Skip to content
ControlVerdict
AC.L2-3.1.14addresses
AC.L2-3.1.14Remote Access Routing
Route remote access via managed access control points.
  • [a]

    managed access control points are identified and implemented; and
  • [b]

    remote access is routed through managed network access control points.

View full control

All remote paths land on managed VPN or IdP — no direct RDP to enclave

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses both Remote Access Routing objectives.

Control points. Internet users reach CUI only via (1) IdP SSO to SaaS or (2) full-tunnel VPN into the lab VRF. Edge firewall denies inbound RDP/SMB from the Internet to enclave subnets.

Routing. VPN terminates on managed concentrators; split tunnel disabled for CUI routes. Admin remote work uses the same VPN then a jump host — not a public jump IP.

Maintenance. Quarterly firewall rule review for accidental publish. Continuous monitoring for new listeners on enclave VLANs.

Accepted gap. A facilities vendor needs a temporary camera VPN. It uses a separate non-CUI VRF with no route to the enclave.

What the evidence looks like

  • Firewall rules denying inbound RDP/SMB to enclave
  • VPN topology showing managed termination points
  • Route table / VRF diagram for CUI vs facilities

Environment

Hybrid lab + SaaS; remote staff.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.