NIST Special Publication 800-171 Revision 2
Date Published: January 28th, 2021
Withdrawn on May 14, 2024. Superseded by SP 800-171 Rev. 3
Author(s): Ron Ross (NIST), Victoria Pillitteri (NIST), Kelley Dempsey (NIST), Mark Riddle (NARA), Gary Guissanie (IDA)
Note: A Class Deviation is in effect as of May 2, 2024 (DEVIATION 2024O0013). The deviation clause requires contractors, who are subject to 252.204-7012, to comply with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2, instead of the version of NIST SP 800-171 in effect at the time the solicitation is issued or as authorized by the contracting officer. Click Here
3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems)
Control Family: Access Control
Control Type: Basic
SPRS Value: 5
CMMC Level(s):
AC.L1-b.1.i
AC.L2-3.1.1
Top Ten Failed Requirement: No
DIBCAC HIGH Failure Rate (OTS):
70th of 110
Referenced in:
FAR Clause 52.204 b.1.i
DFARS 252.204-7012
Derived From: NIST SP 800-53r4
AC-2
AC-3
AC-17
CSF v1.1:
PR.AC-3
PR.AC-4
PR.PT-3
Discussion:
Access control policies (e.g., identity- or role-based policies, control matrices, and cryptography) control access between active entities or subjects (i.e., users or processes acting on behalf of users) and passive entities or objects (e.g., devices, files, records, and domains) in systems. Access enforcement mechanisms can be employed at the application and service level to provide increased information security. Other systems include systems internal and external to the organization. This requirement focuses on account management for systems and applications. The definition of and enforcement of access authorizations, other than those determined by account type (e.g., privileged verses non-privileged) are addressed in requirement 3.1.2.
Determining Statements (NIST SP 800-171Ar2)
Upon assessment, assessors must determine if-
3.1.1[a] authorized users are identified.
3.1.1[b] processes acting on behalf of authorized users are identified.
3.1.1[c] devices (and other systems) authorized to connect to the system are identified.
3.1.1[d] system access is limited to authorized users.
3.1.1[e] system access is limited to processes acting on behalf of authorized users.
3.1.1[f] system access is limited to authorized devices (including other systems).
Assessors are instructed to-
Examine: [SELECT FROM: Access control policy; procedures addressing account management; system security plan; system design documentation; system configuration settings and associated documentation; list of active system accounts and the name of the individual associated with each account; notifications or records of recently transferred, separated, or terminated employees; list of conditions for group and role membership; list of recently disabled system accounts along with the name of the individual associated with each account; access authorization records; account management compliance reviews; system monitoring records; system audit logs and records; list of devices and systems authorized to connect to organizational systems; other relevant documents or records].
Interview: [SELECT FROM: Personnel with account management responsibilities; system or network administrators; personnel with information security responsibilities].
Test: [SELECT FROM: Organizational processes for managing system accounts; mechanisms for implementing account management].
NIST SP 800-171r2 Control 3.1.1 → MITRE ATT&CK
Total Mappings
Families
Control
Access Enforcement 251 techniques
- T1003OS Credential Dumping
- T1003.001LSASS Memory
- T1003.002Security Account Manager
- T1003.003NTDS
- T1003.004LSA Secrets
- T1003.005Cached Domain Credentials
- T1003.006DCSync
- T1003.007Proc Filesystem
- T1003.008/etc/passwd and /etc/shadow
- T1005Data from Local System
- T1021Remote Services
- T1021.001Remote Desktop Protocol
- T1021.002SMB/Windows Admin Shares
- T1021.003Distributed Component Object Model
- T1021.004SSH
- T1021.005VNC
- T1021.006Windows Remote Management
- T1025Data from Removable Media
- T1036Masquerading
- T1036.003Rename System Utilities
- T1036.005Match Legitimate Name or Location
- T1037Boot or Logon Initialization Scripts
- T1037.002Logon Script (Mac)
- T1037.003Network Logon Script
- T1037.004RC Scripts
- T1037.005Startup Items
- T1041Exfiltration Over C2 Channel
- T1047Windows Management Instrumentation
- T1048Exfiltration Over Alternative Protocol
- T1048.001Exfiltration Over Symmetric Encrypted Non-C2 Protocol
- T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1048.003Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
- T1052Exfiltration Over Physical Medium
- T1052.001Exfiltration over USB
- T1053Scheduled Task/Job
- T1053.002At (Windows)
- T1053.003Cron
- T1053.005Scheduled Task
- T1053.006Systemd Timers
- T1053.007Container Orchestration Job
- T1055Process Injection
- T1055.008Ptrace System Calls
- T1055.009Proc Memory
- T1056.003Web Portal Capture
- T1059Command and Scripting Interpreter
- T1059.001PowerShell
- T1059.002AppleScript
- T1059.003Windows Command Shell
- T1059.004Unix Shell
- T1059.005Visual Basic
- T1059.006Python
- T1059.007JavaScript
- T1059.008Network Device CLI
- T1070Indicator Removal on Host
- T1070.001Clear Windows Event Logs
- T1070.002Clear Linux or Mac System Logs
- T1070.003Clear Command History
- T1070.007Clear Network Connection History and Configurations
- T1070.008Clear Mailbox Data
- T1070.009Clear Persistence
- T1071.004DNS
- T1072Software Deployment Tools
- T1078Valid Accounts
- T1078.002Domain Accounts
- T1078.003Local Accounts
- T1078.004Cloud Accounts
- T1080Taint Shared Content
- T1087.004Cloud Account
- T1090Proxy
- T1090.003Multi-hop Proxy
- T1091Replication Through Removable Media
- T1095Non-Application Layer Protocol
- T1098Account Manipulation
- T1098.001Additional Cloud Credentials
- T1098.002Exchange Email Delegate Permissions
- T1098.003Add Office 365 Global Administrator Role
- T1098.004SSH Authorized Keys
- T1098.005Device Registration
- T1110Brute Force
- T1110.001Password Guessing
- T1110.002Password Cracking
- T1110.003Password Spraying
- T1110.004Credential Stuffing
- T1114Email Collection
- T1114.002Remote Email Collection
- T1133External Remote Services
- T1134Access Token Manipulation
- T1134.001Token Impersonation/Theft
- T1134.002Create Process with Token
- T1134.003Make and Impersonate Token
- T1134.005SID-History Injection
- T1136Create Account
- T1136.001Local Account
- T1136.002Domain Account
- T1136.003Cloud Account
- T1185Browser Session Hijacking
- T1187Forced Authentication
- T1190Exploit Public-Facing Application
- T1197BITS Jobs
- T1199Trusted Relationship
- T1200Hardware Additions
- T1205Traffic Signaling
- T1205.001Port Knocking
- T1210Exploitation of Remote Services
- T1213Data from Information Repositories
- T1213.001Confluence
- T1213.002Sharepoint
- T1213.003Code Repositories
- T1218Signed Binary Proxy Execution
- T1218.002Control Panel
- T1218.007Msiexec
- T1218.012Verclsid
- T1219Remote Access Software
- T1222File and Directory Permissions Modification
- T1222.001Windows File and Directory Permissions Modification
- T1222.002Linux and Mac File and Directory Permissions Modification
- T1484Domain Policy Modification
- T1485Data Destruction
- T1486Data Encrypted for Impact
- T1489Service Stop
- T1490Inhibit System Recovery
- T1491Defacement
- T1491.001Internal Defacement
- T1491.002External Defacement
- T1495Firmware Corruption
- T1498Network Denial of Service
- T1498.001Direct Network Flood
- T1498.002Reflection Amplification
- T1499Endpoint Denial of Service
- T1499.001OS Exhaustion Flood
- T1499.002Service Exhaustion Flood
- T1499.003Application Exhaustion Flood
- T1499.004Application or System Exploitation
- T1505Server Software Component
- T1505.002Transport Agent
- T1505.003Web Shell
- T1505.004IIS Components
- T1505.005Terminal Services DLL
- T1525Implant Internal Image
- T1528Steal Application Access Token
- T1530Data from Cloud Storage Object
- T1537Transfer Data to Cloud Account
