800-53|AC-17

Title

REMOTE ACCESS

Description

The organization:

Supplemental

Remote access is access to organizational information systems by users (or processes acting on behalf of users) communicating through external networks (e.g., the Internet). Remote access methods include, for example, dial-up, broadband, and wireless. Organizations often employ encrypted virtual private networks (VPNs) to enhance confidentiality and integrity over remote connections. The use of encrypted VPNs does not make the access non-remote; however, the use of VPNs, when adequately provisioned with appropriate security controls (e.g., employing appropriate encryption techniques for confidentiality and integrity protection) may provide sufficient assurance to the organization that it can effectively treat such connections as internal networks. Still, VPN connections traverse external networks, and the encrypted VPN does not enhance the availability of remote connections. Also, VPNs with encrypted tunnels can affect the organizational capability to adequately monitor network communications traffic for malicious code. Remote access controls apply to information systems other than public web servers or systems designed for public access. This control addresses authorization prior to allowing remote access without specifying the formats for such authorization. While organizations may use interconnection security agreements to authorize remote access connections, such agreements are not required by this control. Enforcing access restrictions for remote connections is addressed in AC-3.

Reference Item Details

Related: AC-18,AC-19,AC-2,AC-20,AC-3,CA-3,CA-7,CM-8,IA-2,IA-3,IA-8,MA-4,PE-17,PL-4,SC-10,SI-4

Category: ACCESS CONTROL

Family: ACCESS CONTROL

Priority: P1

Baseline Impact: LOW,MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.2.1 (L1) Ensure 'NTLM' is set to 'Disabled'WindowsCIS Mozilla Firefox ESR GPO v1.0.0 L1
1.1.7.1 (L1) Ensure 'TLS_RSA_WITH_3DES_EDE_CBC_SHA ' is set to 'Enabled'WindowsCIS Mozilla Firefox ESR GPO v1.0.0 L1
1.1.37 (L1) Ensure 'Maximum SSL version enabled' is set to 'Enabled: TLS 1.3'WindowsCIS Mozilla Firefox ESR GPO v1.0.0 L1
1.1.38 (L1) Ensure 'Minimum SSL version enabled' is set to 'Enabled: TLS 1.2'WindowsCIS Mozilla Firefox ESR GPO v1.0.0 L1
1.10 Ensure system-wide crypto policy is not legacyUnixCIS CentOS Linux 8 Server L1 v2.0.0
1.10 Ensure system-wide crypto policy is not legacyUnixCIS Fedora 28 Family Linux Server L1 v2.0.0
1.10 Ensure system-wide crypto policy is not legacyUnixCIS CentOS Linux 8 Workstation L1 v2.0.0
1.10 Ensure system-wide crypto policy is not legacyUnixCIS Fedora 28 Family Linux Workstation L1 v2.0.0
1.10 OL08-00-010070UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.10.1 (L1) Ensure 'Allow Basic authentication for HTTP' is set to 'Disabled'WindowsCIS Microsoft Edge v3.0.0 L1
1.10.3 (L2) Ensure 'Supported authentication schemes' is set to 'Enabled: ntlm, negotiate'WindowsCIS Microsoft Edge v3.0.0 L2
1.11 UBTU-24-100300UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.12 Ensure 'Internet-facing receive connectors' is set to 'Tls, BasicAuth, BasicAuthRequireTLS'WindowsCIS Microsoft Exchange Server 2019 L1 Edge v1.0.0
1.12 UBTU-24-100310UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.118 UBTU-22-652015UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.127 WN16-CC-000390WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT II
1.127 WN16-CC-000390WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT II
1.129 WN16-CC-000410WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT II
1.129 WN16-CC-000410WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT II
1.129 WN19-CC-000360WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT II
1.129 WN19-CC-000360WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT II
1.129 WN22-CC-000360WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT II
1.129 WN22-CC-000360WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT II
1.131 WN10-CC-000155WindowsCIS Microsoft Windows 10 STIG v1.0.0 CAT I
1.131 WN19-CC-000380WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT II
1.131 WN19-CC-000380WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT II
1.131 WN22-CC-000380WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT II
1.131 WN22-CC-000380WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT II
1.139 WN16-CC-000500WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT I
1.139 WN16-CC-000500WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT I
1.140 WN16-CC-000510WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT II
1.140 WN16-CC-000510WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT II
1.140 WN19-CC-000470WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT I
1.140 WN19-CC-000470WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT I
1.140 WN22-CC-000470WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT I
1.140 WN22-CC-000470WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT I
1.141 WN16-CC-000520WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT II
1.141 WN16-CC-000520WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT II
1.141 WN19-CC-000480WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT II
1.141 WN19-CC-000480WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT II
1.141 WN22-CC-000480WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT II
1.141 WN22-CC-000480WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT II
1.142 WN16-CC-000530WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT I
1.142 WN16-CC-000530WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT I
1.142 WN19-CC-000490WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT II
1.142 WN19-CC-000490WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT II
1.142 WN22-CC-000490WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT II
1.142 WN22-CC-000490WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT II
1.143 WN16-CC-000540WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT II
1.143 WN16-CC-000540WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT II