risk
Remote-work, mobile and split-tunneling exposure
Uncontrolled work outside the premises, split-tunneling, and exploitation of mobile devices/personal systems outside physical and firewall protection expose information through insecure environments and reintroduce compromised devices into the enterprise.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Network & Communications Security
- Access Control & Identity Management
- Data Protection & Privacy
- taxonomy
- iso-27005-vulnerability
- nist-800-30-threat-event
- inherent_rating
- high
Details
- risk_id
- net-remote-work-mobile-exposure
- category
- cyber_security
- likelihood
- high
- impact
- medium
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- iso-27005-vulnerability
- nist-800-30-threat-event
Source
No record-specific source URL is provided.
Connections
- UC-HR-07 — Secure remote working arrangements mitigates Remote-work, mobile and split-tunneling exposure
- strength
- primary
- rationale
- a remote-working policy mandating device, physical, and communications safeguards directly reduces off-premises data and device exposure
- UC-NET-01 — Segment networks and defend the external boundary mitigates Remote-work, mobile and split-tunneling exposure
- strength
- primary
- rationale
- Mediating and monitoring all traffic at managed boundaries restricts unauthorized logical access reaching in from remote/mobile networks (mustKeep).
- UC-ACCESS-09 — Authenticate all users with multi-factor authentication mitigates Remote-work, mobile and split-tunneling exposure
- strength
- related
- rationale
- Enforced MFA for remote access reduces credential compromise from insecure off-premises environments.
- UC-ACCESS-10 — Authenticate devices and services before granting connections mitigates Remote-work, mobile and split-tunneling exposure
- strength
- related
- rationale
- Requiring verifiable device credentials to connect blocks reintroduction of untrusted or compromised devices.
- UC-NET-02 — Authorize and secure remote, wireless, and mobile access mitigates Remote-work, mobile and split-tunneling exposure
- strength
- primary
- rationale
- Explicit authorization, usage/connection restrictions, and encryption for each remote/wireless/mobile connection is the operative control for insecure remote and mobile access.