Requirements / Access Control (AC)
AC.L2-3.1.12
Control Remote Access
Official Source Material
Monitor and control remote access sessions.
Determine if:
- [a] remote access sessions are permitted;
- [b] the types of permitted remote access are identified;
- [c] remote access sessions are controlled; and
- [d] remote access sessions are monitored.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Answer four questions in one policy.
Objective [a] asks whether remote access is permitted. Objective [b] asks which types: VPN, access to cloud services over the internet, vendor support sessions. Objective [c] asks how each is controlled: managed devices only, multifactor authentication, conditional access, device health checks at connection. Objective [d] asks how each is monitored: which logs exist, who reviews them, how often. That document, with the configurations and review records behind it, is the whole requirement.
Define what counts as remote in your environment and defend it in writing.
Whether an established VPN session from a company-owned laptop is still remote access has no settled answer among assessors. Take the durable position. The tunnel is a type of permitted remote access, so list it under [b], then control and monitor it. If you then treat traffic inside the established tunnel as internal, document that treatment and its rationale. The requirement's own discussion says encrypted VPNs do not make access non-remote. They let you treat the connection like an internal network once controlled.
Cloud access is remote access for this requirement.
Sessions to Microsoft 365 or any internet-reached service matter when those services hold CUI, the controlled unclassified information your contract requires you to protect. TLS, the standard encryption on web connections, plus conditional access policies requiring compliant devices are your [c]. The identity provider's sign-in logs and their review are your [d]. A fully cloud organization with no office still has types to identify under [b]: name the TLS access paths and the gateway or conditional access layer that fronts them.
Monitoring means a person looks at the logs.
Collection is not monitoring. Write the review procedure for VPN and sign-in logs. Run it at a frequency matched to your risk. Keep the artifacts: a ticket closing the review, an alert and its disposition, an email summarizing findings. An assessor asks for the procedure and then asks for proof it ran.
No CUI over the remote link does not scope this requirement out.
Remote access used for system maintenance is still remote access to an in-scope system, and the requirement applies. The only way to scope it out is to prevent remote access entirely and have the policy and configuration that prove it.
What falls short
- A system security plan claiming no remote access while staff connect by VPN or reach cloud services from home. The types in [b] go unidentified, and nothing can satisfy [c] or [d] for sessions the plan says do not exist.
- Logs collected with no review procedure and no records of review. Collection alone leaves [d] unmet.
Edge cases
- A site-to-site VPN between your own offices is an extension of the network, not a remote access session. The on-demand tunnel from a user's laptop is one.
- Attended support tools such as Quick Assist are remote access when the operator connects from outside your boundary. Route vendor and managed service provider (MSP) support through an approved, monitored path instead of whatever tool the technician prefers.