AC-17 Remote Access
Access Control family. 25 Control Correlation Identifiers map to this control, and 55 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to AC-17 |
|---|---|---|
| Red Hat Enterprise Linux 8 | V2 | 15 |
| Red Hat Enterprise Linux 9 | V2 | 13 |
| Microsoft Windows Server 2019 | V3 | 6 |
| Microsoft Windows 10 | V3 | 6 |
| Microsoft Windows Server 2022 | V2 | 6 |
| Kubernetes | V2 | 5 |
| Microsoft Windows 11 | V2 | 4 |
Control Correlation Identifiers mapped to AC-17
| CCI | Definition | Rev |
|---|---|---|
| CCI-000063 | The organization defines allowed methods of remote access to the information system. | 4 |
| CCI-000065 | Authorize remote access to the system prior to allowing such connections. | 5, 4 |
| CCI-000067 | Employ automated mechanisms to monitor remote access methods. | 5, 4 |
| CCI-000068 | Implement cryptographic mechanisms to protect the confidentiality of remote access sessions. | 5, 4 |
| CCI-000069 | Route all remote accesses through authorized and managed network access control points. | 5, 4 |
| CCI-000070 | Authorize the execution of privileged commands via remote access only in a format that provides assessable evidence for organization-defined needs. | 5, 4 |
| CCI-000072 | Protect information about remote access mechanisms from unauthorized use and disclosure. | 5, 4 |
| CCI-001453 | Implement cryptographic mechanisms to protect the integrity of remote access sessions. | 5, 4 |
| CCI-001561 | The organization defines managed access control points for remote access to the information system. | 4 |
| CCI-002310 | Establish and document usage restrictions for each type of remote access allowed. | 5, 4 |
| CCI-002311 | Establish and document configuration/connection requirements for each type of remote access allowed. | 5, 4 |
| CCI-002312 | Establish and document implementation guidance for each type of remote access allowed. | 5, 4 |
| CCI-002313 | The information system controls remote access methods. | 4 |
| CCI-002314 | Employ automated mechanisms to control remote access methods. | 5, 4 |
| CCI-002315 | The organization defines the number of managed network access control points through which the information system routes all remote access. | 4 |
| CCI-002316 | Authorize access to security-relevant information via remote access only in a format that provides assessable evidence for organization-defined needs. | 5, 4 |
| CCI-002317 | Defines the needs for when the execution of privileged commands via remote access is to be authorized. | 5, 4 |
| CCI-002318 | Defines the needs for when access to security-relevant information via remote access is to be authorized. | 5, 4 |
| CCI-002319 | Document the rationale for authorization of the execution of privilege commands via remote access. | 5, 4 |
| CCI-002320 | Document the rationale for authorization of access to security-relevant information via remote access. | 5, 4 |
| CCI-002321 | Defines the time-period within which it disconnects or disables remote access to the system. | 5, 4 |
| CCI-002322 | Provide the capability to disconnect or disable remote access to the system within the organization-defined time period. | 5, 4 |
| CCI-003747 | Implement organization-defined mechanisms to authenticate organization-defined remote commands. | 5 |
| CCI-003748 | Defines the mechanisms used to authenticate organization-defined remote commands. | 5 |
| CCI-003749 | Defines the remote commands used for implementing organization-defined mechanisms. | 5 |
STIG rules that implement AC-17
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205634 | WN19-AU-000190 | medium | Windows Server 2019 must be configured to audit logon successes. |
| V-205635 | WN19-AU-000200 | medium | Windows Server 2019 must be configured to audit logon failures. |
| V-205636 | WN19-CC-000370 | medium | Windows Server 2019 Remote Desktop Services must require secure Remote Procedure Call (RPC) communications. |
| V-205637 | WN19-CC-000380 | medium | Windows Server 2019 Remote Desktop Services must be configured with the client connection encryption set to High Level. |
| V-205732 | WN19-DC-000410 | medium | Windows Server 2019 Deny log on through Remote Desktop Services user right on domain controllers must be configured to prevent unauthenticated access. |
| V-205733 | WN19-MS-000120 | medium | Windows Server 2019 "Deny log on through Remote Desktop Services" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and all local accounts and from unauthenticated access on all systems. |
| V-220757 | WN10-AU-000065 | medium | The system must be configured to audit Logon/Logoff - Logoff successes. |
| V-220758 | WN10-AU-000070 | medium | The system must be configured to audit Logon/Logoff - Logon failures. |
| V-220759 | WN10-AU-000075 | medium | The system must be configured to audit Logon/Logoff - Logon successes. |
| V-220851 | WN10-CC-000285 | medium | The Remote Desktop Session Host must require secure RPC communications. |
| V-220852 | WN10-CC-000290 | medium | Remote Desktop Services must be configured with the client connection encryption set to the required level. |
| V-220972 | WN10-UR-000090 | medium | The Deny log on through Remote Desktop Services user right on Windows 10 workstations must at a minimum be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems. |
