NIST 800-53 Rev 5

424 controls available

AC-17(3)moderatehigh

Managed Access Control Points

Access Control

Control Statement

Route remote accesses through authorized and managed network access control points.

Discussion

Organizations consider the Trusted Internet Connections (TIC) initiative [DHS TIC](#4f42ee6e-86cc-403b-a51f-76c2b4f81b54) requirements for external network connections since limiting the number of access control points for remote access reduces attack surfaces.

Framework
NIST SP 800-53 Rev 5
Family
Access Control
Baselines
moderate, high

Related Frameworks

4 paths across 2 frameworks
NIST 800-1711 mapping
3.1.14
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI3 mappings
CCI-000069
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001561
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002315
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

220 STIGs reach this control through 25 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

7 STIGs

Operating System — Server

42 STIGs
Oracle Linux 8 Security Technical Implementation Guide
V2R82026-02-1310 of 375 findings match
Show 34 more STIGs in this category →
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-178 of 448 findings match
IBM AIX 7.x Security Technical Implementation Guide
V3R22026-02-066 of 283 findings match
IBM AIX 7.x Security Technical Implementation Guide
32024-08-166 of 283 findings match
Anduril NixOS Security Technical Implementation Guide
V1R22025-08-193 of 103 findings match
Solaris 11 X86 Security Technical Implementation Guide
V3R52026-02-192 of 216 findings match

Operating System — Mainframe

17 STIGs
IBM z/OS ACF2 Security Technical Implementation Guide
V9R82026-03-099 of 225 findings match
IBM z/OS RACF Security Technical Implementation Guide
V9R82026-03-099 of 222 findings match
IBM z/OS TSS Security Technical Implementation Guide
V9R82026-03-099 of 230 findings match
Show 9 more STIGs in this category →

Operating System — Mobile

6 STIGs

Network Device

53 STIGs
Application Layer Gateway Security Requirements Guide
V2R32025-09-157 of 160 findings match
Cisco ASA VPN Security Technical Implementation Guide
V2R22024-08-226 of 41 findings match
Show 45 more STIGs in this category →
SDN Controller Security Requirements Guide
22024-05-283 of 34 findings match
Cisco ISE NAC Security Technical Implementation Guide
V2R32025-12-101 of 30 findings match
Domain Name System (DNS) Security Requirements Guide
V4R22025-12-191 of 119 findings match
F5 NGINX Security Technical Implementation Guide
V1R12026-01-071 of 32 findings match
Firewall Security Requirements Guide
V3R32025-09-221 of 35 findings match
Firewall Security Requirements Guide
32024-12-041 of 34 findings match

Web / Application Server

34 STIGs
Web Server Security Requirements Guide
V4R42025-09-106 of 126 findings match
Web Server Security Requirements Guide
42025-02-126 of 124 findings match
Show 26 more STIGs in this category →
Application Server Security Requirements Guide
V4R42025-09-105 of 137 findings match
Application Server Security Requirements Guide
42025-02-115 of 128 findings match

Virtualization / Container

39 STIGs
Kubernetes Security Technical Implementation Guide
V2R62026-02-125 of 92 findings match
Virtual Machine Manager Security Requirements Guide
22024-12-065 of 193 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-105 of 198 findings match
Show 31 more STIGs in this category →
Container Platform Security Requirements Guide
V2R42025-09-103 of 188 findings match
Container Platform Security Requirements Guide
22025-05-153 of 187 findings match

Cloud / Identity Service

2 STIGs

Endpoint Security Management

14 STIGs
Tanium 7.x Security Technical Implementation Guide
V2R32025-05-144 of 98 findings match
Show 6 more STIGs in this category →
ISEC7 Sphere Security Technical Implementation Guide
V3R12024-08-201 of 34 findings match

Productivity Application

5 STIGs

Uncategorized

1 STIG