San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

AC-17 Remote Access

Access Control family. 25 Control Correlation Identifiers map to this control, and 55 STIG rules implement those CCIs.

2CAT I (high)
53CAT II (medium)
0CAT III (low)
25CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to AC-17
Red Hat Enterprise Linux 8V215
Red Hat Enterprise Linux 9V213
Microsoft Windows Server 2019V36
Microsoft Windows 10V36
Microsoft Windows Server 2022V26
KubernetesV25
Microsoft Windows 11V24

Control Correlation Identifiers mapped to AC-17

CCIDefinitionRev
CCI-000063The organization defines allowed methods of remote access to the information system.4
CCI-000065Authorize remote access to the system prior to allowing such connections.5, 4
CCI-000067Employ automated mechanisms to monitor remote access methods.5, 4
CCI-000068Implement cryptographic mechanisms to protect the confidentiality of remote access sessions.5, 4
CCI-000069Route all remote accesses through authorized and managed network access control points.5, 4
CCI-000070Authorize the execution of privileged commands via remote access only in a format that provides assessable evidence for organization-defined needs.5, 4
CCI-000072Protect information about remote access mechanisms from unauthorized use and disclosure.5, 4
CCI-001453Implement cryptographic mechanisms to protect the integrity of remote access sessions.5, 4
CCI-001561The organization defines managed access control points for remote access to the information system.4
CCI-002310Establish and document usage restrictions for each type of remote access allowed.5, 4
CCI-002311Establish and document configuration/connection requirements for each type of remote access allowed.5, 4
CCI-002312Establish and document implementation guidance for each type of remote access allowed.5, 4
CCI-002313The information system controls remote access methods.4
CCI-002314Employ automated mechanisms to control remote access methods.5, 4
CCI-002315The organization defines the number of managed network access control points through which the information system routes all remote access.4
CCI-002316Authorize access to security-relevant information via remote access only in a format that provides assessable evidence for organization-defined needs.5, 4
CCI-002317Defines the needs for when the execution of privileged commands via remote access is to be authorized.5, 4
CCI-002318Defines the needs for when access to security-relevant information via remote access is to be authorized.5, 4
CCI-002319Document the rationale for authorization of the execution of privilege commands via remote access.5, 4
CCI-002320Document the rationale for authorization of access to security-relevant information via remote access.5, 4
CCI-002321Defines the time-period within which it disconnects or disables remote access to the system.5, 4
CCI-002322Provide the capability to disconnect or disable remote access to the system within the organization-defined time period.5, 4
CCI-003747Implement organization-defined mechanisms to authenticate organization-defined remote commands.5
CCI-003748Defines the mechanisms used to authenticate organization-defined remote commands.5
CCI-003749Defines the remote commands used for implementing organization-defined mechanisms.5

STIG rules that implement AC-17

RuleSTIG IDSeverityRequirement
V-205634WN19-AU-000190mediumWindows Server 2019 must be configured to audit logon successes.
V-205635WN19-AU-000200mediumWindows Server 2019 must be configured to audit logon failures.
V-205636WN19-CC-000370mediumWindows Server 2019 Remote Desktop Services must require secure Remote Procedure Call (RPC) communications.
V-205637WN19-CC-000380mediumWindows Server 2019 Remote Desktop Services must be configured with the client connection encryption set to High Level.
V-205732WN19-DC-000410mediumWindows Server 2019 Deny log on through Remote Desktop Services user right on domain controllers must be configured to prevent unauthenticated access.
V-205733WN19-MS-000120mediumWindows Server 2019 "Deny log on through Remote Desktop Services" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and all local accounts and from unauthenticated access on all systems.
V-220757WN10-AU-000065mediumThe system must be configured to audit Logon/Logoff - Logoff successes.
V-220758WN10-AU-000070mediumThe system must be configured to audit Logon/Logoff - Logon failures.
V-220759WN10-AU-000075mediumThe system must be configured to audit Logon/Logoff - Logon successes.
V-220851WN10-CC-000285mediumThe Remote Desktop Session Host must require secure RPC communications.
V-220852WN10-CC-000290mediumRemote Desktop Services must be configured with the client connection encryption set to the required level.
V-220972WN10-UR-000090mediumThe Deny log on through Remote Desktop Services user right on Windows 10 workstations must at a minimum be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.
V-230223RHEL-08-010020highRHEL 8 must implement NIST FIPS-validated cryptography for the following: To provision digital signatures, to generate cryptographic hashes, and to protect data requiring data-at-rest protections in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
V-230228RHEL-08-010070mediumAll RHEL 8 remote access methods must be monitored.
V-230251RHEL-08-010290mediumThe RHEL 8 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms.
V-230252RHEL-08-010291mediumThe RHEL 8 operating system must implement DOD-approved encryption to protect the confidentiality of SSH server connections.
V-230254RHEL-08-010293mediumThe RHEL 8 operating system must implement DoD-approved encryption in the OpenSSL package.
V-230255RHEL-08-010294mediumThe RHEL 8 operating system must implement DoD-approved TLS encryption in the OpenSSL package.
V-230256RHEL-08-010295mediumThe RHEL 8 operating system must implement DoD-approved TLS encryption in the GnuTLS package.
V-230504RHEL-08-040090mediumA RHEL 8 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems.
V-230505RHEL-08-040100mediumA firewall must be installed on RHEL 8.
V-230527RHEL-08-040161mediumRHEL 8 must force a frequent session key renegotiation for SSH connections to the server.
V-242376CNTR-K8-000150mediumThe Kubernetes Controller Manager must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination.
V-242377CNTR-K8-000160mediumThe Kubernetes Scheduler must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination.
V-242378CNTR-K8-000170mediumThe Kubernetes API Server must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination.
V-242379CNTR-K8-000180mediumThe Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination.
V-242380CNTR-K8-000190mediumThe Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination.
V-244526RHEL-08-010287mediumThe RHEL 8 SSH daemon must be configured to use system-wide crypto policies.
V-244544RHEL-08-040101mediumA firewall must be active on RHEL 8.
V-253315WN11-AU-000065mediumThe system must be configured to audit Logon/Logoff - Logoff successes.
V-253405WN11-CC-000285mediumThe Remote Desktop Session Host must require secure RPC communications.
V-253406WN11-CC-000290mediumRemote Desktop Services must be configured with the client connection encryption set to the required level.
V-253495WN11-UR-000090mediumThe "Deny log on through Remote Desktop Services" user right on Windows 11 workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.
V-254312WN22-AU-000190mediumWindows Server 2022 must be configured to audit logon successes.
V-254313WN22-AU-000200mediumWindows Server 2022 must be configured to audit logon failures.
V-254368WN22-CC-000370mediumWindows Server 2022 Remote Desktop Services must require secure Remote Procedure Call (RPC) communications.
V-254369WN22-CC-000380mediumWindows Server 2022 Remote Desktop Services must be configured with the client connection encryption set to High Level.
V-254425WN22-DC-000410mediumWindows Server 2022 Deny log on through Remote Desktop Services user right on domain controllers must be configured to prevent unauthenticated access.
V-254439WN22-MS-000120mediumWindows Server 2022 Deny log on through Remote Desktop Services user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and all local accounts and from unauthenticated access on all systems.
V-255924RHEL-08-040342mediumRHEL 8 SSH server must be configured to use only FIPS-validated key exchange algorithms.
V-257935RHEL-09-251010mediumRHEL 9 must have the firewalld package installed.
V-257936RHEL-09-251015mediumThe firewalld service on RHEL 9 must be active.
V-257982RHEL-09-255030mediumRHEL 9 must log SSH connection attempts and failures to the server.
V-257987RHEL-09-255055mediumRHEL 9 SSH daemon must be configured to use system-wide crypto policies.
V-257988RHEL-09-255060mediumRHEL 9 must implement DOD-approved encryption ciphers to protect the confidentiality of SSH connections.
V-257989RHEL-09-255065mediumThe RHEL 9 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.
V-257991RHEL-09-255075mediumThe RHEL 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.
V-257994RHEL-09-255090mediumRHEL 9 must force a frequent session key renegotiation for SSH connections to the server.
V-258144RHEL-09-652030mediumAll RHEL 9 remote access methods must be monitored.
V-258230RHEL-09-671010highRHEL 9 must enable FIPS mode.
V-258232RHEL-09-671020mediumRHEL 9 IP tunnels must use FIPS 140-3 approved cryptographic algorithms.
V-270177RHEL-09-255064mediumThe RHEL 9 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.
V-270178RHEL-09-255070mediumThe RHEL 9 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.
V-272482RHEL-08-010296mediumRHEL 8 SSH client must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms.
V-272483RHEL-08-010297mediumRHEL 8 SSH client must be configured to use only ciphers employing FIPS 140-3 validated cryptographic hash algorithms.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AC-17. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.