id: "AC-17(10)" title: "Authenticate Remote Commands" family: "AC" family_name: "Access Control" sort_id: "ac-17.10" priority: "P1" implementation_level: "system" parent: "AC-17" enhancement: True


Statement

Implement {{ insert: param, ac-17.10_odp.01 }} to authenticate {{ insert: param, ac-17.10_odp.02 }}.

Guidance

Authenticating remote commands protects against unauthorized commands and the replay of authorized commands. The ability to authenticate remote commands is important for remote systems for which loss, malfunction, misdirection, or exploitation would have immediate or serious consequences, such as injury, death, property damage, loss of high value assets, failure of mission or business functions, or compromise of classified or controlled unclassified information. Authentication mechanisms for remote commands ensure that systems accept and execute commands in the order intended, execute only authorized commands, and reject unauthorized commands. Cryptographic mechanisms can be used, for example, to authenticate remote commands.

Assessment Objective

{{ insert: param, ac-17.10_odp.01 }} are implemented to authenticate {{ insert: param, ac-17.10_odp.02 }}.

Access control policy

procedures addressing authentication of remote commands

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developers

Mechanisms implementing authentication of remote commands