Depending on how you administer your server, that's not an acceptable suggestion.
I rely HEAVILY on HLSW which is an RCON application. I absolutely need RCON.
But yes, make sure you don't set your rcon password in your config file.
Some hosts don't let you change the command line, in which case you would have to set it in the config file, but do that at your own risk because there are plenty of exploits out there that grant users access to that file for viewing.