Remote Access

✓ LOW ✓ MODERATE ✓ HIGH
7 Enhancements 1 Overlay 19 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

Remote access is access to organizational systems (or processes acting on behalf of users) that communicate through external networks such as the Internet. Types of remote access include dial-up, broadband, and wireless. Organizations use encrypted virtual private networks (VPNs) to enhance confidentiality and integrity for remote connections. The use of encrypted VPNs provides sufficient assurance to the organization that it can effectively treat such connections as internal networks if the cryptographic mechanisms used are implemented in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Still, VPN connections traverse external networks, and the encrypted VPN does not enhance the availability of remote connections. VPNs with encrypted tunnels can also affect the ability to adequately monitor network communications traffic for malicious code. Remote access controls apply to systems other than public web servers or systems designed for public access. Authorization of each remote access type addresses authorization prior to allowing remote access without specifying the specific formats for such authorization. While organizations may use information exchange and system connection security agreements to manage remote access connections to other systems, such agreements are addressed as part of CA-3 . Enforcing access restrictions for remote access is addressed via AC-3.

Enhancements NIST SOURCE

AC-17(1) Monitoring and Control LOW ✓ MODERATE ✓ HIGH

Employ automated mechanisms to monitor and control remote access methods.

Discussion

Monitoring and control of remote access methods allows organizations to detect attacks and help ensure compliance with remote access policies by auditing the connection activities of remote users on a variety of system components, including servers, notebook computers, workstations, smart phones, and tablets. Audit logging for remote access is enforced by AU-2 . Audit events are defined in AU-2a.

Open full page for AC-17(1) →
AC-17(2) Protection of Confidentiality and Integrity Using Encryption LOW ✓ MODERATE ✓ HIGH

Implement cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.

Discussion

Virtual private networks can be used to protect the confidentiality and integrity of remote access sessions. Transport Layer Security (TLS) is an example of a cryptographic protocol that provides end-to-end communications security over networks and is used for Internet communications and online transactions.

Open full page for AC-17(2) →
AC-17(3) Managed Access Control Points LOW ✓ MODERATE ✓ HIGH

Route remote accesses through authorized and managed network access control points.

Discussion

Organizations consider the Trusted Internet Connections (TIC) initiative DHS TIC requirements for external network connections since limiting the number of access control points for remote access reduces attack surfaces.

Open full page for AC-17(3) →
AC-17(4) Privileged Commands and Access LOW ✓ MODERATE ✓ HIGH
  1. (a) Authorize the execution of privileged commands and access to security-relevant information via remote access only in a format that provides assessable evidence and for the following needs: [organization-defined needs] ; and
  2. (b) Document the rationale for remote access in the security plan for the system.
Discussion

Remote access to systems represents a significant potential vulnerability that can be exploited by adversaries. As such, restricting the execution of privileged commands and access to security-relevant information via remote access reduces the exposure of the organization and the susceptibility to threats by adversaries to the remote access capability.

Open full page for AC-17(4) →
AC-17(5) Monitoring for Unauthorized Connections WITHDRAWN

Withdrawn. Incorporated into SI-4.

AC-17(6) Protection of Mechanism Information LOW MODERATE HIGH

Protect information about remote access mechanisms from unauthorized use and disclosure.

Discussion

Remote access to organizational information by non-organizational entities can increase the risk of unauthorized use and disclosure about remote access mechanisms. The organization considers including remote access requirements in the information exchange agreements with other organizations, as applicable. Remote access requirements can also be included in rules of behavior (see PL-4 ) and access agreements (see PS-6).

Open full page for AC-17(6) →
AC-17(7) Additional Protection for Security Function Access WITHDRAWN

Withdrawn. Incorporated into AC-3(10).

AC-17(8) Disable Nonsecure Network Protocols WITHDRAWN

Withdrawn. Incorporated into CM-7.

AC-17(9) Disconnect or Disable Access LOW MODERATE HIGH

Provide the capability to disconnect or disable remote access to the system within [time period].

Discussion

The speed of system disconnect or disablement varies based on the criticality of missions or business functions and the need to eliminate immediate or future remote access to systems.

Open full page for AC-17(9) →
AC-17(10) Authenticate Remote Commands LOW MODERATE HIGH

Implement [mechanisms] to authenticate [remote commands].

Discussion

Authenticating remote commands protects against unauthorized commands and the replay of authorized commands. The ability to authenticate remote commands is important for remote systems for which loss, malfunction, misdirection, or exploitation would have immediate or serious consequences, such as injury, death, property damage, loss of high value assets, failure of mission or business functions, or compromise of classified or controlled unclassified information. Authentication mechanisms for remote commands ensure that systems accept and execute commands in the order intended, execute only authorized commands, and reject unauthorized commands. Cryptographic mechanisms can be used, for example, to authenticate remote commands.

Open full page for AC-17(10) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for AC-17 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. usage restrictions are established and documented for each type of remote access allowed;
  2. configuration/connection requirements are established and documented for each type of remote access allowed;
  3. implementation guidance is established and documented for each type of remote access allowed;
  4. each type of remote access to the system is authorized prior to allowing such connections.

Examine

[SELECT FROM: Access control policy; procedures addressing remote access implementation and usage (including restrictions); configuration management plan; system configuration settings and associated documentation; remote access authorizations; system audit records; system security plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with responsibilities for managing remote access connections; system/network administrators; organizational personnel with information security responsibilities].

Test

[SELECT FROM: Remote access management capability for the system].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)
  • Added: (9)

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (1) (2) (3) (4)
  • Added: (9) (10)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (1) (2) (3) (4)
  • Added: (9) (10)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for AC-17. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Access control policy
  • system security plan

Configuration

  • configuration management plan
  • system configuration settings and associated documentation

Testing

  • Remote access management capability for the system

Other Records

  • procedures addressing remote access implementation and usage (including restrictions)
  • remote access authorizations
  • system audit records
  • other relevant documents or records