Secure Controls Framework

1,534 controls across 34 domains

Source: SCF 2026.2About SCF
securecontrolsframework.com
Back to catalog
CFG-03.4CFGConfiguration Management

Split Tunneling

Description

Mechanisms exist to prevent split tunneling for remote devices unless the split tunnel is securely provisioned using organization-defined safeguards.

Cross-Mappings

13 paths across 4 frameworks
NIST 800-531 mapping
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
NIST 800-1711 mapping
3.13.7
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI2 mappings
CCI-002397
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004873
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
STIG7 mappings
SV-207243r1005432_ruleThe VPN Gateway must disable split-tunneling for remote clients VPNs.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-214695r856579_ruleThe Juniper SRX Services Gateway VPN must disable split-tunneling for remote clients VPNs.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · V3R2 · disa_xccdf · related
SV-239982r1005432_ruleThe Cisco ASA VPN remote access server must be configured to disable split-tunneling for remote clients.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · V2R2 · disa_xccdf · related
SV-258596r1005432_ruleThe ICS must be configured to disable split-tunneling for remote client VPNs.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · V2R2 · disa_xccdf · related
SV-258596r930476_ruleThe ICS must be configured to disable split-tunneling for remote client VPNs.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 2 · disa_xccdf · related
SV-266644r1040422_ruleAOS, in conjunction with a remote device, must prevent the device from simultaneously establishing nonremote connections with the system and communicating via some other connection to resources in external networks.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 1 · disa_xccdf · related
SV-267000r1040766_ruleAOS, when used as a VPN Gateway, must disable split-tunneling for remote client VPNs.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · V1R1 · disa_xccdf · related

Control mappings provided by the Secure Controls Framework (SCF).

SCF

Powered by the Secure Controls Framework

The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.

© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer