Privileged Remote Access
Practice statement
Authorize remote execution of privileged commands and remote access to security-relevant information.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.15.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(4)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
privileged commands authorized for remote execution are identified;
1 example covers this
- [b]
security-relevant information authorized to be accessed remotely is identified;
1 example covers this
- [c]
the execution of the identified privileged commands via remote access is authorized; and
1 example covers this
- [d]
access to the identified security-relevant information via remote access is authorized.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
AC.L2-3.1.15Privileged Remote Access
Authorize remote execution of privileged commands and remote access to security-relevant information.
[a]
privileged commands authorized for remote execution are identified;[b]
security-relevant information authorized to be accessed remotely is identified;[c]
the execution of the identified privileged commands via remote access is authorized; and[d]
access to the identified security-relevant information via remote access is authorized.
Privileged remote admin only via PAW with ticketed authorization
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses all Privileged Remote Access objectives.
Authorize. Remote privileged commands require (1) eligible privileged role activation with ticket ID and (2) landing on a PAW/jump that is itself gated by phishing-resistant auth. Standing “always-on” domain admin from home is prohibited.
Security functions remotely. IdP and firewall admin consoles are reachable only from the PAW VLAN. Session recording captures privileged jump activity.
Maintenance. Monthly review of remote privileged sessions outside change windows. Quarterly confirm unmanaged devices cannot open admin blades.
Accepted gap. Emergency break-glass can skip the ticket field during Sev-1; activation still alerts security and is reconciled within 24 hours.
What the evidence looks like
- PIM activation policy requiring ticket + MFA
- Network ACL showing admin consoles PAW-only
- Session recording sample for a privileged remote change
- Sev-1 break-glass reconciliation ticket
Environment
Server admins remote; Entra PIM; jump hosts.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.