Check: SRG-APP-000257-MAPP-NA
Mobile Application SRG:
SRG-APP-000257-MAPP-NA
(in version v1 r1)
Title
Applications providing remote connectivity must prevent remote devices that have established a non-remote connection with the system from communicating outside of the communications path with resources in external networks. (Cat II impact)
Discussion
This control enhancement is implemented within the remote device (e.g., notebook/laptop computer) via configuration settings that are not configurable by the user of that device. An example of a non-remote communications path from a remote device is a virtual private network. When a non-remote connection is established using a virtual private network, the configuration settings prevent split-tunneling. Split-tunneling might otherwise be used by remote users to communicate with the information system as an extension of that system and to communicate with local resources such as, a printer or file server. Since the remote device, when connected by a non-remote connection, becomes an extension of the information system, allowing dual communications paths such as split-tunneling would be, in effect, allowing unauthorized external connections into the system. Rationale for non-applicability: Mobile applications that support remote access are not within the scope of this SRG.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-46975r1_rule
Vulnerability ID: V-35688
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001111 |
The information system prevents remote devices that have established a non-remote connection with the system from communicating outside of that communications path with resources in external networks. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |