Require users to authenticate to enterprise-managed VPN and authentication services prior to accessing enterprise resources on end-user devices.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-12.7 | Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure | mitigates | T1021.006 | Windows Remote Management |
Comments
Adversaries may use WinRM for remote command execution and lateral movement. WinRM is not externally reachable and can only be accessed through authenticated enterprise VPN connectivity, directly restricting unauthorized remote WinRM sessions.
References
|
| CIS-12.7 | Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Adversaries use RDP for remote access or lateral movement into enterprise systems. RDP is inaccessible directly from external networks and reachable remotely only after authenticated VPN access through approved paths, directly preventing unauthenticated external RDP connectivity.
References
|
| CIS-12.7 | Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure | mitigates | T1659 | Content Injection |
Comments
Adversaries can inject malicious content into network traffic through a compromised or hostile upstream communication path. VPN integrity protection prevents unauthorized modification of enterprise-bound tunneled traffic, directly blocking injected content from becoming part of the protected session.
References
|
| CIS-12.7 | Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure | mitigates | T1557 | Adversary-in-the-Middle |
Comments
Adversaries positioned along the remote user's network path attempt to intercept or modify enterprise communications. An authenticated VPN tunnel provides confidentiality and integrity protection, directly preventing useful interception or alteration of tunneled traffic.
References
|
| CIS-12.7 | Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure | mitigates | T1040 | Network Sniffing |
Comments
Adversaries capture traffic traversing untrusted remote networks to obtain sensitive enterprise information. The enterprise VPN encrypts traffic between the endpoint and enterprise gateway, directly preventing passive observers from recovering protected traffic.
References
|
| CIS-12.7 | Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure | mitigates | T1133 | External Remote Services |
Comments
Adversaries can use externally accessible remote-access services to enter enterprise networks. Requiring remote devices to authenticate through an enterprise-managed VPN and centralized AAA confines remote access to a controlled gateway, directly eliminating unmanaged direct access paths.
References
|