Validate identity assurance
Review authentication, MFA, certificates, SSO and recovery paths that establish the remote identity.
Damocles Remote Access & VPN Security Review examines VPN and remote-access architecture, identity integration, MFA, certificates, pre-login, device trust, session controls, administrative access and the internal reach granted after connection.
Remote access can be strongly encrypted and still create excessive trust. Weak identity assurance, long-lived sessions, permissive device posture, broad internal routes or administrative access can turn one compromised account or unmanaged endpoint into a high-value foothold.
Damocles reviews the full remote-access path from authentication and client state through gateway policy, routing and internal access so the customer can see where trust is granted and whether the control matches the current threat model.
Review authentication, MFA, certificates, SSO and recovery paths that establish the remote identity.
Assess pre-login, posture, certificate and device conditions used before or during access.
Review the routes, zones, services and management access available after connection.
The review can cover workforce VPN, privileged remote access, third-party access or another defined remote-access service.
Externally reachable remote-access services, gateway design and service exposure.
SSO, directory integration, authentication sources and account lifecycle.
Multi-factor policy, bypass conditions, fallback and recovery paths.
User or device certificates, issuance, validation, lifetime and trust model where used.
Device identity, posture, pre-login and managed/unmanaged client distinctions.
Routes, zones, applications, management services and segmentation available after connection.
Review remote-access architecture, identity, device trust and post-connect controls to identify paths that could turn stolen credentials or an unmanaged device into internal access.
Identity checks, enrolment, recovery and bypass resistance.
Posture, certificates and managed-device controls.
Networks and services available after connection.
Separation of users, administrators, suppliers and sensitive systems.
Configuration, updates and exposed management services.
Certificate, secret and account issuance and revocation.
Session traceability and useful security events.
These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.
Damocles maps portals, gateways, identity providers, client paths, trust zones and downstream dependencies.
Damocles tests login, account enumeration, MFA enrolment and enforcement, recovery and bounded lockout behaviour with dedicated identities.
Damocles follows certificate and credential issue, storage, renewal, expiry and revocation for representative remote users or devices.
Damocles tests approved device trust and posture conditions and compares compliant and controlled non-compliant client outcomes.
Damocles reviews and observes VPN protocol, cipher, certificate and key-exchange configuration without disruptive downgrade testing.
Damocles records split-tunnel policy, assigned routes, DNS behaviour and unintended local or internet path interaction.
Showing 6 representative areas. The full governed matrix contains 12 coverage areas.
References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.
Testing is structured by the governed service profile and the procedures expressly included in the authorised scope.
Findings are reported against the governed service coverage and customer impact. Separate classification references are shown only where they are part of the approved profile.
The engagement produces point-in-time technical evidence about the configured and observed security behaviour within the authorised Remote access and VPN review scope.
A remote-access review with validated access paths, configuration evidence, prioritised remediation and validation results.
What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.
Damocles evaluates portal exposure, identity and MFA behaviour, client posture, cryptography, routing and post-connect access using supplied remote identities and configuration evidence. Availability testing, uncontrolled credential attempts and production changes are excluded.
Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.
Examines portal and gateway exposure, pre-authentication protocols and error behaviour.
Signs in with a dedicated identity and tests MFA, posture, routes, session access and revocation.
Correlates observed behaviour with gateway, certificate, identity, routing and logging configuration.
| Coverage area | What Damocles tests | Perspective and access | Evidence produced | References and limits |
|---|---|---|---|---|
| Remote-access architecture | Damocles maps portals, gateways, identity providers, client paths, trust zones and downstream dependencies. | Authenticated remote-access user or managed device Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for remote-access architecture. | Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to remote-access architecture. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Remote-access architecture when the remote-access path and representative identity or device are included. Limit: The conclusion is limited to the sampled remote-access architecture; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded. |
| Authentication and MFA | Damocles tests login, account enumeration, MFA enrolment and enforcement, recovery and bounded lockout behaviour with dedicated identities. | Authenticated remote-access user or managed device Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for authentication and MFA. | Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to authentication and MFA. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Authentication and MFA when the remote-access path and representative identity or device are included. Limit: The conclusion is limited to the sampled authentication and MFA; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded. |
| Certificate and credential lifecycle | Damocles follows certificate and credential issue, storage, renewal, expiry and revocation for representative remote users or devices. | Authenticated remote-access user or managed device, Portal, gateway and identity-configuration reviewer Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for certificate and credential lifecycle. | Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to certificate and credential lifecycle. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Certificate and credential lifecycle when the remote-access path and representative identity or device are included. Limit: The conclusion is limited to the sampled certificate and credential lifecycle; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded. |
| Client and device posture | Damocles tests approved device trust and posture conditions and compares compliant and controlled non-compliant client outcomes. | Authenticated remote-access user or managed device, Portal, gateway and identity-configuration reviewer Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for client and device posture. | Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to client and device posture. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Client and device posture when the remote-access path and representative identity or device are included. Limit: The conclusion is limited to the sampled client and device posture; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded. |
| VPN cryptographic configuration | Damocles reviews and observes VPN protocol, cipher, certificate and key-exchange configuration without disruptive downgrade testing. | Portal, gateway and identity-configuration reviewer Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for vpn cryptographic configuration. | Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to vpn cryptographic configuration. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to VPN cryptographic configuration when the remote-access path and representative identity or device are included. Limit: The conclusion is limited to the sampled vpn cryptographic configuration; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded. |
| Split tunnelling and routing | Damocles records split-tunnel policy, assigned routes, DNS behaviour and unintended local or internet path interaction. | Portal, gateway and identity-configuration reviewer Named source and destination test points, expected flow matrix and a safe test window. | Source-to-destination results linked to rule, route or boundary evidence. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing. Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity. |
| Post-connect segmentation | Damocles tests approved and denied post-connect destinations from a supplied remote client and records assigned identity and network context. | Authenticated remote-access user or managed device Named source and destination test points, expected flow matrix and a safe test window. | Source-to-destination results linked to rule, route or boundary evidence. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing. Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity. |
| Administrative access | Damocles examines portal and gateway administration paths, permitted sources, authentication and separation from user access. | Authenticated remote-access user or managed device Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for administrative access. | Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to administrative access. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Administrative access when the remote-access path and representative identity or device are included. Limit: The conclusion is limited to the sampled administrative access; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded. |
| Logging and session audit | Damocles traces representative authentication, session, access and revocation events into the supplied logging workflow. | Authenticated remote-access user or managed device Log-source inventory, representative event identifiers, workflow records and responsible contacts. | Source-health state, event timestamps, investigation timeline and linked action or escalation record. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when the relevant telemetry and analyst or customer workflow can be observed during the review window. Limit: Absent or delayed telemetry prevents a detection conclusion, and observation of one event cannot prove continuous detection of all attacks. |
| Third-party access | Damocles samples dedicated third-party identities for sponsorship, access, expiry, device requirements and revocation. | Authenticated remote-access user or managed device Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for third-party access. | Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to third-party access. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Third-party access when the remote-access path and representative identity or device are included. Limit: The conclusion is limited to the sampled third-party access; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded. |
| Availability dependencies | Damocles identifies identity, gateway, network, DNS, certificate and provider dependencies that affect remote-access availability. | Portal, gateway and identity-configuration reviewer Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for availability dependencies. | Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to availability dependencies. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Availability dependencies when the remote-access path and representative identity or device are included. Limit: The conclusion is limited to the sampled availability dependencies; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded. |
| Revocation and emergency change | Damocles validates account, certificate and session revocation and reviews emergency-change and restoration procedures. | Unauthenticated remote client Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for revocation and emergency change. | Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to revocation and emergency change. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Revocation and emergency change when the remote-access path and representative identity or device are included. Limit: The conclusion is limited to the sampled revocation and emergency change; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded. |
| Framework and controls | Mapping type | What Damocles assesses | Evidence produced | Applicability and limits |
|---|---|---|---|---|
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Framework-level context | Contextual | The engagement produces point-in-time technical evidence about the configured and observed security behaviour within the authorised Remote access and VPN review scope. | Coverage status, procedure results and findings can inform the customer’s control assessment and risk treatment records. | Applies: Framework-level context is provided when the customer uses NIST SP 800-53 to organise its security control program. Limit: No individual NIST control is published as verified; organisational implementation, continuous operation, governance and complete catalogue coverage remain outside the engagement. |
Assurance boundary: Damocles maps assessed coverage and observations to agreed objectives as traceable technical evidence. The review is not a certification, does not establish complete compliance, and does not confirm controls outside the authorised scope.
Records authorised scope and rules of engagement produced from the authorised Remote access and VPN review work.
Records coverage matrix produced from the authorised Remote access and VPN review work.
Records retest and residual-risk record produced from the authorised Remote access and VPN review work.
Records portal and gateway inventory produced from the authorised Remote access and VPN review work.
Records remote session and posture evidence produced from the authorised Remote access and VPN review work.
Records post-connect access results produced from the authorised Remote access and VPN review work.
A remote-access review with validated access paths, configuration evidence, prioritised remediation and validation results.
The review focuses on trust decisions and effective access rather than encryption settings alone.
Weak MFA coverage, bypass, legacy access or recovery paths that reduce authentication strength.
Remote access granted without the device trust, certificate or posture the risk model assumes.
Long-lived cookies, sessions or reconnect behaviour that exceed intended reauthentication policy.
Remote users receiving unnecessary routes or reach into sensitive and management networks.
Administrative paths available from standard remote-access contexts or poorly separated privileged users.
Vendor and contractor remote access with excessive duration, scope or weak lifecycle control.
The scope identifies portals, gateways, user groups, identity systems, client types and internal destination networks.
Review standard remote-user access, identity, device trust and internal reach.
Focus on administrator and high-privilege remote paths and their separation from standard access.
Review third-party identities, lifecycle, allowed systems, time windows and monitoring.
Define target architecture and transition controls for a new VPN or zero-trust remote-access design.
Findings are tied to identities, access groups, client conditions and internal destinations.
User groups, authentication paths, device conditions, gateways and internal access relationships.
MFA, certificate, recovery, legacy and authentication-path weaknesses.
Gaps in pre-login, posture, certificate or managed-device enforcement.
Broad routes, management paths and sensitive destination access that exceed the intended role.
Recommended identity, device and segmentation model where redesign is included.
Authentication and reachability tests for proving the new or remediated access model.
Implementation can include portal/gateway configuration, identity integration, certificates, group policy, routing, segmentation, client rollout and controlled transition from the existing service.
Change windows, rollback, user communications and validation are defined before production cutover.
Endpoint security, full identity penetration testing and broader internal segmentation can be added where the customer needs deeper assurance beyond the remote-access path.
Production configuration changes are not implied unless implementation is expressly included.
We will define the gateways, identity systems, client conditions, access groups, deliverables and redesign or implementation support required.