PlumbTrackLive demoGRC Risk System

← internal audit

Audit — AC-17 — Remote Access

Framework: NIST SP 800-53 Rev.5 AC-17 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Examine the remote access policy to confirm it documents usage restrictions, connection/configuration requirements, and the approved remote access methods (e.g., managed VPN) permitted for each type of remote connection.
Examine For a sample of users with remote access, confirm remote access was authorized/approved before it was granted and that the entitlement is tied to a documented business need.
Test Confirm remote access sessions are protected with approved cryptography (e.g., IPsec/TLS VPN) by inspecting the VPN/gateway configuration and, where feasible, observing an encrypted session negotiate.
Test Confirm multi-factor authentication is enforced for remote network access; attempt a remote login with a test account and verify a second factor is required (CIS v8 6.4).
Examine Confirm remote access is routed through a limited number of managed access control points (concentrators/gateways) rather than allowing direct or split-tunnel connections that bypass monitoring.
Test Confirm remote access sessions are logged and monitored, with connection records (user, time, source, duration) available for review and alerting on anomalous access (CIS v8 13.x).
Examine Confirm remote sessions enforce an idle/session timeout and automatic disconnect/re-authentication per the defined threshold.