Skip to content
ControlVerdict
AC.L2-3.1.15CMMC Level 2Level 2

Privileged Remote Access

Practice statement

Authorize remote execution of privileged commands and remote access to security-relevant information.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.15.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(4)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    privileged commands authorized for remote execution are identified;

    1 example covers this

  2. [b]

    security-relevant information authorized to be accessed remotely is identified;

    1 example covers this

  3. [c]

    the execution of the identified privileged commands via remote access is authorized; and

    1 example covers this

  4. [d]

    access to the identified security-relevant information via remote access is authorized.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    AC.L2-3.1.15Privileged Remote Access
    Authorize remote execution of privileged commands and remote access to security-relevant information.
    • [a]

      privileged commands authorized for remote execution are identified;
    • [b]

      security-relevant information authorized to be accessed remotely is identified;
    • [c]

      the execution of the identified privileged commands via remote access is authorized; and
    • [d]

      access to the identified security-relevant information via remote access is authorized.

    Privileged remote admin only via PAW with ticketed authorization

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses all Privileged Remote Access objectives.

    Authorize. Remote privileged commands require (1) eligible privileged role activation with ticket ID and (2) landing on a PAW/jump that is itself gated by phishing-resistant auth. Standing “always-on” domain admin from home is prohibited.

    Security functions remotely. IdP and firewall admin consoles are reachable only from the PAW VLAN. Session recording captures privileged jump activity.

    Maintenance. Monthly review of remote privileged sessions outside change windows. Quarterly confirm unmanaged devices cannot open admin blades.

    Accepted gap. Emergency break-glass can skip the ticket field during Sev-1; activation still alerts security and is reconciled within 24 hours.

    What the evidence looks like

    • PIM activation policy requiring ticket + MFA
    • Network ACL showing admin consoles PAW-only
    • Session recording sample for a privileged remote change
    • Sev-1 break-glass reconciliation ticket

    Environment

    Server admins remote; Entra PIM; jump hosts.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.