Every remote connection into your environment is managed and logged.
What it actually means
Remote access is the most common way attackers get in, so the program weights it heavily. Remote sessions must come through approved, managed methods (VPN or a cloud identity gateway), be logged centrally, and be subject to device-compliance and MFA checks. You control how people connect and you can see when they do.
Pass or fail — an assessor needs a "yes" to each
- Remote access is permitted only through approved, managed paths.
- Remote sessions are logged centrally.
- Device-compliance and MFA checks gate remote connections.
What to have ready
- Remote-access policy
- VPN / gateway configuration and logs
- Conditional-access policies requiring compliant devices + MFA
Where teams trip up
- Ad-hoc remote tools (random RDP, consumer remote-desktop apps) outside the managed path
- No logging of remote sessions
- Remote access without MFA
If your environment genuinely allows no remote access, this can be Not Applicable — but you must document that, and prohibit enabling remote access without a change and reassessment.
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
3.1.13 — Remote sessions must also be encrypted3.1.14 — Route remote access through a managed access-control point3.5.3 — MFA is how remote access is gated
More in Access Control (3.1)
3.1.1 — Limit who (and what) can get in3.1.2 — Limit what users can do3.1.3 — Control the flow of CUI3.1.4 — Separate duties3.1.5 — Least privilege (especially for admins)3.1.6 — Use non-privileged accounts for routine work3.1.7 — Restrict and log privileged functions3.1.8 — Limit failed logons3.1.9 — Show privacy and security notices3.1.10 — Lock idle screens3.1.11 — End sessions automatically3.1.13 — Encrypt remote access sessions3.1.14 — Funnel remote access through managed points3.1.15 — Authorize privileged remote actions3.1.16 — Authorize wireless access first3.1.17 — Protect wireless with authentication + encryption3.1.18 — Control mobile device connections3.1.19 — Encrypt CUI on mobile devices3.1.20 — Control connections to external systems3.1.21 — Limit portable storage on external systems3.1.22 — Control what goes on public systems