NIST 800-171 - Manage Access Control Points (3.1.14)


Overview:
Route remote access via managed access control points.


Action Items:
3.1.14[a]
Determine if: managed access control points are identified and implemented.


3.1.14[b]
Determine if: remote access is routed through managed network access control points.


POTENTIAL ASSESSMENT METHODS AND OBJECTS


1
Examine: Access control policy; procedures addressing remote access to the system; system security plan; system design documentation; list of all managed network access control points; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records].


2
Interview: System or network administrators; personnel with information security responsibilities].


3
Test: Mechanisms routing all remote accesses through managed network access control points].


Related Documents (document name and content will vary by organization):
1) Access control policy
2) procedures addressing remote access to the system
3) system security plan
4) system design documentation
5) list of all managed network access control points
6) system configuration settings and associated documentation
7) system audit logs and records
8) other relevant documents or records


Additional Guidance:
Routing all remote access through managed access control points enhances explicit, organizational control over such connections, reducing the susceptibility to unauthorized access to organizational systems resulting in the unauthorized disclosure of CUI.



Article ID: 119
Created: September 26, 2022
Last Updated: September 27, 2022
Author: Matthew Burdick

Online URL: http://www.compliancewiki.org/article/nist-800-171-manage-access-control-points-3-1-14-119.html