800-53|AC-17(1)

Title

AUTOMATED MONITORING / CONTROL

Description

The information system monitors and controls remote access methods.

Supplemental

Automated monitoring and control of remote access sessions allows organizations to detect cyber attacks and also ensure ongoing compliance with remote access policies by auditing connection activities of remote users on a variety of information system components (e.g., servers, workstations, notebook computers, smart phones, and tablets).

Reference Item Details

Related: AU-12,AU-2

Category: ACCESS CONTROL

Parent Title: REMOTE ACCESS

Family: ACCESS CONTROL

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.6.1 Ensure 'SSH source restriction' is set to an authorized IP addressCiscoCIS Cisco ASA 9.x Firewall L1 v1.1.0
1.6.2 Ensure 'SSH version 2' is enabledCiscoCIS Cisco ASA 9.x Firewall L1 v1.1.0
1.11 UBTU-24-100300UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.12 UBTU-24-100310UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.38 UBTU-24-200090UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.46 UBTU-22-251010UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.47 UBTU-22-251015UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.118 UBTU-22-652015UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.162 RHEL-09-251010UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.163 RHEL-09-251015UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.207 RHEL-09-255030UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.361 RHEL-09-652030UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
2.2.32 Ensure 'Deny log on through Remote Desktop Services' is set to 'Guests, Local account, Enterprise Admins Group, and Domain Admins Group' (STIG MS only)WindowsCIS Microsoft Windows Server 2016 STIG v3.0.0 STIG MS
2.2.36 Ensure 'Deny log on through Remote Desktop Services' is set to 'Guests, Local account, Enterprise Admins Group, and Domain Admins Group' (STIG MS only)WindowsCIS Microsoft Windows Server 2022 STIG v2.0.0 STIG MS
2.8 Ensure TLS authentication for Docker daemon is configuredUnixCIS Docker v1.8.0 L1 OS Linux
2.8.1 Ensure 'Allow remote access connections to this machine' is set to 'Disabled'WindowsCIS Google Chrome L1 v3.0.0
2.8.2 (L1) Ensure 'Allow remote users to interact with elevated windows in remote assistance sessions' is set to 'Disabled'WindowsCIS Google Chrome L1 v3.0.0
2.8.3 (L1) Ensure 'Configure the required domain names for remote access clients' is set to 'Enabled' with a domain definedWindowsCIS Google Chrome L1 v3.0.0
2.8.4 (L1) Ensure 'Enable curtaining of remote access hosts' is set to 'Disabled'WindowsCIS Google Chrome L1 v3.0.0
2.8.5 (L1) Ensure 'Enable firewall traversal from remote access host' is set to 'Disabled'WindowsCIS Google Chrome L1 v3.0.0
2.8.6 (L1) Ensure 'Enable or disable PIN-less authentication for remote access hosts' is set to 'Disabled'WindowsCIS Google Chrome L1 v3.0.0
2.8.7 (L1) Ensure 'Enable the use of relay servers by the remote access host' is set to 'Disabled'.WindowsCIS Google Chrome L1 v3.0.0
2.13.1 (L1) Ensure 'Enable or disable PIN-less authentication for remote access hosts' is set to 'Disabled'WindowsCIS Google Chrome Group Policy v1.0.0 L1
2.13.2 (L1) Ensure 'Enable the use of relay servers by the remote access host' is set to 'Disabled'.WindowsCIS Google Chrome Group Policy v1.0.0 L1
2.13.3 Ensure 'Allow remote access connections to this machine' is set to 'Disabled'WindowsCIS Google Chrome Group Policy v1.0.0 L1
2.13.4 (L1) Ensure 'Allow remote users to interact with elevated windows in remote assistance sessions' is set to 'Disabled'WindowsCIS Google Chrome Group Policy v1.0.0 L1
2.13.5 (L1) Ensure 'Configure the required domain names for remote access clients' is set to 'Enabled' with a domain definedWindowsCIS Google Chrome Group Policy v1.0.0 L1
2.13.6 (L1) Ensure 'Enable firewall traversal from remote access host' is set to 'Disabled'WindowsCIS Google Chrome Group Policy v1.0.0 L1
2.13.7 (L1) Ensure 'Enable curtaining of remote access hosts' is set to 'Disabled'WindowsCIS Google Chrome Group Policy v1.0.0 L1
2.32 Ensure 'Allow remote debugging' is set to 'Disabled'WindowsCIS Google Chrome L1 v3.0.0
2.68 Ensure 'Allow remote debugging' is set to 'Disabled'WindowsCIS Google Chrome Group Policy v1.0.0 L1
3.2 Ensure 'Allow unmanaged devices' is set to 'False'WindowsCIS Microsoft Exchange Server 2019 L1 MDM v1.0.0
3.2.1.16 Ensure 'Allow adding VPN configurations' is set to 'Disabled'MDMAirWatch - CIS Apple iPadOS 18 v1.0.0 L1 Institutionally Owned
3.2.1.16 Ensure 'Allow adding VPN configurations' is set to 'Disabled'MDMMobileIron - CIS Apple iOS 17 Institution Owned L1
3.2.1.16 Ensure 'Allow adding VPN configurations' is set to 'Disabled'MDMAirWatch - CIS Apple iPadOS 17 Institutionally Owned L1
3.2.1.16 Ensure 'Allow adding VPN configurations' is set to 'Disabled'MDMAirWatch - CIS Apple iOS 18 v1.0.0 L1 Institution Owned
3.2.1.16 Ensure 'Allow adding VPN configurations' is set to 'Disabled'MDMAirWatch - CIS Apple iOS 17 Institution Owned L1
3.2.1.16 Ensure 'Allow adding VPN configurations' is set to 'Disabled'MDMMobileIron - CIS Apple iOS 18 v1.0.0 L1 Institution Owned
3.2.1.16 Ensure 'Allow adding VPN configurations' is set to 'Disabled'MDMMobileIron - CIS Apple iPadOS 17 Institutionally Owned L1
3.2.1.16 Ensure 'Allow adding VPN configurations' is set to 'Disabled'MDMMobileIron - CIS Apple iPadOS 18 v1.0.0 L1 Institutionally Owned
3.2.1.29 Ensure 'Allow proximity based password sharing requests' is set to 'Disabled'MDMAirWatch - CIS Apple iOS 18 v1.0.0 L1 Institution Owned
3.2.1.29 Ensure 'Allow proximity based password sharing requests' is set to 'Disabled'MDMAirWatch - CIS Apple iOS 17 Institution Owned L1
3.2.1.29 Ensure 'Allow proximity based password sharing requests' is set to 'Disabled'MDMMobileIron - CIS Apple iOS 17 Institution Owned L1
3.2.1.29 Ensure 'Allow proximity based password sharing requests' is set to 'Disabled'MDMAirWatch - CIS Apple iPadOS 17 Institutionally Owned L1
3.2.1.29 Ensure 'Allow proximity based password sharing requests' is set to 'Disabled'MDMMobileIron - CIS Apple iPadOS 17 Institutionally Owned L1
3.2.1.29 Ensure 'Allow proximity based password sharing requests' is set to 'Disabled'MDMMobileIron - CIS Apple iOS 18 v1.0.0 L1 Institution Owned
3.2.1.29 Ensure 'Allow proximity based password sharing requests' is set to 'Disabled'MDMAirWatch - CIS Apple iPadOS 18 v1.0.0 L1 Institutionally Owned
3.2.1.29 Ensure 'Allow proximity based password sharing requests' is set to 'Disabled'MDMMobileIron - CIS Apple iPadOS 18 v1.0.0 L1 Institutionally Owned
3.2.1.30 Ensure 'Allow password sharing (supervised only)' is set to 'Disabled'MDMMobileIron - CIS Apple iOS 17 Institution Owned L1
10.3.5 Ensure 'Allow Azure services on the trusted services list to access this storage account' is Enabled for Storage Account Accessmicrosoft_azureCIS Microsoft Azure Foundations v4.0.0 L2