Skip to main content

πŸ’Ό AC-17 Remote Access

  • Contextual name: πŸ’Ό AC-17 Remote Access
  • ID: /frameworks/nist-sp-800-53-r5/ac/17
  • Located in: πŸ’Ό AC Access Control

Description​

a. Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and b. Authorize each type of remote access to the system prior to allowing such connections.

Similar​

  • Sections
    • /frameworks/aws-fsbp-v1.0.0/dms/10
    • /frameworks/aws-fsbp-v1.0.0/dynamodb/07
  • Internal
    • ID: dec-c-42214397

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [DMS.10] DMS endpoints for Neptune databases should have IAM authorization enabled
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [DynamoDB.7] DynamoDB Accelerator clusters should be encrypted in transit

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό AC-17 Remote Access (L)(M)(H)414
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό AC-17 Remote Access (L)(M)(H)
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό PR.AA-05: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties58

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό AC-17(1) Remote Access _ Monitoring and Control11
πŸ’Ό AC-17(2) Remote Access _ Protection of Confidentiality and Integrity Using Encryption1113
πŸ’Ό AC-17(3) Remote Access _ Managed Access Control Points
πŸ’Ό AC-17(4) Remote Access _ Privileged Commands and Access
πŸ’Ό AC-17(5) Remote Access _ Monitoring for Unauthorized Connections
πŸ’Ό AC-17(6) Remote Access _ Protection of Mechanism Information
πŸ’Ό AC-17(7) Remote Access _ Additional Protection for Security Function Access
πŸ’Ό AC-17(8) Remote Access _ Disable Nonsecure Network Protocols
πŸ’Ό AC-17(9) Remote Access _ Disconnect or Disable Access
πŸ’Ό AC-17(10) Remote Access _ Authenticate Remote Commands