CCI-002397
CCI-002397 Definition
| Status | |
| Type | CheckType.technical |
Master Assessment Datasheet
Implementation Guidance
Determine if split tunneling is prevented for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using [SC-07(07)_ODP; safeguards to securely provision split tunneling are defined].
Validation Procedures
Examine: [SELECT FROM: System and communications protection policy; procedures addressing boundary protection; system design documentation; system hardware and software; system architecture; system configuration settings and associated documentation; system audit records; system security plan; other relevant documents or records]. Interview: [SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; system developer; organizational personnel with boundary protection responsibilities]. Test: [SELECT FROM: Mechanisms implementing boundary protection capabilities; mechanisms supporting/restricting non-remote connections].