All remote access is protected with strong cryptography.
What it actually means
Whatever path remote users take in, the session has to be encrypted end to end — TLS 1.2+ or an IPsec VPN. This pairs with 3.1.12: 3.1.12 says monitor and control the session; 3.1.13 says encrypt it.
Pass or fail — an assessor needs a "yes" to each
- Remote sessions use TLS 1.2+ or IPsec VPN (strong, current protocols).
- No plaintext or weak/legacy protocols are permitted for remote access.
What to have ready
- VPN/gateway crypto configuration showing TLS 1.2+/IPsec
- Disabled legacy protocol settings
Where teams trip up
- Legacy TLS/SSL or weak ciphers still enabled
- Assuming the VPN is encrypted without verifying the configuration
Not Applicable only if there is genuinely no remote access (document it, same as 3.1.12).
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
3.1.12 — Monitor and control the remote sessions you're encrypting3.13.11 — Crypto protecting CUI must be FIPS-validated
More in Access Control (3.1)
3.1.1 — Limit who (and what) can get in3.1.2 — Limit what users can do3.1.3 — Control the flow of CUI3.1.4 — Separate duties3.1.5 — Least privilege (especially for admins)3.1.6 — Use non-privileged accounts for routine work3.1.7 — Restrict and log privileged functions3.1.8 — Limit failed logons3.1.9 — Show privacy and security notices3.1.10 — Lock idle screens3.1.11 — End sessions automatically3.1.12 — Monitor and control remote access3.1.14 — Funnel remote access through managed points3.1.15 — Authorize privileged remote actions3.1.16 — Authorize wireless access first3.1.17 — Protect wireless with authentication + encryption3.1.18 — Control mobile device connections3.1.19 — Encrypt CUI on mobile devices3.1.20 — Control connections to external systems3.1.21 — Limit portable storage on external systems3.1.22 — Control what goes on public systems