Check: WN08-MO-000002
Windows 8/8.1 STIG:
WN08-MO-000002
(in versions v1 r23 through v1 r16)
Title
The VPN client on mobile devices must disable split tunneling. (Cat II impact)
Discussion
When split tunneling is enabled, device peripherals and other computers communicating with the mobile device may be able to connect to a DoD network and obtain sensitive information or otherwise compromise DoD information resources. Disabling split tunneling eliminates the risk associated with this vulnerability.
Check Content
Verify the VPN client on mobile devices is configured to prevent split tunneling for connections to DoD networks. If it is not, this is a finding. Procedures will vary depending on the VPN client used.
Fix Text
Configure the VPN client on mobile devices to prevent split tunneling when connecting to DoD networks. Procedures will vary depending on the VPN client used.
Additional Identifiers
Rule ID: SV-48427r2_rule
Vulnerability ID: V-36753
Group Title: WN08-MO-000002
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |