id: "AC-17(06)" title: "Protection of Mechanism Information" family: "AC" family_name: "Access Control" sort_id: "ac-17.06" priority: "P1" implementation_level: "organization" parent: "AC-17" enhancement: True
Statement
Protect information about remote access mechanisms from unauthorized use and disclosure.
Guidance
Remote access to organizational information by non-organizational entities can increase the risk of unauthorized use and disclosure about remote access mechanisms. The organization considers including remote access requirements in the information exchange agreements with other organizations, as applicable. Remote access requirements can also be included in rules of behavior (see PL-4 ) and access agreements (see PS-6).
Assessment Objective
information about remote access mechanisms is protected from unauthorized use and disclosure.
Access control policy
procedures addressing remote access to the system
system security plan
other relevant documents or records
Organizational personnel with responsibilities for implementing or monitoring remote access to the system
system users with knowledge of information about remote access mechanisms
organizational personnel with information security responsibilities