Implementation examples
7 examples referencing VPN
- SC.L2-3.13.9[a] [b] [c]
Inactivity windows defined per connection type: 15 minutes for admin sessions, 12 hours for VPN
AO coverage. Addresses all three Connections Termination objectives: defining the inactivity period, terminating at end of session, and terminating after the defined inactivity period. Defined…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - SC.L2-3.13.7[a]
Always-on full tunnel with local LAN access and NIC bridging disabled in client policy
AO coverage. Addresses the single Split Tunneling objective for managed endpoints that can reach CUI. Client posture. The VPN profile is deployed by MDM, set to always-on with user-logon connect, and…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.14[a] [b]
All remote paths land on managed VPN or IdP — no direct RDP to enclave
AO coverage. Addresses both Remote Access Routing objectives. Control points. Internet users reach CUI only via (1) IdP SSO to SaaS or (2) full-tunnel VPN into the lab VRF. Edge firewall denies…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.11[a] [b]
Idle and max session lifetimes on VPN and SSO
AO coverage. Addresses both Session Termination objectives. VPN. Idle disconnect ≤12 hours; absolute session lifetime forces re-auth. Concurrent sessions limited to one unless ticketed. SSO. IdP…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.8[a] [b]
Smart lockout on IdP and VPN; no endless password spray
AO coverage. Addresses both Unsuccessful Logon Attempts objectives. Thresholds. IdP smart lockout after repeated failures (org baseline: lock after sustained failures within a window, with…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.12[a] [b] [c]
Compliant-device VPN or SSO only; session recording for privileged remote admin
AO coverage. Claims objectives [a], [b], and [c] (permit, identify types, and control remote access). Objective [d] (monitor sessions) is only partially covered here: VPN connect/disconnect and…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - IA.L2-3.5.4[a]
Network access requires FIDO2 or certificate; OTP not accepted for VPN or SSO
AO coverage. Addresses all replay-resistant authentication objectives for this practice. Policy. Authentication strength for all CUI applications and the VPN requires a phishing-/replay-resistant…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet