# AC-17 Remote Access

NIST SP 800-53 control. Family: AC Access Control. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and b. Authorize each type of remote access to the system prior to allowing such connections.
Guidance: Remote access is access to organizational systems (or processes acting on behalf of users) that communicate through external networks such as the Internet. Types of remote access include dial-up, broadband, and wireless. Organizations use encrypted virtual private networks (VPNs) to enhance confidentiality and integrity for remote connections. The use of encrypted VPNs provides sufficient assurance to the organization that it can effectively treat such connections as internal networks if the cryptographic mechanisms used are implemented in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Still, VPN connections traverse external networks, and the encrypted VPN does not enhance the availability of remote connections. VPNs with encrypted tunnels can also affect the ability to adequately monitor network communications traffic for malicious code. Remote access controls apply to systems other than public web servers or systems designed for public access. Authorization of each remote access type addresses authorization prior to allowing remote access without specifying the specific formats for such authorization. While organizations may use information exchange and system connection security agreements to manage remote access connections to other systems, such agreements are addressed as part of CA-03. Enforcing access restrictions for remote access is addressed via AC-03.

## Enhancements (7)
- AC-17(01) Monitoring and Control. Baselines: moderate, high
- AC-17(02) Protection of Confidentiality and Integrity Using Encryption. Baselines: moderate, high
- AC-17(03) Managed Access Control Points. Baselines: moderate, high
- AC-17(04) Privileged Commands and Access. Baselines: moderate, high
- AC-17(06) Protection of Mechanism Information
- AC-17(09) Disconnect or Disable Access
- AC-17(10) Authenticate Remote Commands
Withdrawn by NIST: AC-17(05) (now in SI-04); AC-17(07) (now in AC-03(10)); AC-17(08) (now in CM-07).
Each enhancement's statement: /api/v1/controls/AC-17?fields=enhancements

## Patterns that use it (13)
- Critical (3): SP-015 Secure Remote Working; SP-021 Realtime Collaboration Pattern; SP-023 Industrial Control Systems
- Important (7): SP-017 Secure Network Zone Module; SP-029 Zero Trust Architecture; SP-030 API Security; SP-032 Modern Authentication; SP-037 Privileged User Management; SP-046 External Attack Surface Management; SP-054 CBDC and Digital Currency Infrastructure (draft)
- Standard (3): SP-025 Advanced Monitoring and Detection; SP-044 SaaS Identity Lifecycle Management; SP-050 Mobile Security Architecture (draft)

## Clauses by framework (77 frameworks)
- iso_27001_2022: A.5.14, A.5.15, A.6.7, A.7.9. OSA's own, not in NIST's crosswalk: A.5.15, A.7.9
- iso_27002_2022: 5.14, 5.15, 6.7, 7.9
- cobit_2019: DSS05
- pci_dss_v4: 2.2.7
- nist_csf_2: PR.AA-05, PR.DS-02, PR.IR-01. OSA's own, not in NIST's crosswalk: PR.DS-02, PR.IR-01
- cis_controls_v8: CIS 4.6, CIS 6, CIS 6.4, CIS 12.3, CIS 12.6, CIS 12.7, CIS 13.5, CIS 14.8
- soc2_tsc: CC6.6, CC6.6-POF3
- finos_ccc: CCC-C05
- iec_62443: 3-3 SR 1.13, 3-3 SR 2.6, 3-3 SR 4.1
- asd_e8: E8-7 ML2
- nis2: Art. 21(2)(i)
- apra_cps_234: Para 22-23
- mas_trm: 9, 14
- bsi_grundschutz: CON.7, OPS.1.2.4, ORP.4
- anssi: Hygiene.24, Hygiene.28, SecNumCloud.10.7, SecNumCloud.14.2
- osfi_b13: B-13.3.2
- finma_circular: IV.B.d(59), IV.C(62), IV.C(63)
- gdpr: Art.32(1)(a), Art.32(1)(b), Art.44
- dora: Art.9(4)(a), Art.9(4)(c)
- bio2: 5.14, 5.15, 6.7, 7.9
- rbi_csf: Annex1.8, ITGRCA.20
- fisc: FISC.T3, FISC.T8, FISC.T10
- lgpd_bcb: BCB.PIX, LGPD.Art.33-36
- hkma_tme1: TME1.8.5, TME1.10.1
- mlps_2: 8.1.3.1
- dnb_good_practice: DNB.18.4
- cra: CRA.I.2d
- swift_cscf: SWIFT.2.6
- cbb_tm: TM-6, TM-8
- cbuae: CR-4
- nca_ecc: 2-2
- qatar_nia: AC, CS
- sama_csf: 3.1, 3.3, 3.8
- uae_ia: T8, T9
- bog_cisd: CISD-IX, CISD-VIII, CISD-XI
- bom_ctrm: 3.2, 3.13
- cbe_csf: CTO-1, CTO-5, CTO-6
- cbn_csf: Part3.2
- sa_js2: JS2-7.1, JS2-8.1
- bot_cyber: Ch2.2, Ch2.4, Ch9.1
- cpmi_pfmi: CG.PR, PFMI.P22
- eba_ict: 3.4.2
- ecb_croe: CROE.2.3.5
- ffiec_is: II.C.9, II.C.13(b), II.C.15(c), II.C.16
- hipaa_sr: §164.310(b), §164.312(a)(1), §164.312(e)(1)
- iosco_cyber: PROT-1
- nydfs_500: 500.6, 500.7, 500.12
- sebi_cscrf: PR.AA
- cmmc_2: AC
- nerc_cip: CIP-005-7
- nrc_73_54: RG5.71-A-AC
- tsa_psd: SD-2 Sec B
- doe_c2m2: ACCESS
- api_1164: Sec 6
- awia: AWWA Sec 3
- iaea_nss: Sec 5.3
- pci_pts: E, I
- pci_hsm: 3
- common_criteria: CC Part 2 — FRU/FTA/FTP
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.7.3
- fda_21_cfr_11: §11.30, §11.300(d)
- hitrust_csf: 01.b, 01.d, 05.c
- iso_27799: 6.3, 9.5, H.5
- lloyds_ms: MS8.3, MS8.9
- naic_ds: 4-access, 4-audit
- nhs_dspt: NDG-9.7
- pra_ss1_23: P-IT.1
- solvency_ii: EIOPA-ICT-4.4, EIOPA-ICT-4.6
- owasp_masvs_v2: MASVS-NETWORK-1
- csa_ccm_v4: HRS-04
- csa_aicm: HRS-04
- ccss_v9: 1.03.5
- basel_sco60: SCO60.62
- bssc: NOS-05
- sec_custody_digital: SEC-CD-05
- dpdpa: Rules.6(1)(b)
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/AC-17
- Clauses only: /api/v1/controls/AC-17?fields=mappings
- Page for people: /controls/ac-17/
