You can set an access-list with networks that are allowed to pass the VPN connection. By using the 'crypto map <#> match address ' it will be related to the VPN session of your choice.
The other side of the connection requires a similar (but mirrored) access-list.
I hope this answers your question.