| V-230223 | RHEL-08-010020 | high | RHEL 8 must implement NIST FIPS-validated cryptography for the following: To provision digital signatures, to generate cryptographic hashes, and to protect data requiring data-at-rest protections in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards. |
| V-230228 | RHEL-08-010070 | medium | All RHEL 8 remote access methods must be monitored. |
| V-230251 | RHEL-08-010290 | medium | The RHEL 8 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms. |
| V-230252 | RHEL-08-010291 | medium | The RHEL 8 operating system must implement DOD-approved encryption to protect the confidentiality of SSH server connections. |
| V-230254 | RHEL-08-010293 | medium | The RHEL 8 operating system must implement DoD-approved encryption in the OpenSSL package. |
| V-230255 | RHEL-08-010294 | medium | The RHEL 8 operating system must implement DoD-approved TLS encryption in the OpenSSL package. |
| V-230256 | RHEL-08-010295 | medium | The RHEL 8 operating system must implement DoD-approved TLS encryption in the GnuTLS package. |
| V-230504 | RHEL-08-040090 | medium | A RHEL 8 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems. |
| V-230505 | RHEL-08-040100 | medium | A firewall must be installed on RHEL 8. |
| V-230527 | RHEL-08-040161 | medium | RHEL 8 must force a frequent session key renegotiation for SSH connections to the server. |
| V-242376 | CNTR-K8-000150 | medium | The Kubernetes Controller Manager must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination. |
| V-242377 | CNTR-K8-000160 | medium | The Kubernetes Scheduler must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination. |
| V-242378 | CNTR-K8-000170 | medium | The Kubernetes API Server must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination. |
| V-242379 | CNTR-K8-000180 | medium | The Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination. |
| V-242380 | CNTR-K8-000190 | medium | The Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination. |
| V-244526 | RHEL-08-010287 | medium | The RHEL 8 SSH daemon must be configured to use system-wide crypto policies. |
| V-244544 | RHEL-08-040101 | medium | A firewall must be active on RHEL 8. |
| V-253315 | WN11-AU-000065 | medium | The system must be configured to audit Logon/Logoff - Logoff successes. |
| V-253405 | WN11-CC-000285 | medium | The Remote Desktop Session Host must require secure RPC communications. |
| V-253406 | WN11-CC-000290 | medium | Remote Desktop Services must be configured with the client connection encryption set to the required level. |
| V-253495 | WN11-UR-000090 | medium | The "Deny log on through Remote Desktop Services" user right on Windows 11 workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems. |
| V-254312 | WN22-AU-000190 | medium | Windows Server 2022 must be configured to audit logon successes. |
| V-254313 | WN22-AU-000200 | medium | Windows Server 2022 must be configured to audit logon failures. |
| V-254368 | WN22-CC-000370 | medium | Windows Server 2022 Remote Desktop Services must require secure Remote Procedure Call (RPC) communications. |
| V-254369 | WN22-CC-000380 | medium | Windows Server 2022 Remote Desktop Services must be configured with the client connection encryption set to High Level. |
| V-254425 | WN22-DC-000410 | medium | Windows Server 2022 Deny log on through Remote Desktop Services user right on domain controllers must be configured to prevent unauthenticated access. |
| V-254439 | WN22-MS-000120 | medium | Windows Server 2022 Deny log on through Remote Desktop Services user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and all local accounts and from unauthenticated access on all systems. |
| V-255924 | RHEL-08-040342 | medium | RHEL 8 SSH server must be configured to use only FIPS-validated key exchange algorithms. |
| V-257935 | RHEL-09-251010 | medium | RHEL 9 must have the firewalld package installed. |
| V-257936 | RHEL-09-251015 | medium | The firewalld service on RHEL 9 must be active. |
| V-257982 | RHEL-09-255030 | medium | RHEL 9 must log SSH connection attempts and failures to the server. |
| V-257987 | RHEL-09-255055 | medium | RHEL 9 SSH daemon must be configured to use system-wide crypto policies. |
| V-257988 | RHEL-09-255060 | medium | RHEL 9 must implement DOD-approved encryption ciphers to protect the confidentiality of SSH connections. |
| V-257989 | RHEL-09-255065 | medium | The RHEL 9 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. |
| V-257991 | RHEL-09-255075 | medium | The RHEL 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. |
| V-257994 | RHEL-09-255090 | medium | RHEL 9 must force a frequent session key renegotiation for SSH connections to the server. |
| V-258144 | RHEL-09-652030 | medium | All RHEL 9 remote access methods must be monitored. |
| V-258230 | RHEL-09-671010 | high | RHEL 9 must enable FIPS mode. |
| V-258232 | RHEL-09-671020 | medium | RHEL 9 IP tunnels must use FIPS 140-3 approved cryptographic algorithms. |
| V-270177 | RHEL-09-255064 | medium | The RHEL 9 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. |
| V-270178 | RHEL-09-255070 | medium | The RHEL 9 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. |
| V-272482 | RHEL-08-010296 | medium | RHEL 8 SSH client must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms. |
| V-272483 | RHEL-08-010297 | medium | RHEL 8 SSH client must be configured to use only ciphers employing FIPS 140-3 validated cryptographic hash algorithms. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AC-17. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.