In the 2022 Andor series, the Rebel network operates on strict need-to-know access. Operatives who break protocol lose their connection to the network entirely, not as punishment, but as operational necessity. If your credentials or your compliance are in question, the network shuts you out before you become the breach. That's exactly the model CIS Safeguard 13.5 asks you to build for your remote users.
What Is Manage Access Control for Remote Assets?
CIS Safeguard 13.5 is about making sure remote access is earned, not just granted. Before a device connects to your enterprise resources, it needs to prove it deserves to be there.
The official CIS text defines it this way:
Manage access control for assets remotely connecting to enterprise resources. Determine amount of access to enterprise resources based on: up-to-date anti-malware software installed, configuration compliance with the enterprise's secure configuration process, and ensuring the operating system and applications are up-to-date.
In plain terms: valid credentials are not enough. The device itself needs to pass inspection first.
Why It Matters
Remote workers are a fact of life. So are compromised endpoints. A laptop with outdated antivirus, a missing patch, or a misconfigured firewall is a liability, even if the person using it is a trusted employee.
When that device connects to your enterprise network, it carries its problems with it. Ransomware does not care that the user had the right password. Malware does not announce itself at the VPN gateway.
The business case is straightforward: unmanaged remote endpoints are one of the most common initial access vectors. You cannot afford to let good credentials carry bad devices.
Key Details or How It Works
- Posture assessment at connection time: Before granting access, the system checks whether the device meets minimum security requirements.
- Anti-malware compliance: Devices must have active, up-to-date endpoint protection installed and running.
- Configuration compliance: The device's security settings are validated against the enterprise's secure configuration baseline.
- OS and application patching: Unpatched systems are denied access or granted limited access until they come into compliance.
- Conditional access enforcement: Access levels are tiered based on how well the device meets the enterprise's requirements.
- Continuous validation: Compliance checks happen at connection time and can recur throughout active sessions.
How to Implement Manage Access Control for Remote Assets
- Define your minimum device health requirements. Start with the basics: active and updated anti-malware, OS patches current within a defined window (typically 30 days), and configuration settings aligned to your secure baseline. Write this down. Vague requirements do not get enforced.
- Deploy a Network Access Control or Endpoint Detection and Response solution with posture checking. Tools like Microsoft Intune, Cisco ISE, or similar platforms can evaluate device posture before and during connection. Without automated checking, this is just a policy that nobody enforces.
- Integrate posture checks with your VPN or Zero Trust Network Access solution. The access decision should happen at the point of entry. A device that fails posture should be redirected to remediation, not waved through on good faith.
- Tier your access levels based on compliance status. A fully compliant device gets full access. A device missing a patch might get read-only access to non-critical systems. A device with no antivirus gets nothing. Map this out in policy before you configure the controls.
- Set up automated remediation paths. When a device fails posture, it should know what to do next. A self-service remediation portal or automated patch push reduces helpdesk load and gets devices back into compliance faster.
- Audit and review regularly. Review which devices are failing posture checks and why. Patterns here are intelligence: they tell you where your patch management or configuration management processes are breaking down.
Final Thoughts
In Andor, the network does not trust you just because you show up. You have to prove you belong there, every time. That is not paranoia. That is how you keep the mission intact. Safeguard 13.5 is the same principle applied to your VPN gateway. Credentials get you to the door. Device posture determines whether the door opens.
Resources
Here is a link to the Policy Templates provided free of charge from the fine folks at the Center for Internet Security.
Looking for even more detail? Here you go. If this still does not satisfy your curiosity, DM me.
Official CIS Text
CIS Control 13: Network Monitoring and Defense Operate processes and tooling to establish and maintain comprehensive network monitoring and defense against security threats across the enterprise's network infrastructure and user base.
CIS Safeguard 13.5: Manage Access Control for Remote Assets Manage access control for assets remotely connecting to enterprise resources. Determine amount of access to enterprise resources based on: up-to-date anti-malware software installed, configuration compliance with the enterprise's secure configuration process, and ensuring the operating system and applications are up-to-date.
Shameless Marketing Information
Gotham Technology Group helps organizations implement Zero Trust and remote access controls that enforce policy, not just document it. If your VPN lets any device in as long as the credentials check out, let's talk.