SC.L2-3.13.7 Split Tunneling
Prevent a remote device from holding a connection to organizational systems while simultaneously connecting through another path to external network resources, the split tunneling case.
3
artefacts
1
held by a system
1
at each review
moderate
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- VPN or remote client configuration disabling split tunneling · Cloud console / configuration management
periodic reviewEvidence produced at each review
- Evidence the setting is enforced and not user changeable · Document repository
governing documentDocuments that govern the control
- Coverage across all remote client platforms · Document repository
First move
Start with the 1 of 3 artefacts that already live in a system (Cloud console / configuration management); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Split tunneling disabled by policy but user configurable
- Some client platforms or vendor clients still permit it
- Exceptions granted for bandwidth with no compensating control
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetSC.L2-3.13.6 Network Communication by Exception · SC.L2-3.13.8 Data in Transit