id: "AC-17(04)" title: "Privileged Commands and Access" family: "AC" family_name: "Access Control" sort_id: "ac-17.04" priority: "P1" implementation_level: "organization" parent: "AC-17" enhancement: True


Authorize the execution of privileged commands and access to security-relevant information via remote access only in a format that provides assessable evidence and for the following needs: {{ insert: param, ac-17.4_prm_1 }} ; and

Document the rationale for remote access in the security plan for the system.

Guidance

Remote access to systems represents a significant potential vulnerability that can be exploited by adversaries. As such, restricting the execution of privileged commands and access to security-relevant information via remote access reduces the exposure of the organization and the susceptibility to threats by adversaries to the remote access capability.

Assessment Objective: the execution of privileged commands via remote access is authorized only in a format that provides assessable evidence;

Assessment Objective: access to security-relevant information via remote access is authorized only in a format that provides assessable evidence;

Assessment Objective: the execution of privileged commands via remote access is authorized only for the following needs: {{ insert: param, ac-17.04_odp.01 }};

Assessment Objective: access to security-relevant information via remote access is authorized only for the following needs: {{ insert: param, ac-17.04_odp.02 }};

Assessment Objective: the rationale for remote access is documented in the security plan for the system.

Access control policy

procedures addressing remote access to the system

system configuration settings and associated documentation

security plan

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

Mechanisms implementing remote access management