AC-17(2): Protection of Confidentiality and Integrity Using Encryption

Control Family:

Access Control

Parent Control:

AC-17: Remote Access

CSF v1.1 References:

CSF v2.0 References:

PF v1.0 References:

Baselines:

  • Moderate
  • High
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Previous Version:

Control Statement

Implement cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.

Supplemental Guidance

Virtual private networks can be used to protect the confidentiality and integrity of remote access sessions. Transport Layer Security (TLS) is an example of a cryptographic protocol that provides end-to-end communications security over networks and is used for Internet communications and online transactions.

OT Discussion

Encryption-based technologies should be used to support the confidentiality and integrity of remote access sessions. While OT devices often lack the ability to support modern encryption, additional devices (e.g., VPNs) can be added to support these features. This control should not be confused with SC-8 – Transmission Confidentiality and Integrity, which discusses confidentiality and integrity requirements for general communications, including between OT devices.