Identities (users) are not prohibited (by organisational policy) from connecting to critical assets using unknown or unauthorised assets
Context and Guidance: In addition to logical and physical access controls (ACCESS-AP9), organisational policy should make it clear to personnel that they are prohibited from accessing critical assets using unknown or unauthorised assets.
An example of an unauthorised asset is an employee’s personal computer that is not managed by the function. Remote desktop access from an unauthorised asset should be considered when assessing this Anti-Pattern.
Note that by design, some platforms such as Microsoft Outlook Web Access are intended to be accessed on non-managed devices. Such use cases should not affect the assessment of this Anti-Pattern.