3.1 Access Control5 pts

3.1.12 — Monitor and control remote access

Monitor and control remote access sessions.

Every remote connection into your environment is managed and logged.

What it actually means

Remote access is the most common way attackers get in, so the program weights it heavily. Remote sessions must come through approved, managed methods (VPN or a cloud identity gateway), be logged centrally, and be subject to device-compliance and MFA checks. You control how people connect and you can see when they do.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

If your environment genuinely allows no remote access, this can be Not Applicable — but you must document that, and prohibit enabling remote access without a change and reassessment.

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Access Control (3.1)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.