Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family AC

AC-17Remote Access

Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and Authorize each type of remote access to the system prior to allowing such connections.

Last updated: 22 August 2026 07:11 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (81)

Weaknesses this control addresses (7)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-862Missing Authorization10,200+Mandating authorization prior to allowing remote connections addresses missing authorization for remote access.
CWE-284Improper Access Control6,900+Requiring prior authorization for each remote access type prevents improper access control over remote connections.
CWE-863Incorrect Authorization3,900+The authorization process and usage restrictions help prevent incorrect authorization for remote access types.
CWE-285Improper Authorization1,500+Explicitly mandates authorizing remote access types before permitting connections, directly mitigating improper authorization.
CWE-288Authentication Bypass Using an Alternate Path or Channel600+Authorizing remote access reduces the ability to bypass authentication via unauthorized alternate remote channels.
CWE-420Unprotected Alternate Channel39Usage restrictions and authorization for remote access protect against unprotected alternate channels.
CWE-424Improper Protection of Alternate Path35Documenting requirements and authorizing remote access ensures proper protection of alternate paths.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2025-61932 KEV9.99.80.0263good
CVE-2024-40515 7.49.80.0066good
CVE-2024-38886 7.49.80.0064good
CVE-2026-2611 6.79.60.0038good
CVE-2025-59159 6.69.60.0024good
CVE-2024-40516 6.58.80.0033good
CVE-2026-338756.59.30.0027good
CVE-2026-356436.58.80.0037good
CVE-2026-487456.59.30.0032good
CVE-2024-26131 6.38.40.0047good
CVE-2025-23222 6.28.40.0024good
CVE-2024-49579 6.18.10.0042good
CVE-2026-40434 6.08.10.0023good
CVE-2023-51440 5.97.50.0060good
CVE-2025-13086 5.97.50.0063good
CVE-2025-40820 5.97.50.0048good
CVE-2019-25613 5.97.50.0052good
CVE-2024-1621 5.87.50.0036good
CVE-2026-44698 5.68.30.0014good
CVE-2026-44894 5.67.50.0014good
CVE-2026-6734 5.67.50.0034good
CVE-2025-9999 5.57.60.0016good
CVE-2026-556605.57.60.0020good
CVE-2026-45245 5.47.40.0033good
CVE-2025-25305 5.27.00.0024good

Other controls in family AC

AC-1 AC-10 AC-11 AC-12 AC-13 AC-14 AC-15 AC-16 AC-18 AC-19 AC-2 AC-20 AC-21 AC-22 AC-23 AC-24 AC-25 AC-3 AC-4 AC-5 AC-6 AC-7 AC-8 AC-9