id: "AC-17(06)" title: "Protection of Mechanism Information" family: "AC" family_name: "Access Control" sort_id: "ac-17.06" priority: "P1" implementation_level: "organization" parent: "AC-17" enhancement: True


Statement

Protect information about remote access mechanisms from unauthorized use and disclosure.

Guidance

Remote access to organizational information by non-organizational entities can increase the risk of unauthorized use and disclosure about remote access mechanisms. The organization considers including remote access requirements in the information exchange agreements with other organizations, as applicable. Remote access requirements can also be included in rules of behavior (see PL-4 ) and access agreements (see PS-6).

Assessment Objective

information about remote access mechanisms is protected from unauthorized use and disclosure.

Access control policy

procedures addressing remote access to the system

system security plan

other relevant documents or records

Organizational personnel with responsibilities for implementing or monitoring remote access to the system

system users with knowledge of information about remote access mechanisms

organizational personnel with information security responsibilities