1Overview
SC.L2-3.13.7 closes the split-tunneling gap for remote devices. It requires that remote devices be prevented from simultaneously establishing a non-remote connection with organizational systems and communicating via some other connection to external networks, so that a remote device cannot bridge the organization's network to the outside. It is a one-point requirement and may be deferred on a plan of action.
When a remote device is connected to the organization's network and at the same time to an external network, it can become a bridge between the two, letting external traffic reach the internal network through the device. This split-tunneling condition undermines the boundary protections the organization relies on. This control requires preventing that simultaneous configuration, so a device connected to organizational systems routes through the organization's protections rather than tunneling around them. The single assessment objective is that split tunneling is prevented.
Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).
The requirement is to prevent the split-tunneling condition: a remote device holding a connection into organizational systems while also communicating to external networks by another path. Preventing it means the remote connection is configured so that the device's traffic to external resources does not bypass the organization's network protections, typically by forcing all traffic through the organization's controlled path while the remote connection is active.
2The Assessment Objective
NIST SP 800-171A frames 3.13.7 as a single objective: prevent split tunneling.
Remote devices are prevented from simultaneously establishing a non-remote connection with the system and communicating via some other connection to external networks (split tunneling). Remote devices cannot bridge internal and external networks.
The single objective is preventing split tunneling. The common gap is remote-access configurations that permit local internet access while connected, leaving the bridge open. The assessor looks for configuration that prevents the simultaneous condition.
3Failure Patterns
The failures are about remote devices bridging networks.
Split tunneling allowed by default
Remote-access configurations that let a connected device also use its local internet connection leave the split-tunnel path open. Forcing traffic through the organization's path prevents it.
Configuration not enforced on devices
A policy against split tunneling that devices do not actually enforce leaves the condition possible. The prevention has to be enforced in the remote-access configuration.
Inconsistent across remote access methods
Preventing split tunneling on one remote-access method but not others leaves gaps. The prevention has to cover the remote access in use.
4Ownership
This is a network and IT-owned control tied to remote access configuration.
| Role | Responsibility for this control |
|---|---|
| Network and IT | Configures remote access to prevent split tunneling. Owns the remote-access configuration. |
| Security or compliance lead | Confirms the prevention is enforced across remote access methods. |
| Program lead | Documents the remote access configuration. |
5Tooling
The control is delivered by remote-access configuration that forces traffic through the controlled path.
| Objective | Tooling | What it provides |
|---|---|---|
| — | VPN full-tunnel configuration | All remote traffic routed through the organization's protections. |
| — | Endpoint remote-access policy enforcement | The split-tunnel condition prevented on the device. |
The caveat is that the prevention has to be enforced in configuration, not just stated in policy, and cover the remote access in use. A device that can still split-tunnel despite policy leaves the bridge open. The assessor examines whether split tunneling is prevented, so the configuration has to enforce it.
6Evidence
The satisfied version of 3.13.7 shows remote access that prevents split tunneling.
| Evidence | What it demonstrates |
|---|---|
| Remote access configuration | The objective. Split tunneling prevented. |
| Endpoint policy enforcement | The objective. The prevention enforced on devices. |
The evidence should show remote-access configuration that prevents a device from bridging internal and external networks. The remote access configuration and endpoint enforcement are the clearest demonstration of the control.
A remote device should not bridge inside and outside
Split tunneling turns a connected remote device into a path around your boundary protections, so this control asks that the simultaneous condition be prevented. Configuring remote access to keep traffic inside the controlled path is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.7. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.13.7. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov