NIST 800-53 r5 · Controls catalogue · Family AC
AC-17Remote Access
Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and Authorize each type of remote access to the system prior to allowing such connections.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (81)
- T1020.001 Traffic Duplication Exfiltration
- T1021 Remote Services Lateral Movement
- T1021.001 Remote Desktop Protocol Lateral Movement
- T1021.002 SMB/Windows Admin Shares Lateral Movement
- T1021.003 Distributed Component Object Model Lateral Movement
- T1021.004 SSH Lateral Movement
- T1021.005 VNC Lateral Movement
- T1021.006 Windows Remote Management Lateral Movement
- T1021.008 Direct Cloud VM Connections Lateral Movement
- T1037 Boot or Logon Initialization Scripts Persistence, Privilege Escalation
- T1037.001 Logon Script (Windows) Persistence, Privilege Escalation
- T1040 Network Sniffing Credential Access, Discovery
- T1047 Windows Management Instrumentation Execution
- T1059 Command and Scripting Interpreter Execution
- T1059.001 PowerShell Execution
- T1059.002 AppleScript Execution
- T1059.003 Windows Command Shell Execution
- T1059.004 Unix Shell Execution
- T1059.005 Visual Basic Execution
- T1059.006 Python Execution
- T1059.007 JavaScript Execution
- T1059.008 Network Device CLI Execution
- T1070 Indicator Removal Stealth
- T1070.008 Clear Mailbox Data Stealth
- T1114 Email Collection Collection
- T1114.001 Local Email Collection Collection
- T1114.002 Remote Email Collection Collection
- T1114.003 Email Forwarding Rule Collection
- T1119 Automated Collection Collection
- T1127.002 ClickOnce Stealth, Execution
- T1133 External Remote Services Persistence, Initial Access
- T1137 Office Application Startup Persistence
- T1137.002 Office Test Persistence
- T1213 Data from Information Repositories Collection
- T1213.001 Confluence Collection
- T1213.002 Sharepoint Collection
- T1213.005 Messaging Applications Collection
- T1219 Remote Access Tools Command And Control
- T1505.004 IIS Components Persistence
- T1505.005 Terminal Services DLL Persistence
- T1530 Data from Cloud Storage Collection
- T1537 Transfer Data to Cloud Account Exfiltration
- T1543 Create or Modify System Process Persistence, Privilege Escalation
- T1547.003 Time Providers Persistence, Privilege Escalation
- T1547.004 Winlogon Helper DLL Persistence, Privilege Escalation
- T1547.009 Shortcut Modification Persistence, Privilege Escalation
- T1547.012 Print Processors Persistence, Privilege Escalation
- T1547.013 XDG Autostart Entries Persistence, Privilege Escalation
- T1550.001 Application Access Token Lateral Movement
- T1552 Unsecured Credentials Credential Access
Weaknesses this control addresses (7)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-862 | Missing Authorization | 10,200+ | Mandating authorization prior to allowing remote connections addresses missing authorization for remote access. |
CWE-284 | Improper Access Control | 6,900+ | Requiring prior authorization for each remote access type prevents improper access control over remote connections. |
CWE-863 | Incorrect Authorization | 3,900+ | The authorization process and usage restrictions help prevent incorrect authorization for remote access types. |
CWE-285 | Improper Authorization | 1,500+ | Explicitly mandates authorizing remote access types before permitting connections, directly mitigating improper authorization. |
CWE-288 | Authentication Bypass Using an Alternate Path or Channel | 600+ | Authorizing remote access reduces the ability to bypass authentication via unauthorized alternate remote channels. |
CWE-420 | Unprotected Alternate Channel | 39 | Usage restrictions and authorization for remote access protect against unprotected alternate channels. |
CWE-424 | Improper Protection of Alternate Path | 35 | Documenting requirements and authorizing remote access ensures proper protection of alternate paths. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2025-61932 KEV | 9.9 | 9.8 | 0.0263 | good |
CVE-2024-40515 UPD | 7.4 | 9.8 | 0.0066 | good |
CVE-2024-38886 UPD | 7.4 | 9.8 | 0.0064 | good |
CVE-2026-2611 UPD | 6.7 | 9.6 | 0.0038 | good |
CVE-2025-59159 UPD | 6.6 | 9.6 | 0.0024 | good |
CVE-2024-40516 UPD | 6.5 | 8.8 | 0.0033 | good |
CVE-2026-33875 | 6.5 | 9.3 | 0.0027 | good |
CVE-2026-35643 | 6.5 | 8.8 | 0.0037 | good |
CVE-2026-48745 | 6.5 | 9.3 | 0.0032 | good |
CVE-2024-26131 UPD | 6.3 | 8.4 | 0.0047 | good |
CVE-2025-23222 UPD | 6.2 | 8.4 | 0.0024 | good |
CVE-2024-49579 UPD | 6.1 | 8.1 | 0.0042 | good |
CVE-2026-40434 UPD | 6.0 | 8.1 | 0.0023 | good |
CVE-2023-51440 UPD | 5.9 | 7.5 | 0.0060 | good |
CVE-2025-13086 UPD | 5.9 | 7.5 | 0.0063 | good |
CVE-2025-40820 UPD | 5.9 | 7.5 | 0.0048 | good |
CVE-2019-25613 UPD | 5.9 | 7.5 | 0.0052 | good |
CVE-2024-1621 UPD | 5.8 | 7.5 | 0.0036 | good |
CVE-2026-44698 UPD | 5.6 | 8.3 | 0.0014 | good |
CVE-2026-44894 UPD | 5.6 | 7.5 | 0.0014 | good |
CVE-2026-6734 UPD | 5.6 | 7.5 | 0.0034 | good |
CVE-2025-9999 UPD | 5.5 | 7.6 | 0.0016 | good |
CVE-2026-55660 | 5.5 | 7.6 | 0.0020 | good |
CVE-2026-45245 UPD | 5.4 | 7.4 | 0.0033 | good |
CVE-2025-25305 UPD | 5.2 | 7.0 | 0.0024 | good |