{
    "control": "AC-17",
    "title": "Remote Access",
    "ccis": [
        {
            "cci": "CCI-000063",
            "definition": "The organization defines allowed methods of remote access to the information system."
        },
        {
            "cci": "CCI-000065",
            "definition": "Authorize remote access to the system prior to allowing such connections."
        },
        {
            "cci": "CCI-000067",
            "definition": "Employ automated mechanisms to monitor remote access methods."
        },
        {
            "cci": "CCI-000068",
            "definition": "Implement cryptographic mechanisms to protect the confidentiality of remote access sessions."
        },
        {
            "cci": "CCI-000069",
            "definition": "Route all remote accesses through authorized and managed network access control points."
        },
        {
            "cci": "CCI-000070",
            "definition": "Authorize the execution of privileged commands via remote access only in a format that provides assessable evidence for organization-defined needs."
        },
        {
            "cci": "CCI-000072",
            "definition": "Protect information about remote access mechanisms from unauthorized use and disclosure."
        },
        {
            "cci": "CCI-001453",
            "definition": "Implement cryptographic mechanisms to protect the integrity of remote access sessions."
        },
        {
            "cci": "CCI-001561",
            "definition": "The organization defines managed access control points for remote access to the information system."
        },
        {
            "cci": "CCI-002310",
            "definition": "Establish and document usage restrictions for each type of remote access allowed."
        },
        {
            "cci": "CCI-002311",
            "definition": "Establish and document configuration/connection requirements for each type of remote access allowed."
        },
        {
            "cci": "CCI-002312",
            "definition": "Establish and document implementation guidance for each type of remote access allowed."
        },
        {
            "cci": "CCI-002313",
            "definition": "The information system controls remote access methods."
        },
        {
            "cci": "CCI-002314",
            "definition": "Employ automated mechanisms to control remote access methods."
        },
        {
            "cci": "CCI-002315",
            "definition": "The organization defines the number of managed network access control points through which the information system routes all remote access."
        },
        {
            "cci": "CCI-002316",
            "definition": "Authorize access to security-relevant information via remote access only in a format that provides assessable evidence for organization-defined needs."
        },
        {
            "cci": "CCI-002317",
            "definition": "Defines the needs for when the execution of privileged commands via remote access is to be authorized."
        },
        {
            "cci": "CCI-002318",
            "definition": "Defines the needs for when access to security-relevant information via remote access is to be authorized."
        },
        {
            "cci": "CCI-002319",
            "definition": "Document the rationale for authorization of the execution of privilege commands via remote access."
        },
        {
            "cci": "CCI-002320",
            "definition": "Document the rationale for authorization of access to security-relevant information via remote access."
        },
        {
            "cci": "CCI-002321",
            "definition": "Defines the time-period within which it disconnects or disables remote access to the system."
        },
        {
            "cci": "CCI-002322",
            "definition": "Provide the capability to disconnect or disable remote access to the system within the organization-defined time period."
        }
    ],
    "rules_mapped": 55,
    "rules": [
        {
            "rule": "V-242376",
            "stig_id": "CNTR-K8-000150",
            "title": "The Kubernetes Controller Manager must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000068"
            ]
        },
        {
            "rule": "V-242377",
            "stig_id": "CNTR-K8-000160",
            "title": "The Kubernetes Scheduler must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000068"
            ]
        },
        {
            "rule": "V-242378",
            "stig_id": "CNTR-K8-000170",
            "title": "The Kubernetes API Server must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000068"
            ]
        },
        {
            "rule": "V-242379",
            "stig_id": "CNTR-K8-000180",
            "title": "The Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000068"
            ]
        },
        {
            "rule": "V-242380",
            "stig_id": "CNTR-K8-000190",
            "title": "The Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000068"
            ]
        },
        {
            "rule": "V-220757",
            "stig_id": "WN10-AU-000065",
            "title": "The system must be configured to audit Logon/Logoff - Logoff successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000067",
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220758",
            "stig_id": "WN10-AU-000070",
            "title": "The system must be configured to audit Logon/Logoff - Logon failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000067",
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220759",
            "stig_id": "WN10-AU-000075",
            "title": "The system must be configured to audit Logon/Logoff - Logon successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000067",
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220851",
            "stig_id": "WN10-CC-000285",
            "title": "The Remote Desktop Session Host must require secure RPC communications.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-220852",
            "stig_id": "WN10-CC-000290",
            "title": "Remote Desktop Services must be configured with the client connection encryption set to the required level.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000068",
                "CCI-002890"
            ]
        },
        {
            "rule": "V-220972",
            "stig_id": "WN10-UR-000090",
            "title": "The Deny log on through Remote Desktop Services user right on Windows 10 workstations must at a minimum be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000213",
                "CCI-002314"
            ]
        },
        {
            "rule": "V-253315",
            "stig_id": "WN11-AU-000065",
            "title": "The system must be configured to audit Logon/Logoff - Logoff successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000067"
            ]
        },
        {
            "rule": "V-253405",
            "stig_id": "WN11-CC-000285",
            "title": "The Remote Desktop Session Host must require secure RPC communications.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-253406",
            "stig_id": "WN11-CC-000290",
            "title": "Remote Desktop Services must be configured with the client connection encryption set to the required level.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000068"
            ]
        },
        {
            "rule": "V-253495",
            "stig_id": "WN11-UR-000090",
            "title": "The \"Deny log on through Remote Desktop Services\" user right on Windows 11 workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000213",
                "CCI-002314"
            ]
        },
        {
            "rule": "V-205634",
            "stig_id": "WN19-AU-000190",
            "title": "Windows Server 2019 must be configured to audit logon successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000067",
                "CCI-000172"
            ]
        },
        {
            "rule": "V-205635",
            "stig_id": "WN19-AU-000200",
            "title": "Windows Server 2019 must be configured to audit logon failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000067",
                "CCI-000172"
            ]
        },
        {
            "rule": "V-205636",
            "stig_id": "WN19-CC-000370",
            "title": "Windows Server 2019 Remote Desktop Services must require secure Remote Procedure Call (RPC) communications.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000068",
                "CCI-001453"
            ]
        },
        {
            "rule": "V-205637",
            "stig_id": "WN19-CC-000380",
            "title": "Windows Server 2019 Remote Desktop Services must be configured with the client connection encryption set to High Level.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000068",
                "CCI-001453"
            ]
        },
        {
            "rule": "V-205732",
            "stig_id": "WN19-DC-000410",
            "title": "Windows Server 2019 Deny log on through Remote Desktop Services user right on domain controllers must be configured to prevent unauthenticated access.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002314"
            ]
        },
        {
            "rule": "V-205733",
            "stig_id": "WN19-MS-000120",
            "title": "Windows Server 2019 \"Deny log on through Remote Desktop Services\" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and all local accounts and from unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002314"
            ]
        },
        {
            "rule": "V-254312",
            "stig_id": "WN22-AU-000190",
            "title": "Windows Server 2022 must be configured to audit logon successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000067",
                "CCI-000172"
            ]
        },
        {
            "rule": "V-254313",
            "stig_id": "WN22-AU-000200",
            "title": "Windows Server 2022 must be configured to audit logon failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000067",
                "CCI-000172"
            ]
        },
        {
            "rule": "V-254368",
            "stig_id": "WN22-CC-000370",
            "title": "Windows Server 2022 Remote Desktop Services must require secure Remote Procedure Call (RPC) communications.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000068",
                "CCI-001453"
            ]
        },
        {
            "rule": "V-254369",
            "stig_id": "WN22-CC-000380",
            "title": "Windows Server 2022 Remote Desktop Services must be configured with the client connection encryption set to High Level.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000068",
                "CCI-001453"
            ]
        },
        {
            "rule": "V-254425",
            "stig_id": "WN22-DC-000410",
            "title": "Windows Server 2022 Deny log on through Remote Desktop Services user right on domain controllers must be configured to prevent unauthenticated access.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002314"
            ]
        },
        {
            "rule": "V-254439",
            "stig_id": "WN22-MS-000120",
            "title": "Windows Server 2022 Deny log on through Remote Desktop Services user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and all local accounts and from unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002314"
            ]
        },
        {
            "rule": "V-230223",
            "stig_id": "RHEL-08-010020",
            "title": "RHEL 8 must implement NIST FIPS-validated cryptography for the following: To provision digital signatures, to generate cryptographic hashes, and to protect data requiring data-at-rest protections in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000068"
            ]
        },
        {
            "rule": "V-230228",
