NIST Special Publication 800-171 Revision 2
IDName
3.1.14Route remote access via managed access control points
3.13.1Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems
3.13.5Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks
3.13.6Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
3.14.7Identify unauthorized use of organizational systems