Prevent split tunneling for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using [organization-de
Scanned 9/3/2026
Install to Claude Code
npx -y skills add CyberStrikeus/CyberStrike --skill sc-7-7-split-tunneling-for-remote --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Sc 7 7 Split Tunneling For Remote?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/cyberstrikeus-sc-7-7-split-tunneling-for-remote)More formats (shields.io, HTML) on the badges page.
---
name: "SC-7(7)_split-tunneling-for-remote-devices"
description: "Prevent split tunneling for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using [organization-de"
category: "configuration"
version: "5.2.0"
author: "cyberstrike-official"
tags:
- nist
- sp800-53
- rev5
- sc-7-7
- sc
- enhancement
tech_stack:
- aws
- azure
- gcp
- linux
- windows
- network
cwe_ids:
- CWE-311
chains_with: []
prerequisites:
- SC-7
severity_boost: {}
---
# SC-7(7) Split Tunneling for Remote Devices
> **Enhancement of:** SC-7
## High-Level Description
**Family:** System and Communications Protection (SC)
**Framework:** NIST SP 800-53 Rev 5
Split tunneling is the process of allowing a remote user or device to establish a non-remote connection with a system and simultaneously communicate via some other connection to a resource in an external network. This method of network access enables a user to access remote devices and simultaneously, access uncontrolled networks. Split tunneling might be desirable by remote users to communicate with local system resources, such as printers or file servers. However, split tunneling can facilitate unauthorized external connections, making the system vulnerable to attack and to exfiltration of organizational information. Split tunneling can be prevented by disabling configuration settings that allow such capability in remote devices and by preventing those configuration settings from being configurable by users. Prevention can also be achieved by the detection of split tunneling (or of configuration settings that allow split tunneling) in the remote device, and by prohibiting the connection if the remote device is using split tunneling. A virtual private network (VPN) can be used to securely provision a split tunnel. A securely provisioned VPN includes locking connectivity to exclusive, managed, and named environments, or to a specific set of pre-approved addresses, without user control.
## What to Check
- [ ] Verify SC-7(7) Split Tunneling for Remote Devices is documented in SSP
- [ ] Confirm control is operating effectively
- [ ] Review evidence of continuous monitoring for SC-7(7)
- [ ] Verify enhancement builds upon base control SC-7
## How to Test
### Step 1: Review Documentation
Examine the System Security Plan (SSP) and related artifacts for SC-7(7) implementation details. Verify the organization has documented how this control is satisfied.
### Step 2: Validate Implementation
```
# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly
# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null
```
### Step 3: Test Operating Effectiveness
Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.
## Tools
| Tool | Purpose | Usage |
| --------------- | ------------------------------------- | ------------------------------------ |
| cloud-audit-mcp | Check encryption and network controls | `cloud_audit_encryption` |
| nmap | Network scanning | `nmap -sV --script ssl-enum-ciphers` |
## Remediation Guide
### Control Statement
Prevent split tunneling for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using [organization-defined].
### Implementation Guidance
Split tunneling is the process of allowing a remote user or device to establish a non-remote connection with a system and simultaneously communicate via some other connection to a resource in an external network. This method of network access enables a user to access remote devices and simultaneously, access uncontrolled networks. Split tunneling might be desirable by remote users to communicate with local system resources, such as printers or file servers. However, split tunneling can facilitate unauthorized external connections, making the system vulnerable to attack and to exfiltration of organizational information. Split tunneling can be prevented by disabling configuration settings that allow such capability in remote devices and by preventing those configuration settings from being configurable by users. Prevention can also be achieved by the detection of split tunneling (or of configuration settings that allow split tunneling) in the remote device, and by prohibiting the connection if the remote device is using split tunneling. A virtual private network (VPN) can be used to securely provision a split tunnel. A securely provisioned VPN includes locking connectivity to exclusive, managed, and named environments, or to a specific set of pre-approved addresses, without user control.
## Risk Assessment
| Finding | Severity | Impact |
| ---------------------------------------------------------- | -------- | ----------------------------------------------- |
| SC-7(7) Split Tunneling for Remote Devices not implemented | High | System and Communications Protection |
| SC-7(7) partially implemented | Medium | Incomplete System and Communications Protection |
## CWE Categories
| CWE ID | Title |
| ------- | ------------------------------------ |
| CWE-311 | Missing Encryption of Sensitive Data |
## References
- [NIST SP 800-53 Rev 5 - SC-7(7)](https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=sc-7.7)
- [NIST SP 800-53A Rev 5 (Assessment Procedures)](https://csrc.nist.gov/pubs/sp/800/53/a/r5/final)
- [NIST SP 800-53 Rev 5 Full Catalog](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final)
## Checklist
- [ ] Control documented in SSP
- [ ] Implementation evidence collected
- [ ] Operating effectiveness validated
- [ ] Continuous monitoring in place
- [ ] Related controls (none) reviewed
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!