Check: SRC-EPT-620
SRC - Remote Endpoint:
SRC-EPT-620
(in version v2 r7)
Title
Remote users will be trained or given instructions on proper and authorized usage of the VPN client prior to accessing the DoD network. (Cat III impact)
Discussion
Without proper training, remote users may not completely understand the procedures for connecting to a DoD network remotely, which may result in a system compromise.
Check Content
Verify the existence of VPN client configuration and access procedures. Also, examine the site user training program to ensure VPN security procedures are included. Such items as local LAN access, split tunneling, and obtaining approval for configuration changes should be addressed in the training. If written VPN procedures do not exist, are inadequate, or are not provided to the users, this is a finding. If VPN security is not included in the training program, this is a finding.
Fix Text
Develop and distribute user instructions for the VPN client.
Additional Identifiers
Rule ID: SV-6821r1_rule
Vulnerability ID: V-6673
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |