Remote access and VPN security review

Make remote access prove identity and device trust before it becomes an internal path.

Damocles Remote Access & VPN Security Review examines VPN and remote-access architecture, identity integration, MFA, certificates, pre-login, device trust, session controls, administrative access and the internal reach granted after connection.

VPN architectureIdentity and MFACertificates and device trustPost-connect access
Why customers buy this service

Validate the trust boundary around remote access.

Remote access can be strongly encrypted and still create excessive trust. Weak identity assurance, long-lived sessions, permissive device posture, broad internal routes or administrative access can turn one compromised account or unmanaged endpoint into a high-value foothold.

Damocles reviews the full remote-access path from authentication and client state through gateway policy, routing and internal access so the customer can see where trust is granted and whether the control matches the current threat model.

01

Validate identity assurance

Review authentication, MFA, certificates, SSO and recovery paths that establish the remote identity.

02

Validate device trust

Assess pre-login, posture, certificate and device conditions used before or during access.

03

Reduce post-connect reach

Review the routes, zones, services and management access available after connection.

What we review

Remote-access portals, gateways, identities, client controls and internal access in the agreed service.

The review can cover workforce VPN, privileged remote access, third-party access or another defined remote-access service.

GW

Portals and gateways

Externally reachable remote-access services, gateway design and service exposure.

ID

Identity integration

SSO, directory integration, authentication sources and account lifecycle.

MF

MFA

Multi-factor policy, bypass conditions, fallback and recovery paths.

CT

Certificates

User or device certificates, issuance, validation, lifetime and trust model where used.

DT

Device trust and pre-login

Device identity, posture, pre-login and managed/unmanaged client distinctions.

PA

Post-connect access

Routes, zones, applications, management services and segmentation available after connection.

Technical assurance

Validate secure access from remote users and devices.

Review remote-access architecture, identity, device trust and post-connect controls to identify paths that could turn stolen credentials or an unmanaged device into internal access.

Authentication and MFA

Identity checks, enrolment, recovery and bypass resistance.

Device trust

Posture, certificates and managed-device controls.

Post-connect access

Networks and services available after connection.

Segmentation

Separation of users, administrators, suppliers and sensitive systems.

Client and gateway security

Configuration, updates and exposed management services.

Credential lifecycle

Certificate, secret and account issuance and revocation.

Logging and response

Session traceability and useful security events.

12governed test areas
3authorised testing perspectives
6controlled evidence outputs
1framework / control evidence mappings
What we actually test

Representative technical coverage with the evidence produced.

These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.

Jump to full coverage matrix ↓
Coverage area

Remote-access architecture

Damocles maps portals, gateways, identity providers, client paths, trust zones and downstream dependencies.

Evidence producedEvidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to remote-access architecture.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Authentication and MFA

Damocles tests login, account enumeration, MFA enrolment and enforcement, recovery and bounded lockout behaviour with dedicated identities.

Evidence producedEvidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to authentication and MFA.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Certificate and credential lifecycle

Damocles follows certificate and credential issue, storage, renewal, expiry and revocation for representative remote users or devices.

Evidence producedEvidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to certificate and credential lifecycle.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Client and device posture

Damocles tests approved device trust and posture conditions and compares compliant and controlled non-compliant client outcomes.

Evidence producedEvidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to client and device posture.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

VPN cryptographic configuration

Damocles reviews and observes VPN protocol, cipher, certificate and key-exchange configuration without disruptive downgrade testing.

Evidence producedEvidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to vpn cryptographic configuration.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Split tunnelling and routing

Damocles records split-tunnel policy, assigned routes, DNS behaviour and unintended local or internet path interaction.

Evidence producedSource-to-destination results linked to rule, route or boundary evidence.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Showing 6 representative areas. The full governed matrix contains 12 coverage areas.

Standards and assurance coverage

See how this engagement is structured, classified and mapped before opening the full evidence matrix.

References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.

01 · Test method

How testing is structured

Testing is structured by the governed service profile and the procedures expressly included in the authorised scope.

02 · Finding language

How weaknesses and severity are classified

Findings are reported against the governed service coverage and customer impact. Separate classification references are shown only where they are part of the approved profile.

03 · Control evidence

What maps into compliance and assurance work

1governed evidence mapping across 1 approved framework, with framework-level context where exact controls are not claimed.
1 contextual
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Contextual
Framework-level context

The engagement produces point-in-time technical evidence about the configured and observed security behaviour within the authorised Remote access and VPN review scope.

Jump to full control mapping ↓
04 · Evidence package

What the customer can use after the engagement

A remote-access review with validated access paths, configuration evidence, prioritised remediation and validation results.

  • Authorised scope and rules of engagement
  • Coverage matrix
  • Retest and residual-risk record
  • + 3 additional controlled outputs

What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.

How we test

Manual validation backed by controlled evidence.

Damocles evaluates portal exposure, identity and MFA behaviour, client posture, cryptography, routing and post-connect access using supplied remote identities and configuration evidence. Availability testing, uncontrolled credential attempts and production changes are excluded.

How to read the mapping

Evidence is mapped to the part of a control we can actually assess.

Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.

All relevant frameworks
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Information Security Manual June 2026
Testing perspectives3 authorised viewpoints and access models

Unauthenticated remote client

Examines portal and gateway exposure, pre-authentication protocols and error behaviour.

Included when
Used for internet-facing remote-access entry points.
Access required
Approved hostnames, addresses and testing window.
Limitations
Cannot establish post-connect access.

Authenticated remote-access user or managed device

Signs in with a dedicated identity and tests MFA, posture, routes, session access and revocation.

Included when
Used for approved post-authentication behaviour.
Access required
Account, MFA, client or managed device and expected access.
Limitations
Applies only to that identity and device state.

Portal, gateway and identity-configuration reviewer

Correlates observed behaviour with gateway, certificate, identity, routing and logging configuration.

Included when
Used when configuration evidence is supplied.
Access required
Exports, policies, certificates, route assignments and session logs.
Limitations
Configuration does not prove every live client path.
Exact test coverage and evidence12 governed coverage areas
What Damocles tests, the evidence produced and the scope boundary for each controlled coverage area.
Coverage areaWhat Damocles testsPerspective and accessEvidence producedReferences and limits
Remote-access architectureDamocles maps portals, gateways, identity providers, client paths, trust zones and downstream dependencies.Authenticated remote-access user or managed device
Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for remote-access architecture.
Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to remote-access architecture.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Remote-access architecture when the remote-access path and representative identity or device are included.

Limit: The conclusion is limited to the sampled remote-access architecture; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded.

Authentication and MFADamocles tests login, account enumeration, MFA enrolment and enforcement, recovery and bounded lockout behaviour with dedicated identities.Authenticated remote-access user or managed device
Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for authentication and MFA.
Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to authentication and MFA.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Authentication and MFA when the remote-access path and representative identity or device are included.

Limit: The conclusion is limited to the sampled authentication and MFA; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded.

Certificate and credential lifecycleDamocles follows certificate and credential issue, storage, renewal, expiry and revocation for representative remote users or devices.Authenticated remote-access user or managed device, Portal, gateway and identity-configuration reviewer
Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for certificate and credential lifecycle.
Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to certificate and credential lifecycle.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Certificate and credential lifecycle when the remote-access path and representative identity or device are included.

Limit: The conclusion is limited to the sampled certificate and credential lifecycle; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded.

Client and device postureDamocles tests approved device trust and posture conditions and compares compliant and controlled non-compliant client outcomes.Authenticated remote-access user or managed device, Portal, gateway and identity-configuration reviewer
Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for client and device posture.
Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to client and device posture.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Client and device posture when the remote-access path and representative identity or device are included.

Limit: The conclusion is limited to the sampled client and device posture; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded.

VPN cryptographic configurationDamocles reviews and observes VPN protocol, cipher, certificate and key-exchange configuration without disruptive downgrade testing.Portal, gateway and identity-configuration reviewer
Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for vpn cryptographic configuration.
Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to vpn cryptographic configuration.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to VPN cryptographic configuration when the remote-access path and representative identity or device are included.

Limit: The conclusion is limited to the sampled vpn cryptographic configuration; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded.

Split tunnelling and routingDamocles records split-tunnel policy, assigned routes, DNS behaviour and unintended local or internet path interaction.Portal, gateway and identity-configuration reviewer
Named source and destination test points, expected flow matrix and a safe test window.
Source-to-destination results linked to rule, route or boundary evidence.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing.

Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity.

Post-connect segmentationDamocles tests approved and denied post-connect destinations from a supplied remote client and records assigned identity and network context.Authenticated remote-access user or managed device
Named source and destination test points, expected flow matrix and a safe test window.
Source-to-destination results linked to rule, route or boundary evidence.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing.

Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity.

Administrative accessDamocles examines portal and gateway administration paths, permitted sources, authentication and separation from user access.Authenticated remote-access user or managed device
Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for administrative access.
Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to administrative access.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Administrative access when the remote-access path and representative identity or device are included.

Limit: The conclusion is limited to the sampled administrative access; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded.

Logging and session auditDamocles traces representative authentication, session, access and revocation events into the supplied logging workflow.Authenticated remote-access user or managed device
Log-source inventory, representative event identifiers, workflow records and responsible contacts.
Source-health state, event timestamps, investigation timeline and linked action or escalation record.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when the relevant telemetry and analyst or customer workflow can be observed during the review window.

Limit: Absent or delayed telemetry prevents a detection conclusion, and observation of one event cannot prove continuous detection of all attacks.

Third-party accessDamocles samples dedicated third-party identities for sponsorship, access, expiry, device requirements and revocation.Authenticated remote-access user or managed device
Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for third-party access.
Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to third-party access.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Third-party access when the remote-access path and representative identity or device are included.

Limit: The conclusion is limited to the sampled third-party access; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded.

Availability dependenciesDamocles identifies identity, gateway, network, DNS, certificate and provider dependencies that affect remote-access availability.Portal, gateway and identity-configuration reviewer
Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for availability dependencies.
Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to availability dependencies.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Availability dependencies when the remote-access path and representative identity or device are included.

Limit: The conclusion is limited to the sampled availability dependencies; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded.

Revocation and emergency changeDamocles validates account, certificate and session revocation and reviews emergency-change and restoration procedures.Unauthenticated remote client
Assessment requires approved gateways, dedicated identities, MFA, test clients or devices, expected routes and configuration evidence, selected specifically for revocation and emergency change.
Evidence records the portal response, authentication decision, certificate, assigned route, session, log or post-connect result relevant to revocation and emergency change.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Revocation and emergency change when the remote-access path and representative identity or device are included.

Limit: The conclusion is limited to the sampled revocation and emergency change; results apply to supplied clients and identities; availability and uncontrolled credential testing are excluded.

Framework and control mappings1 governed evidence mappings
Where scoped technical evidence maps to approved security frameworks and control objectives.
Framework and controlsMapping typeWhat Damocles assessesEvidence producedApplicability and limits
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Framework-level context
ContextualThe engagement produces point-in-time technical evidence about the configured and observed security behaviour within the authorised Remote access and VPN review scope.Coverage status, procedure results and findings can inform the customer’s control assessment and risk treatment records.

Applies: Framework-level context is provided when the customer uses NIST SP 800-53 to organise its security control program.

Limit: No individual NIST control is published as verified; organisational implementation, continuous operation, governance and complete catalogue coverage remain outside the engagement.

Assurance boundary: Damocles maps assessed coverage and observations to agreed objectives as traceable technical evidence. The review is not a certification, does not establish complete compliance, and does not confirm controls outside the authorised scope.

Report and evidence outputs6 controlled output types

Authorised scope and rules of engagement

Records authorised scope and rules of engagement produced from the authorised Remote access and VPN review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Coverage matrix

Records coverage matrix produced from the authorised Remote access and VPN review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Retest and residual-risk record

Records retest and residual-risk record produced from the authorised Remote access and VPN review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Portal and gateway inventory

Records portal and gateway inventory produced from the authorised Remote access and VPN review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Remote session and posture evidence

Records remote session and posture evidence produced from the authorised Remote access and VPN review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Post-connect access results

Records post-connect access results produced from the authorised Remote access and VPN review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.
What you receive

A remote-access review with validated access paths, configuration evidence, prioritised remediation and validation results.

What we commonly find

Remote-access weaknesses that create a high-trust internal foothold.

The review focuses on trust decisions and effective access rather than encryption settings alone.

IA

Insufficient identity assurance

Weak MFA coverage, bypass, legacy access or recovery paths that reduce authentication strength.

UD

Unmanaged-device access

Remote access granted without the device trust, certificate or posture the risk model assumes.

PS

Persistent sessions

Long-lived cookies, sessions or reconnect behaviour that exceed intended reauthentication policy.

BA

Broad internal access

Remote users receiving unnecessary routes or reach into sensitive and management networks.

PA

Privileged remote access

Administrative paths available from standard remote-access contexts or poorly separated privileged users.

TP

Third-party trust

Vendor and contractor remote access with excessive duration, scope or weak lifecycle control.

Engagement options

Choose the workforce, privileged or third-party access path that needs review.

The scope identifies portals, gateways, user groups, identity systems, client types and internal destination networks.

Workforce
WF

Workforce VPN review

Review standard remote-user access, identity, device trust and internal reach.

Privileged
PR

Privileged remote-access review

Focus on administrator and high-privilege remote paths and their separation from standard access.

Third party
TP

Vendor and contractor access review

Review third-party identities, lifecycle, allowed systems, time windows and monitoring.

Migration
MG

Remote-access redesign or migration

Define target architecture and transition controls for a new VPN or zero-trust remote-access design.

What you receive

A remote-access trust model showing who can connect, from what device and what they can reach.

Findings are tied to identities, access groups, client conditions and internal destinations.

AM

Access model

User groups, authentication paths, device conditions, gateways and internal access relationships.

IF

Identity findings

MFA, certificate, recovery, legacy and authentication-path weaknesses.

DF

Device-trust findings

Gaps in pre-login, posture, certificate or managed-device enforcement.

AF

Access findings

Broad routes, management paths and sensitive destination access that exceed the intended role.

TA

Target access model

Recommended identity, device and segmentation model where redesign is included.

VR

Validation plan

Authentication and reachability tests for proving the new or remediated access model.

Implementation and remediation

Remote-access redesign and migration can be scoped separately from the assurance review.

Implementation can include portal/gateway configuration, identity integration, certificates, group policy, routing, segmentation, client rollout and controlled transition from the existing service.

Change windows, rollback, user communications and validation are defined before production cutover.

Scope boundaries

The review covers the approved remote-access service and supporting identity/network controls in scope.

Endpoint security, full identity penetration testing and broader internal segmentation can be added where the customer needs deeper assurance beyond the remote-access path.

Production configuration changes are not implied unless implementation is expressly included.

Scope the service

Give us the remote-access service, user groups, identity controls and internal destinations that need review.

We will define the gateways, identity systems, client conditions, access groups, deliverables and redesign or implementation support required.