Skip to content
ControlVerdict
AC.L2-3.1.13addresses
AC.L2-3.1.13Remote Access Confidentiality
Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.
  • [a]

    cryptographic mechanisms to protect the confidentiality of remote access sessions are identified; and
  • [b]

    cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented.

View full control

TLS 1.2+ and approved ciphers on every remote access path

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses both Remote Access Confidentiality objectives.

Identified mechanisms. Remote paths use TLS 1.2+ (SaaS/IdP) or IPsec/IKE suites approved on the crypto inventory (VPN). TLS 1.0/1.1 disabled on terminators.

Implemented. VPN portal and gateways enforce the approved proposal. Published internal tools sit behind a reverse proxy with the same cipher policy; direct exposure is blocked.

Maintenance. Quarterly cipher scan of external listeners. After appliance upgrades, re-validate proposals on a canary gateway.

Accepted gap. A customer-mandated partner portal only offers older TLS. Staff use remote browser isolation from a PAW; no local client to that portal.

What the evidence looks like

  • Crypto inventory entries for VPN and TLS terminators
  • VPN crypto proposal / portal TLS config
  • External TLS scan output
  • Partner portal RBI exception

Environment

SSO + GlobalProtect-class VPN; reverse proxies for any published internal tools.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.