- T1538Cloud Service Dashboard
- T1539Steal Web Session Cookie
- T1542Pre-OS Boot
- T1542.001System Firmware
- T1542.003Bootkit
- T1542.004ROMMONkit
- T1542.005TFTP Boot
- T1543Create or Modify System Process
- T1543.001Launch Agent
- T1543.002Systemd Service
- T1543.003Windows Service
- T1543.004Launch Daemon
- T1546.003Windows Management Instrumentation Event Subscription
- T1546.004Unix Shell Configuration Modification
- T1546.013PowerShell Profile
- T1547.003Time Providers
- T1547.004Winlogon Helper DLL
- T1547.006Kernel Modules and Extensions
- T1547.007Re-opened Applications
- T1547.009Shortcut Modification
- T1547.012Print Processors
- T1547.013XDG Autostart Entries
- T1548Abuse Elevation Control Mechanism
- T1548.002Bypass User Account Control
- T1548.003Sudo and Sudo Caching
- T1550Use Alternate Authentication Material
- T1550.002Pass the Hash
- T1550.003Pass the Ticket
- T1552Unsecured Credentials
- T1552.002Credentials in Registry
- T1552.005Cloud Instance Metadata API
- T1552.007Container API
- T1553Subvert Trust Controls
- T1553.003SIP and Trust Provider Hijacking
- T1553.006Code Signing Policy Modification
- T1556Modify Authentication Process
- T1556.001Domain Controller Authentication
- T1556.003Pluggable Authentication Modules
- T1556.004Network Device Authentication
- T1556.006Multi-Factor Authentication
- T1556.007Hybrid Identity
- T1557Adversary-in-the-Middle
- T1557.001LLMNR/NBT-NS Poisoning and SMB Relay
- T1557.002ARP Cache Poisoning
- T1557.003DHCP Spoofing
- T1558Steal or Forge Kerberos Tickets
- T1558.001Golden Ticket
- T1558.002Silver Ticket
- T1558.003Kerberoasting
- T1558.004AS-REP Roasting
- T1559Inter-Process Communication
- T1559.001Component Object Model
- T1561Disk Wipe
- T1561.001Disk Content Wipe
- T1561.002Disk Structure Wipe
- T1562Impair Defenses
- T1562.001Disable or Modify Tools
- T1562.002Disable Windows Event Logging
- T1562.004Disable or Modify System Firewall
- T1562.006Indicator Blocking
- T1562.007Disable or Modify Cloud Firewall
- T1562.008Disable Cloud Logs
- T1562.009Safe Mode Boot
- T1563Remote Service Session Hijacking
- T1563.001SSH Hijacking
- T1563.002RDP Hijacking
- T1564.004NTFS File Attributes
- T1565Data Manipulation
- T1565.001Stored Data Manipulation
- T1565.003Runtime Data Manipulation
- T1567Exfiltration Over Web Service
- T1569System Services
- T1569.001Launchctl
- T1569.002Service Execution
- T1570Lateral Tool Transfer
- T1572Protocol Tunneling
- T1574Hijack Execution Flow
- T1574.004Dylib Hijacking
- T1574.005Executable Installer File Permissions Weakness
- T1574.007Path Interception by PATH Environment Variable
- T1574.008Path Interception by Search Order Hijacking
- T1574.009Path Interception by Unquoted Path
- T1574.010Services File Permissions Weakness
- T1574.012COR_PROFILER
- T1578Modify Cloud Compute Infrastructure
- T1578.001Create Snapshot
- T1578.002Create Cloud Instance
- T1578.003Delete Cloud Instance
- T1580Cloud Infrastructure Discovery
- T1599Network Boundary Bridging
- T1599.001Network Address Translation Traversal
- T1601Modify System Image
- T1601.001Patch System Image
- T1601.002Downgrade System Image
- T1602Data from Configuration Repository
- T1602.001SNMP (MIB Dump)
- T1602.002Network Device Configuration Dump
- T1606Forge Web Credentials
- T1606.001Web Cookies
- T1606.002SAML Tokens
- T1609Container Administration Command
- T1610Deploy Container
- T1611Escape to Host
- T1612Build Image on Host
- T1613Container and Resource Discovery
- T1619Cloud Storage Object Discovery
- T1622Debugger Evasion
- T1647Plist File Modification
- T1648Serverless Execution
Account Management 194 techniques
- T1003OS Credential Dumping
- T1003.001LSASS Memory
- T1003.002Security Account Manager
- T1003.003NTDS
- T1003.004LSA Secrets
- T1003.005Cached Domain Credentials
- T1003.006DCSync
- T1003.007Proc Filesystem
- T1003.008/etc/passwd and /etc/shadow
- T1005Data from Local System
- T1021Remote Services
- T1021.001Remote Desktop Protocol
- T1021.002SMB/Windows Admin Shares
- T1021.003Distributed Component Object Model
- T1021.004SSH
- T1021.005VNC
- T1021.006Windows Remote Management
- T1025Data from Removable Media
- T1036Masquerading
- T1036.003Rename System Utilities
- T1036.005Match Legitimate Name or Location
- T1041Exfiltration Over C2 Channel
- T1047Windows Management Instrumentation
- T1048Exfiltration Over Alternative Protocol
- T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1048.003Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
- T1052Exfiltration Over Physical Medium
- T1052.001Exfiltration over USB
- T1053Scheduled Task/Job
- T1053.002At (Windows)
- T1053.003Cron
- T1053.005Scheduled Task
- T1053.006Systemd Timers
- T1053.007Container Orchestration Job
- T1055Process Injection
- T1055.008Ptrace System Calls
- T1056.003Web Portal Capture
- T1059Command and Scripting Interpreter
- T1059.001PowerShell
- T1059.002AppleScript
- T1059.003Windows Command Shell
- T1059.004Unix Shell
- T1059.005Visual Basic
- T1059.006Python
- T1059.007JavaScript
- T1059.008Network Device CLI
- T1068Exploitation for Privilege Escalation
- T1070Indicator Removal on Host
- T1070.001Clear Windows Event Logs
- T1070.002Clear Linux or Mac System Logs
- T1070.003Clear Command History
- T1070.007Clear Network Connection History and Configurations
- T1070.008Clear Mailbox Data
- T1070.009Clear Persistence
- T1072Software Deployment Tools
- T1078Valid Accounts
- T1078.001Default Accounts
- T1078.002Domain Accounts
- T1078.003Local Accounts
- T1078.004Cloud Accounts
- T1087.004Cloud Account
- T1098Account Manipulation
- T1098.001Additional Cloud Credentials
- T1098.002Exchange Email Delegate Permissions
- T1098.003Add Office 365 Global Administrator Role
- T1098.005Device Registration
- T1110Brute Force
- T1110.001Password Guessing
- T1110.002Password Cracking
- T1110.003Password Spraying
- T1110.004Credential Stuffing
- T1134Access Token Manipulation
- T1134.001Token Impersonation/Theft
- T1134.002Create Process with Token
- T1134.003Make and Impersonate Token
- T1136Create Account
- T1136.001Local Account
- T1136.002Domain Account
- T1136.003Cloud Account
- T1185Browser Session Hijacking
- T1190Exploit Public-Facing Application
- T1197BITS Jobs
- T1210Exploitation of Remote Services
- T1212Exploitation for Credential Access
- T1213Data from Information Repositories
- T1213.001Confluence
- T1213.002Sharepoint
- T1213.003Code Repositories
- T1218Signed Binary Proxy Execution
- T1218.007Msiexec
- T1222File and Directory Permissions Modification
- T1222.001Windows File and Directory Permissions Modification
- T1222.002Linux and Mac File and Directory Permissions Modification
- T1484Domain Policy Modification
- T1489Service Stop
- T1495Firmware Corruption
- T1505Server Software Component
- T1505.002Transport Agent
- T1505.003Web Shell
- T1505.005Terminal Services DLL
- T1525Implant Internal Image
- T1528Steal Application Access Token
- T1530Data from Cloud Storage Object
- T1537Transfer Data to Cloud Account
- T1538Cloud Service Dashboard
- T1542Pre-OS Boot
- T1542.001System Firmware
- T1542.003Bootkit
- T1542.005TFTP Boot
- T1543Create or Modify System Process
- T1543.001Launch Agent
- T1543.002Systemd Service
- T1543.003Windows Service
- T1543.004Launch Daemon
- T1546.003Windows Management Instrumentation Event Subscription
- T1547.004Winlogon Helper DLL
- T1547.006Kernel Modules and Extensions
- T1547.009Shortcut Modification
- T1547.012Print Processors
- T1547.013XDG Autostart Entries
- T1548Abuse Elevation Control Mechanism
- T1548.002Bypass User Account Control
- T1548.003Sudo and Sudo Caching
- T1550Use Alternate Authentication Material
- T1550.002Pass the Hash
- T1550.003Pass the Ticket
- T1552Unsecured Credentials
- T1552.001Credentials In Files
- T1552.002Credentials in Registry
- T1552.004Private Keys
- T1552.006Group Policy Preferences
- T1552.007Container API
- T1553Subvert Trust Controls
- T1553.006Code Signing Policy Modification
- T1556Modify Authentication Process
- T1556.001Domain Controller Authentication
- T1556.003Pluggable Authentication Modules
- T1556.004Network Device Authentication
- T1556.005Reversible Encryption
- T1556.006Multi-Factor Authentication
- T1556.007Hybrid Identity
- T1558Steal or Forge Kerberos Tickets
- T1558.001Golden Ticket
- T1558.002Silver Ticket
- T1558.003Kerberoasting
- T1558.004AS-REP Roasting
- T1559Inter-Process Communication
- T1559.001Component Object Model
- T1562Impair Defenses
- T1562.001Disable or Modify Tools
- T1562.002Disable Windows Event Logging
- T1562.004Disable or Modify System Firewall
- T1562.006Indicator Blocking
- T1562.007Disable or Modify Cloud Firewall
- T1562.008Disable Cloud Logs
- T1562.009Safe Mode Boot
- T1563Remote Service Session Hijacking
- T1563.001SSH Hijacking
- T1563.002RDP Hijacking
- T1567Exfiltration Over Web Service
- T1569System Services
- T1569.001Launchctl
- T1569.002Service Execution
- T1574Hijack Execution Flow
- T1574.004Dylib Hijacking
- T1574.005Executable Installer File Permissions Weakness
- T1574.007Path Interception by PATH Environment Variable
- T1574.008Path Interception by Search Order Hijacking
- T1574.009Path Interception by Unquoted Path
- T1574.010Services File Permissions Weakness
- T1574.012COR_PROFILER
- T1578Modify Cloud Compute Infrastructure
- T1578.001Create Snapshot
- T1578.002Create Cloud Instance
- T1578.003Delete Cloud Instance
- T1580Cloud Infrastructure Discovery
- T1585.003Cloud Accounts
- T1586.003Cloud Accounts
- T1599Network Boundary Bridging
- T1599.001Network Address Translation Traversal
- T1601Modify System Image
- T1601.001Patch System Image
- T1601.002Downgrade System Image
- T1606Forge Web Credentials
- T1606.001Web Cookies
- T1606.002SAML Tokens
- T1609Container Administration Command
- T1610Deploy Container
- T1611Escape to Host
- T1612Build Image on Host
- T1613Container and Resource Discovery
- T1619Cloud Storage Object Discovery
- T1621Multi-Factor Authentication Request Generation
- T1648Serverless Execution
Remote Access 75 techniques
- T1020.001Traffic Duplication
- T1021Remote Services
- T1021.001Remote Desktop Protocol
- T1021.002SMB/Windows Admin Shares
- T1021.003Distributed Component Object Model
- T1021.004SSH
- T1021.005VNC
- T1021.006Windows Remote Management
- T1037Boot or Logon Initialization Scripts
- T1037.001Logon Script (Windows)
- T1040Network Sniffing
- T1047Windows Management Instrumentation
- T1059Command and Scripting Interpreter
- T1059.001PowerShell
- T1059.002AppleScript
- T1059.003Windows Command Shell
- T1059.004Unix Shell
- T1059.005Visual Basic
- T1059.006Python
- T1059.007JavaScript
- T1059.008Network Device CLI
- T1070Indicator Removal on Host
- T1070.001Clear Windows Event Logs
- T1070.002Clear Linux or Mac System Logs
- T1070.008Clear Mailbox Data
- T1114Email Collection
- T1114.001Local Email Collection
- T1114.002Remote Email Collection
- T1114.003Email Forwarding Rule
- T1119Automated Collection
- T1133External Remote Services
- T1137Office Application Startup
- T1137.002Office Test
- T1213Data from Information Repositories
- T1213.001Confluence
- T1213.002Sharepoint
- T1219Remote Access Software
- T1505.004IIS Components
- T1505.005Terminal Services DLL
- T1530Data from Cloud Storage Object
- T1537Transfer Data to Cloud Account
- T1543Create or Modify System Process
- T1543.003Windows Service
- T1543.004Launch Daemon
- T1547.003Time Providers
- T1547.004Winlogon Helper DLL
- T1547.009Shortcut Modification
- T1547.012Print Processors
- T1547.013XDG Autostart Entries
- T1550.001Application Access Token
- T1552Unsecured Credentials
- T1552.002Credentials in Registry
- T1552.004Private Keys
- T1552.007Container API
- T1557Adversary-in-the-Middle
- T1557.002ARP Cache Poisoning
- T1558Steal or Forge Kerberos Tickets
- T1558.002Silver Ticket
- T1558.003Kerberoasting
- T1558.004AS-REP Roasting
- T1563Remote Service Session Hijacking
- T1563.001SSH Hijacking
- T1563.002RDP Hijacking
- T1565Data Manipulation
- T1565.001Stored Data Manipulation
