environments

  • [ ] Enable Depth Vision anti-spoofing
  • [ ] Set Very Fast blocking speed
  • [ ] Disable block screen registration
  • [ ] Enable comprehensive logging
  • [ ] Implement network segmentation
  • [ ] Regular penetration testing
  • [ ] Continuous monitoring

Additional Resources

Security Documentation

  • NIST Cybersecurity Framework
  • CIS Controls
  • ISO 27001 Standards
  • Industry-specific guidelines

Training Resources

  • GuacamoleID security training
  • Security awareness programs
  • Phishing simulation
  • Incident response drills

Support Contacts

  • Security issues: security@guacamole.ai
  • General support: support@guacamole.ai
  • Documentation: docs.guacamole.ai