NIST SP 800-53 Rev 5
AC - Access Control

NIST SP 800-53 Rev 5 NIST800-AC-17: AC-17 Remote Access

a. Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and b. Authorize each type of remote access to the system prior to allowing such connections.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 80 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 7 controls

  • AC-17 Remote Access
  • AC-17(1) Monitoring and Control
  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • AC-17(3) Managed Access Control Points
  • AC-17(4) Privileged Commands and Access
  • SC-7(4) External Telecommunications Services
  • SC-7(7) Split Tunneling for Remote Devices

FedRAMP Moderate · 7 controls

  • AC-17 Remote Access
  • AC-17(1) Monitoring and Control
  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • AC-17(3) Managed Access Control Points
  • AC-17(4) Privileged Commands and Access
  • SC-7(4) External Telecommunications Services
  • SC-7(7) Split Tunneling for Remote Devices

ISO 27701:2019 · 7 controls

  • 6.10 Communications security
  • 6.10.1 Network security management
  • 6.3.2 Mobile devices and teleworking
  • 6.6.2 User access management
  • 6.9.4 Logging and monitoring
  • 7.4.9 PII transmission controls
  • 8.4.3 PII transmission controls

PCI DSS 4.0 · 7 controls

  • 1.5.1 1.5.1 Security controls on dual-connected devices
  • 12.2.1 12.2.1 Rules for acceptable use of end-user technology
  • 2.2.7 2.2.7 Non-console administrative access encrypted
  • 3.4.2 3.4.2 Remote access blocks copying or relocating PAN
  • 8.2.3 8.2.3 Service provider unique factors per customer
  • 8.2.7 8.2.7 Third-party remote access accounts controlled
  • 8.4.3 8.4.3 MFA for remote access that could reach CDE

CMMC 2.0 · 5 controls

SOC 2 · 5 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • ASBv3-IM-9 Secure user access to existing applications
  • ASBv3-NS-9 Connect on-premises or cloud network privately
  • ASBv3-PA-6 Use privileged access workstations
  • IM-7 Restrict resource access based on conditions

ISO 27002:2022 · 4 controls

  • 6.7 Remote working
  • 7.9 Security of assets off-premises
  • 8.20 Networks security
  • 8.21 Security of network services

CIS Controls v8 · 3 controls

  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-6.4 Require MFA for Remote Network Access

ISO 27001:2022 · 3 controls

  • 5.15 Access control
  • 5.23 Information security for use of cloud services
  • 6.7 Remote working
  • ANSSI-HYG-13 Prefer Strong Authentication Where Possible
  • ANSSI-HYG-32 Secure the Network Connection of Devices Used for Mobile Working

C5 (Germany) · 2 controls

HIPAA Security Rule · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

UK Cyber Essentials · 2 controls

  • CE-FW.3 Block Unauthenticated Inbound Connections
  • CE-FW.6 Host-Based Firewall for Remote Workers
  • E8-MFA-ML1 Multi-Factor Authentication - Maturity Level 1

API 1164 · 1 control

  • API1164-07 Remote Access
  • ASD37-20 Multi-factor authentication (Essential)
  • SEC06-BP03 Reduce manual management and interactive access
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage

NIST SP 800-207 · 1 control

  • AC-17 AC-17 Remote Access
  • AC-17 AC-17 Remote Access
  • AC-17 AC-17 Remote Access

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in AC - Access Control

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-AC-17 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 80 it maps to, and the evidence behind each claim, over MCP and REST.