CIS Controls CIS-12.7

Require users to authenticate to enterprise-managed VPN and authentication services prior to accessing enterprise resources on end-user devices.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure mitigates T1021.006 Windows Remote Management
Comments
Adversaries may use WinRM for remote command execution and lateral movement. WinRM is not externally reachable and can only be accessed through authenticated enterprise VPN connectivity, directly restricting unauthorized remote WinRM sessions.
References
CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure mitigates T1021.001 Remote Desktop Protocol
Comments
Adversaries use RDP for remote access or lateral movement into enterprise systems. RDP is inaccessible directly from external networks and reachable remotely only after authenticated VPN access through approved paths, directly preventing unauthenticated external RDP connectivity.
References
CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure mitigates T1659 Content Injection
Comments
Adversaries can inject malicious content into network traffic through a compromised or hostile upstream communication path. VPN integrity protection prevents unauthorized modification of enterprise-bound tunneled traffic, directly blocking injected content from becoming part of the protected session.
References
CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure mitigates T1557 Adversary-in-the-Middle
Comments
Adversaries positioned along the remote user's network path attempt to intercept or modify enterprise communications. An authenticated VPN tunnel provides confidentiality and integrity protection, directly preventing useful interception or alteration of tunneled traffic.
References
CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure mitigates T1040 Network Sniffing
Comments
Adversaries capture traffic traversing untrusted remote networks to obtain sensitive enterprise information. The enterprise VPN encrypts traffic between the endpoint and enterprise gateway, directly preventing passive observers from recovering protected traffic.
References
CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure mitigates T1133 External Remote Services
Comments
Adversaries can use externally accessible remote-access services to enter enterprise networks. Requiring remote devices to authenticate through an enterprise-managed VPN and centralized AAA confines remote access to a controlled gateway, directly eliminating unmanaged direct access paths.
References