- T1565.002Transmitted Data Manipulation
- T1602Data from Configuration Repository
- T1602.001SNMP (MIB Dump)
- T1602.002Network Device Configuration Dump
- T1609Container Administration Command
- T1610Deploy Container
- T1612Build Image on Host
- T1613Container and Resource Discovery
- T1619Cloud Storage Object Discovery
- T1647Plist File Modification
FURTHER DISCUSSION
Identify users, processes, and devices that are allowed to use company computers and can log on to the company network. Automated updates and other automatic processes should be associated with the user who initiated (authorized) the process. Limit the devices (e.g., printers) that can be accessed by company computers. Set up your system so that only authorized users, processes, and devices can access the company network.
This requirement, AC.L2-3.1.1, controls system access based on user, process, or device identity. AC.L2-3.1.1 leverages IA.L2-3.5.1 which provides a vetted and trusted identity for access control.
Example 1
Your company maintains a list of all personnel authorized to use company information systems, including those that store, process, and transmit CUI [a]. This list is used to support identification and authentication activities conducted by IT when authorizing access to systems [a,d].
Example 2
A coworker wants to buy a new multi-function printer/scanner/fax device and make it available on the company network within the CUI enclave. You explain that the company controls system and device access to the network and will prevent network access by unauthorized systems and devices [c]. You help the coworker submit a ticket that asks for the printer to be granted access to the network, and appropriate leadership approves the device [f].
Potential Assessment Considerations
Is a list of authorized users maintained that defines their identities and roles [a]?
Are account requests authorized before system access is granted [d,e,f]?
ISO/IEC 27001:2013
A.9.2.1 User registration and de-registration
A.9.2.2 User access provisioning
A.9.2.3 Management of privileged access rights
A.9.2.5 Review of user access rights
A.9.2.6 Removal or adjustment of access rights
A.6.2.2 Teleworking
A.9.1.2 Access to networks and network services
A.9.4.1 Information access restriction
A.9.4.4 Use of privileged utility programs
A.9.4.5 Access control to program source code
A.13.1.1 Network controls
A.14.1.2 Securing application services on public networks
A.14.1.3 Protecting application services transactions
A.18.1.3 Protection of records
A.6.2.1 Mobile device policy
A.6.2.2 Teleworking
A.13.1.1 Network controls
A.13.2.1 Information transfer policies and procedures
A.14.1.2 Securing application services on public networks
NIST SP 800-171r2 Control 3.1.1 → MITRE ATT&CK
Summary
- Total mappings: 520
- Families: 3
- Outer ring: Technique ID + name
Family counts
- Account Management: 194 techniques
- Access Enforcement: 251 techniques
- Remote Access: 75 techniques
Usage notes
- Click a family or technique to zoom in.
- Click the center to zoom back out.
- Hover to view technique details.
Frameworks & Controls
3.1.3: Control the flow of CUI in accordance with approved authorizations
3.1.6: Use non-privileged accounts or roles when accessing nonsecurity functions
3.1.9: Provide privacy and security notices consistent with applicable CUI rules
3.1.11: Terminate (automatically) a user session after a defined condition
3.1.13: Employ cryptographic mechanisms to protect the confidentiality of remote access sessions
3.1.14: Route remote access via managed access control points
3.1.16: Authorize wireless access prior to allowing such connections
3.1.17: Protect wireless access using authentication and encryption
3.1.19: Encrypt CUI on mobile devices and mobile computing platforms
3.1.20: Verify and control/limit connections to and use of external systems
3.1.21: Limit use of portable storage devices on external systems
3.1.22: Control CUI posted or processed on publicly accessible systems