AC.L2-3.1.13Remote Access Confidentiality
Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.
[a]
cryptographic mechanisms to protect the confidentiality of remote access sessions are identified; and[b]
cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented.
TLS 1.2+ and approved ciphers on every remote access path
Implementation
AO coverage. Addresses both Remote Access Confidentiality objectives.
Identified mechanisms. Remote paths use TLS 1.2+ (SaaS/IdP) or IPsec/IKE suites approved on the crypto inventory (VPN). TLS 1.0/1.1 disabled on terminators.
Implemented. VPN portal and gateways enforce the approved proposal. Published internal tools sit behind a reverse proxy with the same cipher policy; direct exposure is blocked.
Maintenance. Quarterly cipher scan of external listeners. After appliance upgrades, re-validate proposals on a canary gateway.
Accepted gap. A customer-mandated partner portal only offers older TLS. Staff use remote browser isolation from a PAW; no local client to that portal.
What the evidence looks like
- Crypto inventory entries for VPN and TLS terminators
- VPN crypto proposal / portal TLS config
- External TLS scan output
- Partner portal RBI exception
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.