            "stig_id": "RHEL-08-010070",
            "title": "All RHEL 8 remote access methods must be monitored.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000067"
            ]
        },
        {
            "rule": "V-230251",
            "stig_id": "RHEL-08-010290",
            "title": "The RHEL 8 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-230252",
            "stig_id": "RHEL-08-010291",
            "title": "The RHEL 8 operating system must implement DOD-approved encryption to protect the confidentiality of SSH server connections.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-230254",
            "stig_id": "RHEL-08-010293",
            "title": "The RHEL 8 operating system must implement DoD-approved encryption in the OpenSSL package.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-230255",
            "stig_id": "RHEL-08-010294",
            "title": "The RHEL 8 operating system must implement DoD-approved TLS encryption in the OpenSSL package.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-230256",
            "stig_id": "RHEL-08-010295",
            "title": "The RHEL 8 operating system must implement DoD-approved TLS encryption in the GnuTLS package.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-230504",
            "stig_id": "RHEL-08-040090",
            "title": "A RHEL 8 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002314"
            ]
        },
        {
            "rule": "V-230505",
            "stig_id": "RHEL-08-040100",
            "title": "A firewall must be installed on RHEL 8.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002314"
            ]
        },
        {
            "rule": "V-230527",
            "stig_id": "RHEL-08-040161",
            "title": "RHEL 8 must force a frequent session key renegotiation for SSH connections to the server.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000068"
            ]
        },
        {
            "rule": "V-244526",
            "stig_id": "RHEL-08-010287",
            "title": "The RHEL 8 SSH daemon must be configured to use system-wide crypto policies.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-244544",
            "stig_id": "RHEL-08-040101",
            "title": "A firewall must be active on RHEL 8.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002314"
            ]
        },
        {
            "rule": "V-255924",
            "stig_id": "RHEL-08-040342",
            "title": "RHEL 8 SSH server must be configured to use only FIPS-validated key exchange algorithms.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-272482",
            "stig_id": "RHEL-08-010296",
            "title": "RHEL 8 SSH client must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-272483",
            "stig_id": "RHEL-08-010297",
            "title": "RHEL 8 SSH client must be configured to use only ciphers employing FIPS 140-3 validated cryptographic hash algorithms.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-257935",
            "stig_id": "RHEL-09-251010",
            "title": "RHEL 9 must have the firewalld package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000382",
                "CCI-002314",
                "CCI-002322"
            ]
        },
        {
            "rule": "V-257936",
            "stig_id": "RHEL-09-251015",
            "title": "The firewalld service on RHEL 9 must be active.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000382",
                "CCI-002314"
            ]
        },
        {
            "rule": "V-257982",
            "stig_id": "RHEL-09-255030",
            "title": "RHEL 9 must log SSH connection attempts and failures to the server.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000067"
            ]
        },
        {
            "rule": "V-257987",
            "stig_id": "RHEL-09-255055",
            "title": "RHEL 9 SSH daemon must be configured to use system-wide crypto policies.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-257988",
            "stig_id": "RHEL-09-255060",
            "title": "RHEL 9 must implement DOD-approved encryption ciphers to protect the confidentiality of SSH connections.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-257989",
            "stig_id": "RHEL-09-255065",
            "title": "The RHEL 9 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-257991",
            "stig_id": "RHEL-09-255075",
            "title": "The RHEL 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-257994",
            "stig_id": "RHEL-09-255090",
            "title": "RHEL 9 must force a frequent session key renegotiation for SSH connections to the server.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000068",
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-258144",
            "stig_id": "RHEL-09-652030",
            "title": "All RHEL 9 remote access methods must be monitored.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000067"
            ]
        },
        {
            "rule": "V-258230",
            "stig_id": "RHEL-09-671010",
            "title": "RHEL 9 must enable FIPS mode.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000068",
                "CCI-000877",
                "CCI-002418",
                "CCI-002450"
            ]
        },
        {
            "rule": "V-258232",
            "stig_id": "RHEL-09-671020",
            "title": "RHEL 9 IP tunnels must use FIPS 140-3 approved cryptographic algorithms.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000068"
            ]
        },
        {
            "rule": "V-270177",
            "stig_id": "RHEL-09-255064",
            "title": "The RHEL 9 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001453"
            ]
        },
        {
            "rule": "V-270178",
            "stig_id": "RHEL-09-255070",
            "title": "The RHEL 9 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001453"
            ]
        }
    ]
}